Tyscorpa Study resources Open the Academy

Asset Management

Hardware, software, and data asset management including MDM, BYOD, and secure data disposal.

SY0-701 Obj. 4.2 Security Operations 28% of the exam

Asset Inventory & Tracking

You cannot protect what you don't know exists. Asset management starts with a complete inventory:

Mobile Device Management (MDM)

MDM solutions centrally manage and enforce policy on mobile devices:

Examples: Microsoft Intune, Jamf (Apple), VMware Workspace ONE, Google Endpoint Management.

MAM vs. MDM

MDM (Mobile Device Management)MAM (Mobile Application Management)
ScopeEntire deviceOnly managed apps
Use CaseCorporate-owned devicesBYOD — employee personal devices
Remote WipeFull device wipeOnly corporate app data wiped
PrivacyCan see all device activityCannot see personal apps/data

BYOD, COPE, CYOD Policies

PolicyDescriptionSecurity Posture
BYOD (Bring Your Own Device)Employee uses personal device for workWeakest control — use MAM, containerization
COPE (Corporate-Owned, Personally Enabled)Company buys device; employee can use personallyFull MDM policy applied
CYOD (Choose Your Own Device)Employee picks from an approved list of corporate devicesFull MDM; limited device variety
Corporate-Owned OnlyStrict corporate devices; no personal useStrongest control

Secure Data Disposal (Asset Lifecycle)

When an asset reaches end-of-life, its data must be properly destroyed before disposal or repurposing. (See also: Domain 3 — Secure Data Destruction)

PreviousHardening & Configuration NextIncident Response

Test yourself on this

Reading is the easy half. The Academy has 1,360 exam-style questions, including performance-based ones, and it keeps pulling from whichever domain you keep getting wrong. Free to create an account.

Open the Academy