Android and iOS

Mobile Threat Defense and application protection

Scope, trust models and the layers of application protection.

Protection foundations1 min readEditorial methods

MTD broadens visibility into devices, networks and mobile threats. App protection applies controls directly to a particular application's code and operations.

Evaluation approach

In an enterprise device-management environment, these signals may contribute to one access policy. A consumer application may not have the same management privileges.

Application example

Measure management status and application integrity separately in an employee application. Avoid assuming that an enrolled corporate device is always healthy.

Limits and considerations

The distribution model affects product selection. BYOD and a fully managed fleet do not require identical control designs.

Device management and application decisions

MTD products can connect device risk to enterprise monitoring and access systems. RASP describes defenses added to a distributed application. Because vendors may combine these capabilities, inspect the actual data flow.

A corporate device appearing compliant does not establish that every critical in-app decision is correct. An application event does not replace the corporate device inventory either. Shared event identifiers and clear responsibilities reduce the chance that two teams track the same problem under different names.

Checks and decisions

  • Measure managed-device coverage
  • Assign signal owners
  • Separate consumer use cases

Sources

The primary references above provide the technical basis. Example workflows and evaluation suggestions are this publication’s explanations, not independent test results for a particular product.