Where the device belongs to the user.
WHAT THE TENSION IS
The organisation needs its data protected; the user's personal data must not be exposed or erased.
WHAT USER ENROLMENT PROVIDES
Separation of organisational and personal data on the same device.
WHAT THE ORGANISATION CAN DO
Manage its own applications and accounts Enforce policy on its own data Remove its data
WHAT IT CANNOT DO
See personal applications and data Erase the device Access personal photographs, messages or location
WHY THAT MATTERS
It makes enrolment acceptable to users, which is what makes it work.
WHAT TO COMMUNICATE CLEARLY
Exactly what the organisation can and cannot see.
WHY
Assumptions otherwise are worse than the reality, and refusal follows.
WHAT TO ESTABLISH IN POLICY
What data may be accessed on personal devices What happens when someone leaves
What is required: passcode, encryption, current version
WHAT TO DOCUMENT AND HAVE ACKNOWLEDGED
All of it.
WHAT TO CONSIDER
Whether the organisation should simply provide devices instead.