Glossary

The terms, explained without the sales pitch

MDM, UEM, EMM, MTD, IRAP, PROTECTED. These come up in every scoping conversation we have, and they are used loosely often enough to be worth pinning down.

Mobility & endpoint

MDM Mobile Device Management

A platform that enrols mobile devices, applies configuration and policy to them, and reports whether they comply.

MDM is the foundation layer: enrolment, configuration profiles, passcode policy, app installation and remote wipe. It answers the question “is this device configured the way I said?”

What it does not do is tell you a device is under attack — a fully compliant handset on a hostile network still reports green. That gap is what mobile threat defence covers.

Managed MDM & UEM

UEM Unified Endpoint Management

One platform managing every endpoint class — phones, tablets, laptops and desktops — under a single policy model.

UEM is the successor to managing mobile and desktop estates in separate tools. The value is a single compliance position across every device a person uses, rather than two consoles that disagree.

In practice most organisations land somewhere in between, often running one platform for Windows and another for mobile and Apple. That is a legitimate architecture as long as somebody owns the joins.

Managed MDM & UEM

EMM Enterprise Mobility Management

An older term for MDM plus application and content management. Largely superseded by UEM.

EMM described the bundle of MDM, mobile application management and mobile content management. You will still see it in older documentation and in some procurement templates.

If a requirement document asks for EMM, it almost always means what the market now calls UEM.

BYOD Bring Your Own Device

An arrangement where staff use personally-owned devices for work.

The technical question is how to protect organisational data without claiming authority over a device you do not own — usually solved with app-level protection and a container rather than full device management.

The privacy model matters more than the feature list here. Staff will resist, correctly, any arrangement that lets an employer see personal apps or browsing.

Security & compliance

MTD Mobile Threat Defence

Security software that detects attacks against a mobile device across network, device, application and phishing vectors.

MTD is the mobile equivalent of endpoint detection on a laptop. The better implementations run detection on the device itself using machine learning, so they work with no connectivity and without sending user traffic to a cloud service for inspection.

It is complementary to MDM, not a replacement: MDM enforces configuration, MTD detects hostile activity. A detection is only useful if it changes something — the integration that matters is feeding device risk into conditional access.

Mobile Threat Defence

Essential Eight

Eight mitigation strategies published by the Australian Signals Directorate, scored across four maturity levels from ML0 to ML3.

The eight are: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication and regular backups.

It is a maturity position you hold rather than a certificate you obtain, and it decays — an exception granted for a project, a patch window missed. Most assessments are also scoped around the desktop fleet, quietly leaving mobile outside the boundary.

Cyber Security & Essential Eight

IRAP Information Security Registered Assessors Program

An ASD programme under which endorsed assessors evaluate a system against the Information Security Manual.

An IRAP assessment applies to a specific system or solution at a specific classification, assessed at a point in time. It is not a certification a company holds.

This distinction gets blurred constantly in Australian government sales. A vendor product can be IRAP assessed at PROTECTED while the partner delivering it holds no assessment of its own — both facts can be true. Ask any provider to state precisely which is which.

PROTECTED

An Australian Government security classification for information whose compromise would cause damage to the national interest, organisations or individuals.

PROTECTED sits above OFFICIAL and OFFICIAL: Sensitive, and below SECRET and TOP SECRET, under the Protective Security Policy Framework.

When a product is described as “(PROTECTED)” it usually means it has been assessed as suitable for handling information at that classification — a statement about the platform, not about whoever is selling it to you.

PSPF Protective Security Policy Framework

The Australian Government framework covering security governance, information, personnel and physical security.

The PSPF sets out what Commonwealth entities must do to protect their people, information and assets. Information handling, including protective markings, sits within it.

For mobile fleets the practical questions are whether protective markings are enforced on the device, and whether the personnel touching the environment meet the framework’s vetting expectations.

ISM Information Security Manual

The ASD publication of security controls that systems handling government information are assessed against.

The ISM is the control catalogue an IRAP assessment measures a system against. It is updated regularly, so a control mapping written two years ago is not current.

Conditional access

Access control that evaluates signals — user, device compliance, location, risk — before granting access to a resource.

It is what turns a compliance signal into a consequence. Without it, a device failing policy generates a report; with it, the device loses access to the data.

The quality of the decision depends entirely on the quality of the signals feeding it, which is why device management and identity should be designed together rather than as separate projects.

Modern Workplace & Microsoft 365

Apple & Android

Apple Business Manager ABM

Apple’s portal for linking devices, apps and identities to an organisation, and the prerequisite for zero-touch enrolment on Apple hardware.

A device registered in ABM is bound to your organisation at the hardware level. On activation it discovers it belongs to you and enrols into your MDM automatically, supervised, before anyone touches it.

Devices bought on a carrier plan are normally invisible to ABM. Carrier DEP is the mechanism that brings them in.

Apple Device Management

Carrier DEP CDEP

An Apple programme allowing an authorised party to register carrier-supplied iPhones into an organisation’s Apple Business Manager.

Without it, devices bought bundled with a telco plan behave as retail hardware — unsupervised, and enrollable only by handling each device or by a user-driven method the user can remove.

Carrier DEP also allows retrospective enrolment of devices you already own. Very few Australian resellers are enabled for it.

Carrier DEP explained

Zero-touch enrolment

Provisioning where a device configures and enrols itself on first boot, with no administrator handling it.

Delivered by Apple Business Manager on iOS and macOS, Android Enterprise zero-touch and Samsung Knox Mobile Enrolment on Android, and Windows Autopilot on Windows.

It is the single biggest determinant of what a fleet rollout costs, because the alternative is a person physically touching every device — at issue, at replacement and at every refresh.

Supervision

An Apple device mode that grants an organisation a deeper set of management controls than a personally-enrolled device allows.

A supervised device can have restrictions the user cannot remove, organisational activation lock, and management that cannot simply be deleted from Settings.

An unsupervised device can have its management removed by whoever is holding it, and you will not necessarily be told.

Managed IT

RPO and RTO Recovery Point / Recovery Time Objective

RPO is how much data you can afford to lose. RTO is how long you can afford to be unavailable.

Both are business decisions rather than technical ones, and both determine the cost of the protection you need. An RPO of one hour and an RPO of 24 hours are very different bills.

They are also the numbers most often assumed rather than agreed. If nobody in the business has signed off on them, they are IT’s guess.

Backup & Business Continuity

IPP Indigenous Procurement Policy

Commonwealth policy setting targets for the proportion of government contracts awarded to Indigenous businesses.

Purchasing from a majority Indigenous-owned supplier contributes to an agency’s IPP targets. CDTS is 100% Indigenous-owned and listed on the BuyICT Digital Marketplace.

ICT Procurement & Lifecycle

SOE Standard Operating Environment

A defined, repeatable build — operating system, applications and configuration — deployed across an estate.

The value of an SOE is that every device starts identical and drift is visible. The risk is that the build ages, and the exceptions accumulate until the “standard” environment describes almost nothing in the fleet.

Still unclear?

Ask us the question directly

If a supplier has told you something that does not match what you have read here, we are happy to give you a straight second opinion — including when it does not favour us.