# Mobile Device Security & Secure Telework: Work Anywhere, Secure Everywhere Course (Self-Paced)

Canonical URL: <https://www.graduateschool.edu/courses/mobile-device-security-and-secure-telework-self-paced>

## Overview

This is behavioral awareness training for anyone who uses mobile devices and remote access to do their job, written from the learner's point of view rather than the administrator's. Every objective is something a learner does or can explain, which is what makes the course assessable rather than abstract, and it deliberately does not cover mobile device management architecture or enrollment design; it answers the questions a device user has, including the honest one about what a remote wipe does to their personal photos. Authentication is the standout material. Framing multifactor authentication as sufficient no longer holds, since attackers routinely defeat it with push bombing, one-time-code phishing and relay proxies, so this course names phishing-resistant authentication directly — PIV cards, derived credentials and passkeys — and devotes a separate objective to recognizing and refusing MFA abuse, in line with the federal Zero Trust strategy's phishing-resistant requirement rather than decade-old guidance.

Social engineering is taught mobile-first, not desktop-era, covering SMS and messaging-app phishing, malicious QR codes, and AI-generated voice or video impersonation of a supervisor or help desk. Shadow IT and shadow AI get named too, since work content moved into personal cloud storage or consumer AI assistants is now among the most common data-spillage paths in federal telework. The home network module trades general advice for specific actions: change default router credentials, apply firmware updates, turn on current wireless encryption, and keep work traffic away from smart-home equipment. The closing module connects reporting to required timeframes and then explains what follows, including remote lock and wipe and its effect on personal data, the most common reason people resist bring-your-own-device programs. It is a natural companion to the [ICAM and MFA Fundamentals Course (Self-Paced)](https://www.graduateschool.edu/courses/icam-and-mfa-fundamentals-self-paced) for anyone wanting the authentication material in greater depth.

## What you'll learn

- Distinguish government-furnished, personally owned and third-party-managed devices, and the rules that apply to each
- Explain how telework moves the security boundary to the device and the home, and identify what you are personally responsible for protecting
- Configure screen lock, biometrics, automatic locking and device encryption
- Explain what mobile device management sees, what it enforces, and what remote wipe does to personal data
- Limit app permissions, sideloading, and use of unapproved cloud or AI applications
- Identify approved remote-access methods, and verify that a connection is actually encrypted
- Use phishing-resistant authentication including PIV, derived credentials and passkeys
- Recognize and refuse MFA abuse, including push bombing and one-time-code theft
- Secure a home router, and separate work activity from personal accounts and smart-home equipment
- Recognize mobile-first lures including smishing, QR-code attacks and voice or video impersonation
- Recognize a compromised device or account and report it within required timeframes
- Complete recovery steps including credential changes, re-enrollment and return to service

## Prerequisites

Comfort using a smartphone, laptop and remote-access tools for work. No technical background required.

## Curriculum

#### Module 1

- Security Beyond the Office: Mobile & Telework Foundations
- Defining mobile device security, telework, remote access and bring-your-own-device
- Government-furnished versus personally owned versus third-party-managed devices
- How telework moves the security boundary
- What the learner is personally responsible for
- Obligations under the telework agreement and rules of behavior

#### Module 2

- The Device Is an Endpoint: Mobile Device Security
- Malicious apps, smishing, spyware and untrusted accessories
- Screen lock, biometrics, automatic locking and device encryption
- What mobile device management enforces, verifies and can wipe
- Prompt updates and limiting permissions, sideloading and unapproved cloud or AI apps
- Protecting data on devices being lost, transferred, repaired or retired

#### Module 3

- Connect with Confidence: Secure Remote Access
- Approved methods including VPN, virtual desktop and zero trust network access
- Verifying encryption and responding to certificate and captive-portal warnings
- Phishing-resistant authentication with PIV, derived credentials and passkeys
- Refusing unexpected authentication prompts and recognizing push bombing and one-time-code theft
- Assessing public, hotel, shared and home networks

#### Module 4

- Home Is Part of the Attack Surface: Secure Telework Practices
- Securing the home router through default credentials, updates and current wireless encryption
- Separating work from personal accounts, personal devices and smart-home equipment
- Recognizing phishing, smishing, QR-code lures and voice or video impersonation
- Protecting information from unauthorized viewing, printing, storage and sharing
- Physical and privacy practices in shared, public and travel settings

#### Module 5

- Lost, Stolen, Compromised: Monitoring & Response
- Indicators of a compromised device or account including unexpected access alerts
- What compliance checks, logging and monitoring actually detect on a managed device
- Reporting within required timeframes
- Remote lock, wipe and credential revocation and their effect on personal data
- Recovery steps through credential changes, re-enrollment and return to service

## Pricing

**Tuition:** $675
