# Mobile Device Security & Secure Telework: Work Anywhere, Secure Everywhere Course

Canonical URL: <https://www.graduateschool.edu/courses/mobile-device-security-and-secure-telework>

## Overview

This is a behavioral awareness course for the people who use mobile devices and remote access for work, written from the learner's point of view rather than the administrator's. Every objective is something the learner does or can explain, which makes the whole course assessable rather than abstract, and it does not promise mobile device management architecture or enrollment design — it answers the questions a device user actually has. The authentication material is what sets it apart. Ordinary multifactor authentication is no longer sufficient framing, because attackers routinely defeat it through push bombing, one-time-code phishing and relay proxies, so this course teaches phishing-resistant authentication by name — PIV cards, derived credentials and passkeys — and adds a separate objective on recognizing and refusing MFA abuse, reflecting the federal Zero Trust strategy's phishing-resistant requirement rather than decade-old guidance.

The social engineering content is mobile-first rather than desktop-era, covering SMS and messaging-app phishing, malicious QR codes, and AI-generated voice or video impersonation of a supervisor or help desk, along with shadow IT and shadow AI — work content moved into personal cloud storage or consumer AI assistants — now one of the most common data-spillage paths in federal telework. The home network module gives specific actions rather than general advice: change default router credentials, apply firmware updates, enable current wireless encryption, and keep work traffic away from smart-home equipment. The final module ties reporting to required timeframes and then explains what happens next, including remote lock and wipe and what that means for personal data, which is the single most common source of resistance to bring-your-own-device programs. It pairs naturally with the [ICAM and MFA Fundamentals Course](https://www.graduateschool.edu/courses/icam-and-mfa-fundamentals) for anyone who wants the authentication material in more depth.

## What you'll learn

- Distinguish government-furnished, personally owned and third-party-managed devices, and the rules that apply to each
- Explain how telework moves the security boundary to the device and the home, and identify what you are personally responsible for protecting
- Configure screen lock, biometrics, automatic locking and device encryption
- Explain what mobile device management sees, what it enforces, and what remote wipe does to personal data
- Limit app permissions, sideloading, and use of unapproved cloud or AI applications
- Identify approved remote-access methods, and verify that a connection is actually encrypted
- Use phishing-resistant authentication including PIV, derived credentials and passkeys
- Recognize and refuse MFA abuse, including push bombing and one-time-code theft
- Secure a home router, and separate work activity from personal accounts and smart-home equipment
- Recognize mobile-first lures including smishing, QR-code attacks and voice or video impersonation
- Recognize a compromised device or account and report it within required timeframes
- Complete recovery steps including credential changes, re-enrollment and return to service

## Curriculum

#### Module 1

- Security Beyond the Office: Mobile & Telework Foundations
- Defining mobile device security, telework, remote access and bring-your-own-device
- Government-furnished versus personally owned versus third-party-managed devices
- How telework moves the security boundary
- What the learner is personally responsible for
- Obligations under the telework agreement and rules of behavior

#### Module 2

- The Device Is an Endpoint: Mobile Device Security
- Malicious apps, smishing, spyware and untrusted accessories
- Screen lock, biometrics, automatic locking and device encryption
- What mobile device management enforces, verifies and can wipe
- Prompt updates and limiting permissions, sideloading and unapproved cloud or AI apps
- Protecting data on devices being lost, transferred, repaired or retired

#### Module 3

- Connect with Confidence: Secure Remote Access
- Approved methods including VPN, virtual desktop and zero trust network access
- Verifying encryption and responding to certificate and captive-portal warnings
- Phishing-resistant authentication with PIV, derived credentials and passkeys
- Refusing unexpected authentication prompts and recognizing push bombing and one-time-code theft
- Assessing public, hotel, shared and home networks

#### Module 4

- Home Is Part of the Attack Surface: Secure Telework Practices
- Securing the home router through default credentials, updates and current wireless encryption
- Separating work from personal accounts, personal devices and smart-home equipment
- Recognizing phishing, smishing, QR-code lures and voice or video impersonation
- Protecting information from unauthorized viewing, printing, storage and sharing
- Physical and privacy practices in shared, public and travel settings

#### Module 5

- Lost, Stolen, Compromised: Monitoring & Response
- Indicators of a compromised device or account including unexpected access alerts
- What compliance checks, logging and monitoring actually detect on a managed device
- Reporting within required timeframes
- Remote lock, wipe and credential revocation and their effect on personal data
- Recovery steps through credential changes, re-enrollment and return to service

## Schedule
- Jan 8, 2027 1:00pm–5:00pm — Live Online
- Apr 8, 2027 1:00pm–5:00pm — Live Online
- Jul 8, 2027 1:00pm–5:00pm — Live Online

## Pricing

**Tuition:** $675
