Only approved applications, restricted by code signing, are allowed to execute on devices. The Applicant must: o actively approve such applications before deploying them to devices o maintain a current list of approved applications Users must not be able to install any application that is unsigned or has an * invalid signature.
The organization must have list of approved applications, and application sources, that are allowed to be used on the organization's endpoint devices.
The organization should, if possible, execute management of approved software using automation for example with policies from mobile device management system.
Only software approved by the organization can be run on the devices. The organization should: