Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

COBO

← Back to Glossary
By NHI Mgmt Group Updated September 26, 2026 Domain: Governance, Ownership & Risk

Company Owned, Business Only refers to devices that the organisation owns and restricts to work use. This model maximises administrative control, simplifies security tooling, and supports stronger compliance enforcement. It is commonly paired with stricter management approaches when the business needs clear visibility into device posture and data handling.

COBO as a device ownership and control model

COBO, or Company Owned, Business Only, describes endpoints that the organisation owns and reserves for work use. The operational value is simple: the company can set the device baseline, control which apps and services are permitted, and apply consistent security policy without mixing in personal use requirements.

This model is most useful where the business wants a clear boundary between corporate data and personal activity. Because the device is dedicated to work, administrators can standardise hardening, logging, and compliance checks more confidently than on a personally owned device.

Why COBO changes security posture

COBO strengthens security by reducing ambiguity about who controls the device and what it is allowed to do. That clarity makes it easier to enforce patching, encryption, mobile threat protection, and remote wipe, while also limiting shadow IT and consumer app risk.

The trade-off is that COBO succeeds only when the organisation actually manages the full lifecycle of the device. If control is uneven, or if business-only rules are not backed by policy and tooling, the model can create a false sense of containment rather than real separation.

In practice, COBO is often paired with stronger endpoint policy stacks and baseline controls, such as the safeguards described in NIST SP 800-53 Rev 5 Security and Privacy Controls and the hardening approach in CIS Benchmarks.

Where COBO is used

COBO is common in environments that need tight oversight of managed endpoints, such as regulated operations, executive devices, field devices, and roles that handle sensitive business data. It is also attractive when the enterprise wants predictable device posture, simpler support boundaries, and fewer exceptions in endpoint management.

Compared with more flexible bring-your-own-device approaches, COBO is easier to standardise and audit, because the organisation does not need to compensate for personal apps, personal accounts, or mixed-use storage. That makes the model especially effective when the device itself is part of the control boundary.

COBO and governance expectations

COBO is not just a procurement label. It implies ownership of configuration, support, update enforcement, data handling rules, and decommissioning. The security benefit comes from operational discipline, not from the acronym alone.

Where COBO is deployed at scale, policy must define what “business only” means in practice, including approved use, prohibited local storage, exception handling, and the point at which a device must be retired or reset. For organisations aligning endpoint governance to broader security architecture, NIST Cybersecurity Framework 2.0 provides a useful structure for govern, protect, detect, respond, and recover thinking. Device access and trust decisions can also be framed through NIST SP 800-207 Zero Trust Architecture.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01 — Organizational ContextCOBO is a device ownership model shaped by organisational operating context.
PR.AA-05 — Identity Management, Authentication, and Access ControlCOBO depends on controlling who and what can use the managed device.
Recommendation — Define COBO policy within organisational context and clarify ownership, scope, and permitted use. Enforce access and device-use rules so only approved users and workflows operate on COBO endpoints.
NIST SP 800-53 Rev 5CM-6 — Configuration SettingsCOBO relies on standardised, enforceable device configuration baselines.
MP-7 — Media UseBusiness-only devices need rules governing removable media and local data exposure.
Recommendation — Apply configuration baselines to keep business-only devices in a known approved state. Restrict media use to reduce data leakage paths on COBO devices.
ISO/IEC 27001:2022A.8.1 — User end-point devicesCOBO is directly about organisational control of endpoint devices.
Recommendation — Establish endpoint controls for company-owned devices and verify their secure handling.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 26, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org