The development of the modern labour market involves increasing the level of mobility of personnel, so the current trend is the spread of mobile devices in the implementation of professional activities. This practice improves the efficiency of enterprise, but also has a negative impact on the security of information systems of enterprises. The growing requirements of employers have led to the growth of the functionality of mobile devices. However, this also causes an increase in the number of vulnerabilities in them, leading to an increase in the complexity of the security processes. The combination of the above problems determines the need to organize the process of information security management of enterprise mobile devices. The model of information security management of enterprise mobile devices is described in the article. It allows identifying vulnerabilities of operating system objects of enterprise mobile devices by modelling combinations of dangerous permissions more accurately.