@R3B005t
How are you handling the iTunes issue? With the iOS exploit that is now in Metasploit, we can now pull all that juicy info right from the device, as long as itunes is installed on the box.
Simple we dont allow iTunes to be installed in the environment. As part of our user acceptance policy for the iPhones we state that:
1) All iOS updates must be applied within 7 days of release or we will disable access to enterprise mail. For those users unable to update their iPhone's in a timely manner we disable it, update it for them and then re-enable email access.
2) The end user is responsible for backing up any content on their device, we recommend they install iTunes on a computer at home for this purpose since we A) don't allow iTunes on any of our machines and B) My users don't have rights to install sofware, they don't have any elevated privilages beyond the standard user account.
The product we are using for enterprise mail requres that A) Any backup be encrypted by defualt and B)Does not back up data contained in the app only the application itself.