A control improperly configured and unmaintained is not a control, it is a checkbox. Start at page 6.
"Even though ICE’s MDM provides visibility to all installed applications, ICE did not have a process to periodically review, assess, block, and remove risky applications installed on devices."
Also didn't prevent folks from installing VPN apps and TikTok (redacted, but easy to discern from what isn't).
(i own $day job's acceptable use policy and MDM baseline/operation)