### Purpose

This policy establishes minimum security requirements for laptops, desktops, smartphones, tablets, servers, and other devices used for company business.

### Approved Devices

Company information should be accessed primarily through company-managed or specifically approved devices.

Personal devices should only be used where permitted.

### Supported Systems

Devices should use supported operating systems and applications.

Unsupported operating systems should be upgraded, replaced, isolated, or formally accepted as a risk.

### Updates

Security updates should be enabled and applied within appropriate timeframes.

Users must not deliberately prevent required security updates.

### Endpoint Protection

Company-managed endpoints should have appropriate security protection enabled.

**This may include:**

- Antivirus or endpoint detection
- Firewall
- Disk encryption
- Web or DNS protection
- Device management
- Security logging

### Screen Lock

Devices should automatically lock after an appropriate period of inactivity.

Users should manually lock devices whenever they leave them unattended.

### Encryption

Portable devices containing company information should use full-disk encryption where supported.

Encryption recovery keys should be stored securely.

### Administrator Rights

Normal users should not have permanent local administrator privileges unless required and approved.

Administrator access should be separated from ordinary daily use where practical.

### Software Installation

Users should not install unapproved software, browser extensions, remote access tools, or security-disabling utilities.

### Lost or Stolen Devices

Lost or stolen devices must be reported immediately.

**Where possible, the company should be able to:**

- Disable accounts
- Revoke sessions
- Locate or remotely wipe managed devices
- Assess whether sensitive information was stored locally

### Physical Protection

**Users should:**

- Avoid leaving devices unattended in public places
- Protect devices during travel
- Avoid sharing company devices with unauthorized people
- Secure company equipment when working remotely

### Disposal and Reuse

**Before devices are sold, discarded, returned, or reassigned:**

- Company information should be securely removed
- Accounts should be removed
- Device management enrollment should be updated
- Encryption keys and recovery information should be handled appropriately

### Practical Rule

Every device accessing company information should be supported, protected, updated, and accountable to an owner.
