Device Security Policy
Purpose
This policy establishes minimum security requirements for laptops, desktops, smartphones, tablets, servers, and other devices used for company business.
Approved Devices
Company information should be accessed primarily through company-managed or specifically approved devices.
Personal devices should only be used where permitted.
Supported Systems
Devices should use supported operating systems and applications.
Unsupported operating systems should be upgraded, replaced, isolated, or formally accepted as a risk.
Updates
Security updates should be enabled and applied within appropriate timeframes.
Users must not deliberately prevent required security updates.
Endpoint Protection
Company-managed endpoints should have appropriate security protection enabled.
This may include:
- Antivirus or endpoint detection
- Firewall
- Disk encryption
- Web or DNS protection
- Device management
- Security logging
Screen Lock
Devices should automatically lock after an appropriate period of inactivity.
Users should manually lock devices whenever they leave them unattended.
Encryption
Portable devices containing company information should use full-disk encryption where supported.
Encryption recovery keys should be stored securely.
Administrator Rights
Normal users should not have permanent local administrator privileges unless required and approved.
Administrator access should be separated from ordinary daily use where practical.
Software Installation
Users should not install unapproved software, browser extensions, remote access tools, or security-disabling utilities.
Lost or Stolen Devices
Lost or stolen devices must be reported immediately.
Where possible, the company should be able to:
- Disable accounts
- Revoke sessions
- Locate or remotely wipe managed devices
- Assess whether sensitive information was stored locally
Physical Protection
Users should:
- Avoid leaving devices unattended in public places
- Protect devices during travel
- Avoid sharing company devices with unauthorized people
- Secure company equipment when working remotely
Disposal and Reuse
Before devices are sold, discarded, returned, or reassigned:
- Company information should be securely removed
- Accounts should be removed
- Device management enrollment should be updated
- Encryption keys and recovery information should be handled appropriately
Practical Rule
Every device accessing company information should be supported, protected, updated, and accountable to an owner.