Device Security Policy

Purpose

This policy establishes minimum security requirements for laptops, desktops, smartphones, tablets, servers, and other devices used for company business.

Approved Devices

Company information should be accessed primarily through company-managed or specifically approved devices.

Personal devices should only be used where permitted.

Supported Systems

Devices should use supported operating systems and applications.

Unsupported operating systems should be upgraded, replaced, isolated, or formally accepted as a risk.

Updates

Security updates should be enabled and applied within appropriate timeframes.

Users must not deliberately prevent required security updates.

Endpoint Protection

Company-managed endpoints should have appropriate security protection enabled.

This may include:

  • Antivirus or endpoint detection
  • Firewall
  • Disk encryption
  • Web or DNS protection
  • Device management
  • Security logging

Screen Lock

Devices should automatically lock after an appropriate period of inactivity.

Users should manually lock devices whenever they leave them unattended.

Encryption

Portable devices containing company information should use full-disk encryption where supported.

Encryption recovery keys should be stored securely.

Administrator Rights

Normal users should not have permanent local administrator privileges unless required and approved.

Administrator access should be separated from ordinary daily use where practical.

Software Installation

Users should not install unapproved software, browser extensions, remote access tools, or security-disabling utilities.

Lost or Stolen Devices

Lost or stolen devices must be reported immediately.

Where possible, the company should be able to:

  • Disable accounts
  • Revoke sessions
  • Locate or remotely wipe managed devices
  • Assess whether sensitive information was stored locally

Physical Protection

Users should:

  • Avoid leaving devices unattended in public places
  • Protect devices during travel
  • Avoid sharing company devices with unauthorized people
  • Secure company equipment when working remotely

Disposal and Reuse

Before devices are sold, discarded, returned, or reassigned:

  • Company information should be securely removed
  • Accounts should be removed
  • Device management enrollment should be updated
  • Encryption keys and recovery information should be handled appropriately

Practical Rule

Every device accessing company information should be supported, protected, updated, and accountable to an owner.