Section outline

    • Think about the devices you use for work today. Does your organization have an agreement on how you can or cannot use these devices? For most organizations, there is an acceptable use agreement for work-issued device usage, whether verbal or written. However, it is important to also have documented guidance on how to safely manage devices such as laptops, tablets, phones, and any connected devices used for work purposes within an organization. This guidance is known as a device security policy

      This policy can include different steps that people within the organization can take to secure devices. The policy document should be accessible to the entire organization and all team members should review it on a regular basis.

       

      If You Can Keep Personal and Work Devices Separate, You Should  

      Oftentimes, we think about the devices we use in terms of productivity and getting our day-to-day work tasks done. How often, though, do we consider the risks that these devices can pose to ourselves and our organizations? 

      For example, it is common practice for staff members to use laptops and desktops to perform various work functions. While there are some organizations that provide employees with work-issued devices, it is quite common for individuals to use work devices for personal reasons and personal devices for work tasks. This mixed use can increase your risk of an attack. 

      Similarly, mobile devices are vulnerable to attacks on various levels including exploitation of vulnerabilities within the mobile device or its operating system or malicious applications (malware) that users can accidentally install on their devices. 

      Because so many of us now use mobile devices for work, cybercriminals have increased their attacks on these devices. The biggest cyber threats to mobile devices include device theft or seizure, which can give cybercriminals or malicious actors access to the physical device and ultimately, critical data, and the use of outdated software, which can leave your device vulnerable to attacks that might also expose your network to security risks.

      To lower the risk to your mobile security, we recommend keeping your work and personal devices separate. Alternatively, compartmentalizing data reduces access to sensitive information when a mobile device is confiscated, stolen, lost, or exposed to malware. 

       

      What Should Your Device Security Policy Cover?

      A proper device security policy should include: 

      The following sections break down all the above-mentioned components of a device security policy.

       

      Define Responsibility for Devices 

      As part of your device security policy, your organization should outline the various types of mobile devices employees can use, who owns and maintains the devices, and the rules and policies employees need to follow to use mobile devices and access valuable organizational data. 

      There are different approaches to the level of freedom employees can have while using mobile devices in the workplace for work purposes. This includes: 

      Depending on the organization’s chosen approach, the policy should state clearly who has ownership of the device and what is considered acceptable use.  This helps employees follow best practices while using mobile devices for work and mitigating threats. 

       

      Determine How You Will Manage Devices

      There are two practices organizations can consider when it comes to managing devices: endpoint management and mobile device management.

      Endpoint management is a practice focused on supervising and authenticating access to endpoint devices with the aim of preventing internal or external threats posed by access to the network system. An endpoint device is any hardware device such as a mobile phone, laptop, tablet, desktop, or a server that connects to your network or data. Endpoint management ensures that only authorized devices can access the network.. This practice is used to restrict access to the network, apply and monitor endpoint security policies, and enable security administrators to manage processes and devices from one central application or console.

      Mobile device management (MDM) is software that allows organizations to monitor, manage, and secure company-owned devices. Using MDM organizations are able to monitor, track, and secure mobile devices employees use at work, protect sensitive data from loss, theft, or hacking, and  extend protection to printers, desktop computers, and other devices through Unified Endpoint Management. 

      You can learn more about endpoint protection and mobile device management in this module.

       

      Address Working From Home In Your Policy

      Remote work has exposed organizations to unique information security challenges. Remote work environments do not have the same safeguards that exist in an office, which often has security systems to prevent or minimize cyberattacks. To ensure employees are able to secure their devices while working remotely, your device policy should have various guidance on how to secure mobile devices at home, keep devices updated, and avoid sharing devices with family members and friends. 

       

      Access to Devices/Systems

      Onboarding and offboarding employees

      As an organization, it's always important to establish and document the onboarding and offboarding processes that work for both IT and other internal teams.

      The policy should include details such as how to onboard new staff members and set their permission levels based on their roles. In addition, if you're issuing work devices, you should include clear guidance for new staff members on what they can or cannot do with their devices. Additionally, if staff members wish to install software, you should cover those procedures in your policy, as well, including approved sources to find software. 

      Although offboarding is typically handled by HR departments for most organizations, it's important to include the IT team, as well, to ensure you recover work devices and other assets. The company should also take extensive measures to lock access to internal systems once an employee leaves. This can prevent attacks such as unauthorized access, data theft, and hacking through accounts belonging to former employees that are still active.

      Login policy

      The main purpose of a login policy is to avoid or prevent unauthorized access to your system, such as brute force attacks. For this reason, you should specify the number of times a user or an administrator is allowed to enter the wrong login details before they have to reset their credentials. Depending on your preference, you can also decide to limit the number of logins for a particular service in a day.

      Third-party providers/contractors

      A device security policy should also have a section that covers contractors and third-party vendors. This could include security protocols for user authentication and access as well as common industry security practices such as antivirus protection and malware protection. If you have the capacity as an organization, you can run an initial security assessment of the contractors’ security posture before engaging further with them. You can use the Cybersecurity Assessment Tool for this. 

      Lost or stolen devices

      Organizations need to have steps and procedures employees should follow when a mobile device is stolen or lost. Whether it’s an accidental loss of the device or a theft, the organization should have procedures in place to handle these different scenarios. The device policy should have information on:

      Some of the steps that can be taken include wiping the device remotely, reporting the theft to relevant authorities,  recovering the device when possible, and replacing the device. 

      Devices during a crisis

      Employees can be exposed to various challenges including pandemics, conflicts, natural disasters, or civil unrest. The loss of devices is common during times of crisis. Organizations need to implement device policies to safeguard their data in such scenarios, depending on the type of crisis they face. 

       

      Make Your Policy Effective

      A device security policy is a living document that should be updated on a regular basis. To make the policy effective, your organization needs to communicate the importance of following the policy, as well as create and nurture a culture of security.