BYOD & Endpoint Security Policy¶
| Field | Value |
|---|---|
| Owner | Puneet Gupta (Co-Founder) |
| Classification | Internal (shareable under NDA) |
| Version | 1.0 |
| Effective date | 2026-06-11 |
| Next review | 2027-06-11 |
1. Purpose¶
Define the security requirements for endpoint devices — including personal (BYOD) devices — used to access Revzio or customer systems and data.
2. Scope¶
All laptops and devices used by personnel to access Revzio systems, code, or customer data.
3. Mandatory device requirements¶
Any device used for work must have:
- Full-disk encryption enabled (FileVault on macOS, BitLocker on Windows, LUKS on Linux).
- Screen lock with a short inactivity timeout (≤ 5 minutes) and a strong device passcode/biometric.
- Operating system kept current — a supported OS with automatic security updates enabled.
- Anti-malware protection active and updated (OS-native protection is acceptable).
- A host firewall enabled.
- No shared device accounts for work activity.
4. Removable / portable media¶
Use of removable media (USB drives, external disks) for customer or sensitive data is discouraged. Sensitive data is held in the managed application database, not on local or portable media. Controls on removable media are enforced as part of device management rollout.
5. Loss, theft, and offboarding¶
- Lost or stolen devices must be reported immediately (see Incident Response Plan).
- Personnel consent to remote revocation of access and, where feasible, remote wipe of work data on a lost/stolen or offboarded device.
- Access is revoked promptly on offboarding.
6. Attestation & enforcement¶
- Personnel attest that their device meets this policy on onboarding and annually.
- Centralized verification and compliance reporting will be provided via Mobile Device Management (MDM) rollout, which will produce an endpoint-compliance dashboard reviewed on a weekly/monthly basis. (Planned — Tier 2 of the endpoint-security task.)
Revision history¶
| Version | Date | Author | Change | Approved by |
|---|---|---|---|---|
| 1.0 | 2026-06-11 | Puneet Gupta | Initial draft | Puneet Gupta (Co-Founder) |