Device security guidance
Guidance for organisations on how to choose, configure and use devices securely.
Pages
Page 34 of 37
Action 2 - Develop the policy
Once you have established your appetite for the types of risk associated with BYOD, you should start developing your BYOD policy. This should clarify and communicate both organisational and employee responsibilities.
There are two stages to developing a BYOD policy:
-
What tasks will employees be permitted or encouraged to do from their own devices? What will they not be permitted to do?
For example, you may want your employees to submit expense reports from their personal devices but not access emails.
Users with privileged or administrative access should not have this level of access from a personal device. However, they can be granted the standard accesses which you permit for BYOD devices.
It is just as important to define and document here what you do not want your users to do. This may change over time. When it does, you should adapt your policy accordingly.
-
What services will you expose to personal devices? What data you will expose from within those services?
For example, although you might decide to allow users to submit expense reports, you may not permit changing of bank details.
-
How much control will your employees be willing to grant you over their devices, and how much control do you need?
If you expect users to reject any control of their devices, your ability to manage risks will be compromised. For example, users may not like the idea of their employer being able to remotely wipe their entire device.
-
How enforceable are your policies?
If your policies rely entirely on users following specific procedures to keep devices secure, you should also consider what happens if users do not follow those procedures, and how you might respond in such circumstances.
Enforcing your policy with technical controls
-
What types of client access are permitted?
For example, phones with native apps, third-party container apps, web browsers – see Action 4: Deployment approaches for more detail.
-
What minimum standards for hardware and software versions will you enforce?
Older or unsupported platform versions are more likely to contain security weaknesses for which no fix exists. Newer platforms are more likely to contain improved mitigations which make them harder to exploit, even if a security vulnerability is found. See our Obsolete platforms guidance for more information.
-
What policies will you enforce, and how will you enforce them? Will they apply at device, application or both levels?
You may be able to enforce some policies, including minimum passcode length and preventing copy and paste between work and personal apps. You will need to check your MDM or MAM service documentation for what policies are supported on your chosen platforms.
-
How will you handle an employee changing their device, changing their role, or leaving the organisation?
What method will you use to remove access and corporate data (if stored on the device)?
-
What service access policies will you enforce?
For example, you could use compliance policies and strong authentication to verify devices before they are allowed access to BYOD approved enterprise services. Strong user authentication including MFA is especially important for BYOD as it may not be possible to implement strong machine authentication for personal devices.
You should consider here how you will implement these effective authentication practices. Multi-Factor Authentication (MFA) is a minimum requirement.
-
How will individual services prevent personal devices from accessing sensitive data?
You might want to restrict access from personal devices to certain areas of a single service. For example, you may block access from personal devices to the most sensitive internal documents within your file storage services, while still allowing them to access less sensitive material in the same service.
-
How and where will you enforce these policies?
They could be enforced at an authentication service, network firewall, or boundary/perimeter of specific services.
-
How will you enforce separation between business and personal applications?
What will you use to prevent corporate data being opened or moved to personal applications? For example, you may use MAM policies to block copying of corporate data to personal storage services.
-
What will you do in the event of a security incident?
How will you deal with potential loss, theft or compromise of devices and data?
What will you put in place to enable you to act swiftly in the event of a potential security incident?
Security controls which adversely affect the usability of a device or service will drive down BYOD adoption and therefore undermine your approach. Overly restrictive controls may even encourage staff to find workarounds, which increase your security risk.
-
What types of devices will you allow to be used for BYOD. Will employees be able to use more than one BYOD device?
Are you intending your services to only be used by specific devices (desktop and laptop PC’s, smartphones, and tablets)? Just because a device could be used for BYOD, does not mean that it should be used for BYOD.
-
Where will BYOD devices be used?
Will BYOD devices only be used from remote locations or will they also be brought into office spaces and connected to ‘trusted’ networks? Will they be permitted to be used abroad? If so, consider whether limitations need to be put in place on the countries they can be used in.
-
How will you prevent unauthorised devices from accessing sensitive information?
What controls will you put in place to separate your sensitive corporate services and those which you will expose to BYOD?
-
How will you encourage users to adopt your policies?
How will you communicate your BYOD policies and practices to your users and get them to embrace this way of working?