Skip to main content
Guidance

Device security guidance

Guidance for organisations on how to choose, configure and use devices securely.

Page 27 of 37

Advising end users

Advising your organisation’s users on expected and acceptable uses of devices, including smartphones, tablets, laptops and desktop PCs

Once devices have been provisioned and distributed to your organisation's employees, it is important that they know what behaviours they need to adopt or actions they need to take in order to keep their devices secure.

In many cases, administrators can use technical controls such as MDM policies and security configuration to help automatically keep devices secure, but sometimes users will have to be informed of expectations and acceptable usage. These procedural controls will be needed to mitigate certain threats.





In BYOD deployments, you might also want to include:

  • Which devices are acceptable for access corporate data

    This should include consideration of operating system and application versions.

  • Which policies must apply to the entire device

    For example, a full device passcode or VPN. This is in contrast to policies that might only apply to a container application. You should ensure users understand that their access may be limited if they do not follow these policies.

  • Which parts of the device or OS your organisation controls or oversees



Published

Reviewed

Version

2.1