Personal Device (BYOD) & Removable Media
- Use of personally owned devices for work is governed by a Personal Device Use Policy and the acceptable-use policy, with company-provided devices preferred and personal use limited to an as-needed basis.
- Personal devices must meet defined security requirements before access — encryption, screen-lock, current anti-malware/EDR, maintained operating systems, and no jailbroken/rooted devices — and every device is treated as untrusted by default, requiring validation before access is granted.
- Removable media is automatically scanned upon insertion, and endpoints are contained if malware is identified.
Framework Alignment: NIST CSF PR.AA, PR.PS, DE.CM; CIS Control 4, 10; CMMC Level 1; GDPR Art. 32; ISO 27001:2022 A.8.1, A.7.10