# Endpoint and mobile device policy

Source: https://aestech.com.au/policy-templates/#endpoint-and-mobile-device-policy
Markdown URL: https://aestech.com.au/policy-templates/endpoint-and-mobile-device-policy.md

Use for ISO 27001 A.6.7, A.7.9, A.8.1, malware protection, remote work, and SOC 2 endpoint controls.

Frameworks: ISO 27001, SOC 2

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines baseline security requirements for laptops, mobile devices and remote work.

2. Requirements
- Company devices must be enrolled in device management where practical.
- Disk encryption, screen lock and supported operating systems are required.
- Endpoint protection or malware protection must be enabled.
- Lost or stolen devices must be reported immediately.
- Confidential information must not be stored on unmanaged removable media.
- Remote work must use approved networks, MFA and secure storage practices.

3. Evidence
Keep device inventory, MDM compliance reports, endpoint protection status, encryption status, exception approvals and lost-device incident records.
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md