# Mobile device and BYOD policy

Source: https://aestech.com.au/policy-templates/#mobile-device-and-byod-policy
Markdown URL: https://aestech.com.au/policy-templates/mobile-device-and-byod-policy.md

Use for ISO 27001 A.6.7, A.7.9, A.8.1, SOC 2 Security, and controls for remote and personally owned devices.

Frameworks: ISO 27001, SOC 2

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines the security requirements for mobile devices and for personally owned devices used to access company information, so that company data is protected regardless of who owns the device.

2. Scope
This policy applies to all smartphones, tablets and personally owned computers used to access company email, systems or data, and to all employees and contractors who use such devices.

3. Policy statements
- Access to company data from a personal device is permitted only where the device meets the minimum security requirements and the user accepts this policy.
- Devices accessing company data must have a screen lock, a supported operating system and current security updates.
- Company data on mobile and personal devices should be contained within managed apps or profiles where possible.
- Company data must not be stored in unapproved personal cloud accounts or applications.
- The company must be able to remotely remove company data, or the managed work profile, from a device that is lost, stolen or belongs to a leaver.
- Jailbroken or rooted devices must not access company data.
- Lost or stolen devices must be reported immediately.
- Users must not disable required security controls on devices used for work.

4. Roles and responsibilities
- The [IT Manager] defines minimum device requirements and manages enrolment.
- IT administers mobile device management and remote wipe capability.
- The [Security Lead] approves exceptions and reviews compliance.
- Users keep their devices compliant and report loss or theft.

5. Procedures
- Define the minimum security baseline for mobile and personal devices.
- Enrol eligible devices in mobile device management or apply managed app controls.
- Require users to accept the policy before access is granted.
- Monitor compliance and restrict access for non-compliant devices.
- Execute selective wipe of company data at offboarding or on loss.

6. Evidence and records
Keep device enrolment and compliance reports, signed user acknowledgements, exception approvals, remote wipe records and lost-device incident tickets.

7. Review cadence
This policy is reviewed at least annually and after changes to device management capability.

Owner: [role]
Version: [x.y]   Approved by: [name/role]   Date: [date]
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md