Skip to content

Device Management Policy

Purpose. Soon is fully remote: laptops (and phones used for work accounts) are the entire "estate". This policy sets the security baseline every such device must meet. Absorbs the former BYOD Policy.

1. Scope

Every device — company-provided or personal (BYOD) — used to access Soon systems or data. Applies to all personnel.

2. Policy

2.1 Baseline for all devices

Every device accessing Soon data must have:

  • Full-disk encryption enabled (FileVault / BitLocker / native mobile encryption).
  • A screen lock with password/PIN/biometric, engaging automatically.
  • OS and browser auto-updates enabled.
  • MFA enabled on all Soon accounts used from the device.
  • Endpoint protection per the Endpoint Protection Policy.

2.2 Management and remote wipe

  • Company devices must be enrolled in central management. No MDM is deployed, by documented decision — see the Device Security Standard §1.1, which records the rationale, the compensating controls and the triggers to adopt one.
  • It must be possible to remotely wipe Soon data from any device (device-level wipe via MDM, or at minimum remote account revocation and cloud data removal).

2.3 Loss or theft

  • Loss or theft of any device with access to Soon data must be reported immediately per the Information Security Event Reporting Procedure, so accounts can be revoked and the device wiped.

2.4 BYOD

Personal devices may be used for work only if:

  • All controls in 2.1 are applied and the user confirms this at onboarding.
  • The user accepts that Soon may require removal/wipe of work data (work accounts, cached data) — including at offboarding, which must include verified removal of Soon data from personal devices.
  • Privacy boundary: Soon manages and may wipe work data only; personal data, apps, and accounts on a BYOD device remain the user's own and are not monitored by Soon.

3. Roles & responsibilities

  • All personnel: keep their devices compliant with 2.1; report loss/theft immediately.
  • Security responsible: maintains enrolment/verification, executes wipes, runs the offboarding device step.

Change log

Version Date Author Comments
0.1 2023-10-23 Olaf Jacobson First draft document
0.2 2026-07-18 Andrea Cardinali Rewritten lean and Soon-specific (ISMS overhaul); absorbs the BYOD Policy