Device Management Policy¶
Purpose. Soon is fully remote: laptops (and phones used for work accounts) are the entire "estate". This policy sets the security baseline every such device must meet. Absorbs the former BYOD Policy.
1. Scope¶
Every device — company-provided or personal (BYOD) — used to access Soon systems or data. Applies to all personnel.
2. Policy¶
2.1 Baseline for all devices¶
Every device accessing Soon data must have:
- Full-disk encryption enabled (FileVault / BitLocker / native mobile encryption).
- A screen lock with password/PIN/biometric, engaging automatically.
- OS and browser auto-updates enabled.
- MFA enabled on all Soon accounts used from the device.
- Endpoint protection per the Endpoint Protection Policy.
2.2 Management and remote wipe¶
- Company devices must be enrolled in central management. No MDM is deployed, by documented decision — see the Device Security Standard §1.1, which records the rationale, the compensating controls and the triggers to adopt one.
- It must be possible to remotely wipe Soon data from any device (device-level wipe via MDM, or at minimum remote account revocation and cloud data removal).
2.3 Loss or theft¶
- Loss or theft of any device with access to Soon data must be reported immediately per the Information Security Event Reporting Procedure, so accounts can be revoked and the device wiped.
2.4 BYOD¶
Personal devices may be used for work only if:
- All controls in 2.1 are applied and the user confirms this at onboarding.
- The user accepts that Soon may require removal/wipe of work data (work accounts, cached data) — including at offboarding, which must include verified removal of Soon data from personal devices.
- Privacy boundary: Soon manages and may wipe work data only; personal data, apps, and accounts on a BYOD device remain the user's own and are not monitored by Soon.
3. Roles & responsibilities¶
- All personnel: keep their devices compliant with 2.1; report loss/theft immediately.
- Security responsible: maintains enrolment/verification, executes wipes, runs the offboarding device step.
4. Related documents¶
- Endpoint Protection Policy
- Remote Working Policy
- Information Security Event Reporting Procedure
- Employee Termination and Change of Employment Checklist
Change log¶
| Version | Date | Author | Comments |
|---|---|---|---|
| 0.1 | 2023-10-23 | Olaf Jacobson | First draft document |
| 0.2 | 2026-07-18 | Andrea Cardinali | Rewritten lean and Soon-specific (ISMS overhaul); absorbs the BYOD Policy |