This template sets ground rules for employees who use personal devices to access company systems and data.
1. Purpose
This policy establishes requirements for employees who use personal devices (“BYOD”) to access [Organization Name] systems and data.
2. Eligibility
BYOD access is available to [eligible roles] upon enrollment in the organization’s mobile device management (MDM) solution.
3. Enrollment Requirements
Before accessing organizational data, personal devices must be enrolled in [MDM tool], which enforces [minimum OS version, passcode requirement, encryption].
4. Data Separation
Organizational data must be accessed only through approved, containerized applications that keep work data separate from personal data on the device.
5. Prohibited Actions
- Storing Confidential or Restricted data (per the Data Classification Policy) directly on the device outside approved containers
- Jailbreaking or rooting an enrolled device
- Sharing an enrolled device with anyone else while work data is accessible
6. Lost or Stolen Devices
Employees must report a lost or stolen enrolled device to [IT/Security contact] immediately, so organizational data can be remotely wiped from the device.
7. Offboarding
Upon termination or program withdrawal, the organization will remotely remove organizational data and applications from the device, without affecting personal data.
8. Monitoring
[Organization Name] may monitor and log access to organizational data and applications on enrolled devices, but does not monitor personal data, apps, or activity outside the managed work container.
Want this built and implemented for your organization?
A template is a starting point. Cyberix builds, customizes, and maintains policies like this as part of a full GRC engagement.
