Data outside the office.
WHAT THE EXPOSURE IS
Personal data on devices you do not control.
WHERE IT ACCUMULATES
Email on phones Downloaded attachments Screenshots Messaging conversations Local copies of spreadsheets
WHAT TO ESTABLISH
Whether personal devices may be used at all.
WHAT PERMITTING THEM REQUIRES
A policy Minimum security requirements The ability to remove access Agreement from staff
WHAT MINIMUM REQUIREMENTS USUALLY INCLUDE
A device passcode Encryption Current operating system No shared use
WHAT TO AVOID REQUIRING
Full control of a personal device.
WHY
It is intrusive, resisted, and creates its own obligations.
WHAT TO PREFER
Access through systems rather than local copies.
WHAT THAT MEANS
Working in a browser, not downloading.
WHAT TO PROVIDE
Approved tools that meet the need.
WHY
Prohibition without an alternative produces unmonitored workarounds.
WHAT TO DO WHEN SOMEONE LEAVES
Remove access, and confirm local data is deleted.
WHAT TO DO ABOUT A LOST DEVICE
Treat it as a potential breach, and assess.
WHAT TO TRAIN ON
Public networks Screens visible to others Messaging used for work data