HLD Group
Mobile device & BYOD policy
MDM, encryption, and acceptable use for mobile endpoints.
Last updated: 24 July 2026
Version 1.0 · Review cycle: 365 days · View all frameworks
1. Purpose
This policy defines how mobile devices — smartphones, tablets, and laptops — are secured when used to access HLD Group systems or data, including both company-owned and, where permitted, personal devices under a bring-your-own-device arrangement.
2. Scope
This policy applies to all mobile devices used to access company or customer data, and to the personnel who use them.
3. Definitions
- Mobile device management (MDM) — tooling that enforces security configuration on devices
- Bring your own device (BYOD) — the use of a personally owned device for work
- Containerisation — separating and protecting work data from personal data on a device
- Remote wipe — the ability to erase company data from a lost or compromised device
4. Device enrolment and configuration
- Devices accessing company data are enrolled in management and meet a security baseline
- Device encryption, screen lock, and strong authentication are enforced
- Operating systems and apps are kept current, and jailbroken or rooted devices are blocked
- Only approved applications access company data, and app permissions are managed
5. Data protection and separation
- Company data is protected and, on personal devices, separated from personal data through containerisation
- Company data is not copied to unmanaged apps or personal cloud storage
- Data loss prevention controls apply to sharing and transfer where supported
6. Lost, stolen, and retired devices
Lost or stolen devices are reported immediately and handled as a potential incident, and company data is remotely wiped. On personal devices, wipe is limited to the company container where technically possible, respecting the individual’s personal data. Devices are sanitised before reuse or disposal under the Asset Management Policy.
7. Privacy in BYOD
Where personal devices are used for work, HLD Group limits its management to what is necessary to protect company data and is transparent about what is and is not visible to the organisation. Personal data and activity on the device are not monitored.
8. Framework alignment
- ISO/IEC 27001:2022 Annex A control 8.1 (user endpoint devices) and 6.7 (remote working)
- NIST SP 800-124 (managing the security of mobile devices)
- NIST SP 800-53 Rev. 5 control AC-19 (access control for mobile devices)
- SOC 2 Trust Services Criteria CC6.6 and CC6.7
9. Roles, exceptions, and review
IT and security own mobile device security under the CISO. Exceptions require documented CISO approval with compensating controls and an expiry date. This policy is reviewed at least annually.
Related frameworks
For contractual attestations or audit packs, contact [email protected].