People & Physical Policy
Mobile Device Policy
Define requirements for mobile devices that access company information.
Summary
Policy overview
Scope
Phones and tablets used for company email, authentication, or collaboration.
Objectives
- Require device lock and encryption
- Require prompt operating system updates
- Enable remote wipe capability where supported
- Restrict data storage on mobile devices
What the policy covers
- Device passcode and encryption are required.
- Operating systems are kept current.
- Lost or stolen devices are reported immediately.
- Customer data is not stored locally on mobile devices.
Governance
Reviewed alongside remote work and access control policies.
Framework references
- NIST SP 800-124
- CIS Controls 4
These are public governance summaries. Full policy text, operational procedures, runbooks, and configuration standards are not published and are provided under NDA or contract where a review requires them.
Related
More People & Physical policies
Remote Work Policy
Define security expectations for work performed outside company-controlled locations.
Personnel Security Policy
Manage security risk associated with personnel throughout employment.
Physical Security Policy
Protect equipment and information in physical work environments.
IEP ALLY APP LLC does not hold FedRAMP authorization, SOC 2 attestation, ISO 27001 certification, or CMMC certification. Framework references describe familiarity and practice alignment only. They do not represent certification, authorization, endorsement, audit, or verified compliance status.
Requesting security documentation?
Contracting officers, prime contractors, integrators, and auditors can request review materials through our secure documentation workflow.