Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Operations Manager

previous version on gdrive

A.8.1 User end point devices

Control Objective

Information stored on, processed by or accessible via user end point devices shall be protected.

Policy Statement

anDREa implements robust physical and logical controls to protect information accessed by or stored on all user endpoint devices. Given our remote-first operational structure, endpoint defense serves as a primary boundary for protecting the myDRE ecosystem. Security integrity is maintained across both company-issued and approved personal hardware through unified configuration profiles and mandatory compliance attestation.


Endpoint Protection Framework

The operational and technical controls required to secure user endpoints are fully integrated into A.06.07: Remote Working and A.7: Physical Controls, encompassing the following domains:

  • Hardware Governance: Explicit acceptable-use parameters for both corporate-provisioned endpoints and Bring-Your-Own-Device (BYOD) hardware.
  • Identity & Access Security: Mandatory deployment of multi-factor authentication (MFA), role-based privilege restrictions, and manual/automated inactivity locks (see A.07.07: Clear Desk and Clear Screen).
  • Cryptographic Safeguards: Enforced full-disk encryption (BitLocker, FileVault, or ChromeOS native encryption) across all production-touching devices.
  • Threat Mitigation: Continuous execution of industry-accepted anti-malware and antivirus solutions.
  • Patch Management: Timely application of software security updates, with critical vendor patches mandatorily deployed within 72 hours.
  • Device Hardening & MDM: Device restriction baselines enforced centrally via Google Endpoint Management.
  • Network Integrity: Compulsory use of secure VPNs (e.g., NordVPN) when operating on unverified or public networks.
  • Remote Wipe Authority: Full administrative capability to execute a remote cryptographic wipe on any compromised, lost, or decommissioned endpoint.
  • Compliance Checks: Continuous automated auditing of device health, configuration baselines, and enrollment status.

Endpoint Inventory & Administration

To maintain an accurate asset posture, anDREa cross-references hardware status using two distinct internal directories:

Inventory TypeScopePlatform / LocationAccess Control
Unified Endpoint MatrixCovers all active corporate-issued hardware AND approved BYOD profiles.Google Admin PortalAuthorized Personnel Only
Corporate Asset LedgerExclusively tracks physical hardware owned and distributed by anDREa.Overview of anDREa-Issued DevicesAuthorized Personnel Only

Personnel Attestation & Awareness

  • Annual Compliance Re-Attestation: All personnel are contractually required to review the endpoint security rules in A.06.07: Remote Working upon onboarding and annually thereafter, providing a formal sign-off confirming compliance.
  • Incident Preparedness: During annual evaluations, employees are explicitly re-trained on A.06.08: Information Security Event Reporting, ensuring they know how to instantly escalate a lost device or technical compromise to meet our regulatory reporting timelines.