Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Business Manager

previous version on gdrive

Acceptable Use of Hardware & Internet Policy

This policy defines the acceptable use of company-provided hardware and internet resources across anDREa B.V. (anDREa). Operating under a fully remote model, this framework enforces information security baselines satisfying ISO/IEC 27001:2023 (A.07.08, A.07.09, A.08.01) and NIS 2 parameters while ensuring structural alignment with Dutch legal standards, including the Working Conditions Act (Arbowet) and mandatory Risk Inventory and Evaluation (RI&E) protocols.

This policy undergoes mandatory evaluation and re-validation annually or immediately following significant operational changes.


1. Device Enrollment & Mobile Device Management (MDM)

To guarantee clear administrative control over all distributed endpoints, anDREa enforces absolute endpoint oversight:

  • Automated Chrome OS Provisioning: All company-provided Chrome OS devices are systematically pre-enrolled into the Google Mobile Device Management (MDM) plane directly via hardware identifiers.
  • Windows Laptop Enrolment: Any company-provided Windows workstation must be manually enrolled into the corporate Google MDM environment immediately upon allocation.

2. Bring Your Own Device (BYOD) Governance

By default, anDREa provides managed corporate hardware for all operational duties and does not require or expect employees to utilize personal equipment.

warning

BYOD Pre-Approval Requirement: Any utilize of a privately owned laptop or desktop to access anDREa systems, directories, or cloud data pools is strictly prohibited unless explicitly approved in writing by the Management Team.

If a BYOD exception is authorized, the employee must strictly adhere to the following security controls:

  1. Isolated Profile: The device must be used exclusively via a dedicated, MDM-managed corporate work account.
  2. Patch Discipline: The user must guarantee an up-to-date operating system, immediate security patch application, and active corporate endpoint protection.
  3. Authentication Floor: Access must be gated via strong passwords, Multi-Factor Authentication (MFA), and mandatory hardware keys.
  4. Physical Quarantine: The device must be locked against access by household members or external third parties.
  5. Immediate Incident Route: Any device loss, physical theft, credential compromise, or suspicious telemetry behavior must be reported immediately to security@andrea-cloud.com.

anDREa retains the absolute right to remotely wipe devices enrolled with @andrea-cloud.com, corporate data repositories, push restrictive security scripts, or revoke BYOD privileges instantly to safeguard its intellectual properties.


3. Acceptable & Personal Use Parameters

Authorized Business Conduct

  • Leverage company-provided hardware primarily for authorized business objectives supporting anDREa.
  • Maintain the absolute integrity, confidentiality, and security of all data blocks stored or accessed via endpoints.
  • Install and execute only software applications explicitly authorized by anDREa management. The injection of unapproved third-party code or tools is strictly blocked.
  • Promptly execute all operating system updates, browser updates, and security patches.
  • Route any technical anomalies or suspected hardware losses immediately to security@andrea-cloud.com.

Personal Use Boundary

Personal utilization of company-managed hardware is highly discouraged. If personal use becomes necessary, it must follow strict technical containment rules:


┌────────────────────────────────────────────────────────────────────────┐
│                        HARDWARE CONTAINERIZATION                       │
├────────────────────────────────────────┬───────────────────────────────┤
│ 💼 Primary Work Profile                │ 👥 Dedicated Guest Account    │
├────────────────────────────────────────┼───────────────────────────────┤
│ Exclusively for authorized business    │ Temporary, isolated container │
│ activities and corporate data flows.   │ for minimal personal tasks.   │
└────────────────────────────────────────┴───────────────────────────────┘

  • Personal tasks must never occur within the primary corporate account profile. They must be executed exclusively inside the isolated device Guest Account.
  • Personal surfing must never degrade device performance or introduce risk.
  • Absolute Prohibitions: Accessing, viewing, or downloading illegal, offensive, or inappropriate content; engaging in peer-to-peer sharing, or installing unverified packages that threaten the perimeter.

4. Remote Connectivity & Physical Security

Home Network Safeguards

Because anDREa operates as a fully remote enterprise, employees are directly responsible for securing their home network perimeter. This requires enforcing strong, complex WPA3/WPA2 Wi-Fi passwords, disabling administrative remote management interfaces, and keeping home router firmware updated.

Public Wireless Protocols & VPN Enforcement

When working outside a secure private residence, connecting to public, unencrypted, or shared Wi-Fi networks (e.g., cafes, trains, libraries, hotels) requires mandatory encrypted encapsulation.

  • NordVPN Requirement: Users must activate corporate NordVPN connections immediately upon connecting to a public network. No company asset, email, or database may be queried until traffic is safely routed through an active VPN tunnel.
  • Provisioning: VPN access profiles are managed on-demand by the Operations Manager.

Physical Security in Public Spaces

  • Zero-Attendance Rule: Never leave an active laptop or corporate device unattended in a public area for any duration.
  • Session Locking: Instantly execute a manual screen lock the moment you step away from the keyboard.
  • Visual Privacy: The utilization of micro-louver physical privacy screens for both laptops and mobile phones is highly recommended to block visual eavesdropping. Costs for privacy filters are fully reimbursable following supervisor authorization under the Reimbursement & Declaration Policy.

5. Privileged Utilities & Compliance Enforcement

  • High-Privilege Tools: Specialized utility programs capable of overriding baseline system controls or modifying global Azure SaaS rules are heavily restricted. Their use is governed strictly under the Use of Privilieged Uitity Programs to ensure strict log auditing.
  • Compliance Monitoring: anDREa reserves the right to execute proportionate, transparent monitoring of all corporate hardware assets to audit policy alignment, within the statutory boundaries of applicable privacy legislation.
  • Sanctions: Documented violations of this framework will trigger immediate disciplinary pathways, up to and including formal termination of employment, contract cancellation, and direct legal prosecution.
  • Onboarding Execution: Reviewing and executing the formal Equipment & Acceptable Use Agreement t or the *Hardwary Key Receipt & Use Declaration is a mandatory condition of employment. Upon offboarding, all hardware must be returned in good working order; anDREa will invoke remote wipe protocols to clean devices if physical return paths are delayed.