Skip to content

Bring Your Own Device Policy

Bring your own device Policy

Version history

Version Number Date Description Created By Approved By
0.1 17/Apr/2024 Initial Copy [Name]
0.2 18/Jun/2024 Approved [Name] [Name]
0.3 28/Aug/2026 Knowledge kernel, AI/agents, control alignment Knowledge steward [Name]

Scope

This Policy applies to employees who use a personal mobile device including any accompanying software or hardware (referred to as a “Device” in this Policy) for business purposes. It applies to use of the device both during and outside office hours and whether use of the device takes place at your normal place of work and office hours.

This Policy applies to all devices used to access our IT resources and communications systems (collectively referred to as “Systems” in this Policy), which may include (but are not limited to) smartphones, mobile or cellular phones, PDAs, tablets, and laptop or notebook computers.

Policy Statement

This Policy authorizes an employee to use a personal mobile device for specific business purposes and builds use-cases to identify functions for which the employee will need the device. Anyone covered by this Policy may use a personal mobile device for business purposes if they accept/acknowledge the declaration at the end of this Policy and adhere to its terms. By signing the declaration hereunder, the users acknowledge and understand that maintaining the security, confidentiality, integrity, and availability of information. The user is expected to read this Policy, understand risks, and abide by the guidelines when using consumer devices. It is at employee’s sole discretion to choose to use her/his personal mobile device for business purposes. By signing the declaration, the employee voluntarily accepts and consents to follow the Policy.

Objectives

The objective to implement Bring Your Own Device to Work Policy (“Policy”) is to ensure the establishment and maintenance of appropriate precautionary measures (both technical and process) for the security of our IT resources and communications systems, protection of our confidential and proprietary information and reputation, and compliance with legal obligations.

Roles and Responsibilities

The CTO is responsible for all aspects of the implementation and management of this procedure unless noted otherwise.

Top Management is responsible for the implementation of this policy, within the scope of their responsibilities, and must ensure that all staff under their control understand and undertake their responsibilities accordingly.

BYOD Policy

General

  • tecciance remains committed to enabling staff to do their jobs as efficiently as possible using technology.

  • This policy sets out requirements for the use of personally owned smartphones and/or tablets or Laptops by staff to access tecciance’s information, resources, and/or services.

  • We respect the privacy of your personal device and will only request access to the device by technicians to implement security controls if needed or to respond to legitimate discovery requests arising out of administrative, civil, or criminal proceedings. This differs from our policy for the

  • Equipment and/or services we provide, for which staff do not have the right, nor should they expect, of privacy while using our equipment and/or services.

  • This policy is intended to protect the security and integrity of our data and technology infrastructure. Limited exceptions to the policy may be authorized by the CTO due to variations in devices and platforms.

Policy

  • BYOD registered devices are subject to all our information security-related policies and procedures.

  • This policy is in addition to and should be read alongside our Acceptable Use of assets and Mobile computing and Teleworking security.

Approval, registration, and support of devices

  • The following devices are supported:

  • Laptop – All Models but models should not be older than 2015.

  • iPad- All Models but models should not be older than 2015.

  • Connectivity issues are supported by IT Services - employees should contact the device manufacturer or their carrier for the operating system or hardware-related issues.

Acceptable use of registered devices

  • Acceptable business uses are those activities that directly or indirectly support our business.

  • Acceptable personal use during the working day is limited to reasonable personal communication or recreation.

  • Staff are not permitted to access certain categories of websites during work hours/while connected to the corporate network at our discretion.

  • Such websites categories include, but are not limited to –

  • Adult and Pornography, Bot Nets, Confirmed SPAM Sources, Gambling, Key loggers and Monitoring, Marijuana, Nudity, Peer to Peer, Phishing and Other Frauds, Spyware, and adware.

  • Staff/employees shall not record audio or video while on-site.

  • Any apps that are not downloaded through iTunes or Google Play store are not permitted

  • Device must not be used at any time to

  • Store or transmit illicit materials.

  • Store or transmit proprietary information harass others.

  • Engage in outside business activities.

  • Staff may use their mobile devices to access our assets, such as:

  • Calanders

  • Contacts

  • Documents

  • Texting or emailing while driving is forbidden and even hands-free talking while driving is also not permitted.

Reimbursement by tecciance

  • We will/will not reimburse staff for a percentage of the cost of the device. We will not pay for the phone/data plan, etc.

  • We will/will not reimburse the employee for the following charges: roaming, plan overages, etc.

Security

  • To prevent unauthorized access, registered devices must be password protected in accordance with our Password Policy organization wide.

  • The registered device must lock itself with a password or PIN if it is idle for five minutes or ten minutes.

  • After five failed attempts to enter a password, the device will be automatically locked – take the device to the IT Service Desk to have it unlocked.

  • Rooted (Android) or jailbroken (iOS) devices are forbidden.

  • Smartphones and tablets that are not on the company’s list of supported devices are not permitted to connect to our ICT systems.

  • Smartphones and tablets belonging to staff that are for personal use only are not permitted to connect to our ICT systems.

  • Staff access to our information is automatically limited as set out in our Access Control Staff must take all reasonable steps to prevent the theft or loss of registered devices.

  • Staff access to our information is automatically limited as set out in our access control staff must take all reasonable steps to prevent the theft or loss of registered devices.

  • Staff are expected to maintain the registered device themselves and to ensure that its systems are regularly updated and patched.

  • Staff are expected to be aware of, and comply with, any regulatory or other requirements regarding the handling of personal data.

  • Lost or stolen devices must be reported to the IT Services as soon as is practicable and in every case within 24 hours.

  • Staff are responsible for notifying their mobile carrier immediately upon loss of a registered device. A registered device may be remotely wiped if:

  • The device is lost or stolen.

  • The person cases to be a member of the staff IT services detect o data or policy breach.

  • IT services detect a virus or similar threat to the security of our information or technology infrastructure.

Risks, Liabilities, and Disclaimers

  • While IT Services will take every precaution to prevent any personal data from being lost if a registered device must be remotely wiped, all staff are responsible for taking additional precautions, such as backing up email, contacts, etc.

  • We reserve the right to disconnect registered devices or disable services without notification.

  • Staff are expected to always use their registered devices in an ethical manner and to adhere to our Acceptable Use of Assets

Breaches of policy

tecciance will take all necessary measures to remedy any breach of this policy including the use of our disciplinary or contractual processes where appropriate.

Terms and Definitions

  • “Registered devices” are those personal devices approved by tecciance for use in accordance with this policy.

  • “Staff” and “users” mean all of those who work under our control, including employees, contractors, Interns, etc.

  • “We” and “our” refer to tecciance.