Access Control

BYOD Policy

A bring your own device policy template defining the conditions under which personally owned devices may access organisational data, covering enrolment, minimum security requirements, separation of personal and corporate data, and remote wipe, aligned to ISO 27001, NIST SP 800-53 and GDPR.

14-18 pages|Updated 2026-09-11|4 frameworks

What's Included

1. Purpose & Scope

Defines the objective and which devices, users and data classes are covered.

Policy ObjectiveEligible DevicesEligible UsersData Classes Permitted

2. Conditions of Use

Sets what the user agrees to in exchange for access.

User AgreementAcceptable UseProhibited ActivitiesSupport Boundaries

3. Minimum Device Security

Defines the technical baseline a device must meet before enrolment.

Screen Lock and AuthenticationDevice EncryptionOperating System CurrencyJailbreak and Root Prohibition

4. Enrolment & Management

Governs how devices are enrolled and what the organisation can and cannot see.

Enrolment ProcessManagement Profile ScopePrivacy BoundariesDeprovisioning

5. Data Separation

Keeps organisational data separable from personal data on the same device.

ContainerisationApproved ApplicationsProhibited Storage LocationsCopy and Paste Restrictions

6. Loss, Theft & Remote Wipe

Defines the response when a personal device holding company data is lost.

Reporting ObligationSelective WipeFull Wipe ConditionsUser Notification

7. Exit & Review

Handles departure and periodic reassessment.

Offboarding WipeDevice ReplacementAnnual Policy Review

Frequently Asked Questions

What should a byod policy include?

A comprehensive byod policy should include purpose & scope, conditions of use, minimum device security, enrolment & management, and more. This template covers 7 key sections aligned to ISO 27001, NIST SP 800-53, GDPR, SOC 2 requirements.

Which frameworks require a access control policy?

Major frameworks requiring access control policies include ISO 27001, NIST SP 800-53, GDPR, SOC 2. This template maps directly to their control requirements, making it easier to demonstrate compliance across multiple standards.

How often should a byod policy be reviewed?

Best practice is to review your byod policy at least annually, or whenever significant changes occur in your organisation, technology environment, or regulatory landscape. Most frameworks including ISO 27001 and NIST CSF require documented policy review cycles.

Build Your Compliance Programme

Pair this policy template with our compliance platform to map controls across 686+ frameworks, run self-assessments, and get AI-powered compliance advisory.

Get Started Free →

Free forever — no credit card required