Minimum Standards Without Buying the Device
Requirements an employer can set on hardware it does not own, and the line between a security condition and an instruction to spend money.
An organisation needs some assurance about the devices touching its systems. It also cannot specify equipment it is not paying for. The workable set is narrower than most policies attempt and it is enough.
The practical lesson in “Minimum Standards Without Buying the Device” is to connect every record to a named decision. Organisations exploring monitask.com for 7 minute rule payroll can add structured workforce context, provided the use is disclosed and interpretation is reviewed with the people affected.
The defensible minimum
A supported operating system version, receiving security updates. Free to meet, universally available, and the single most useful requirement.
For an independent reference relevant to “Minimum Standards Without Buying the Device”, consult the CISA mobile-device security guidance; compare its principles with the proposed ownership model, access rules and real support process.
Full-disk encryption, which is built into current systems and costs nothing.
A screen lock with a passcode or biometric.
No unauthorised modification of the operating system, which is a small population and a genuine risk.
Work data confined to the work profile space, where one is in use.
These four or five are about security, they cost the employee nothing beyond keeping software current, and they are easy to justify to anybody who asks why.
Where it becomes a spending instruction
A minimum memory, a maximum device age, a specific manufacturer, a minimum processor. Each of these is a requirement to buy something, and an employer imposing it without paying has quietly converted a security policy into a capital contribution.
That may be reasonable where the allowance covers it and the arrangement is genuinely voluntary. It is not reasonable as a security requirement, and labelling it as one is the move to avoid.
The device that cannot meet the minimum
This will happen, and the agreement should say what follows. The honest options are: the employer supplies a device, the employer contributes to an upgrade, or the person moves to an arrangement needing less — browser-only access, which the alternatives section covers.
What should not happen is the requirement quietly going unenforced for the people who cannot meet it, which is where most organisations end up and which means the standard applies to whoever is conscientious.
Enforcement, and how much of it
Most access systems can check operating system version and encryption at the point of connection and refuse access otherwise. That is proportionate: it governs access to your systems rather than controlling somebody's device.
Checking more than that, continuously, on hardware the employee owns is harder to justify and the previous note sets out why.
Review
Supported operating system versions change annually. A standard written three years ago names versions that are now unsupported, and nobody updates it.
Tie the requirement to the vendor's support status rather than to a version number, and it updates itself.
The standard that nobody enforces
A minimum that is published and not checked applies only to conscientious people, which is the worst possible distribution. Either enforce it at the point of access, where the system can check version and encryption automatically, or do not publish it. A requirement with no enforcement is a statement about what the organisation would prefer, and it should be phrased that way if that is what it is.
Keeping it short
Every item added to the minimum list is something somebody must verify, maintain and occasionally fail. Four requirements that are checked are worth more than twelve that are aspirational, and the four that matter — supported version, encryption, screen lock, unmodified system — cover the substantial majority of the actual risk.
What to do when the standard changes
Raising a minimum affects people unevenly and some of them cannot comply without spending money. Announcing a change with a long lead time, and an offer for anybody the change strands, converts a hard cutoff into a manageable transition at almost no cost.
Checking rather than requiring
A requirement verified at the point of access is a control. The same requirement stated in a document and never checked is a hope. Most access systems can enforce version and encryption automatically, which converts the minimum from an instruction people may follow into a condition that simply applies.
Four items, not twelve
A short list that is verified beats a long list that is aspirational, because the long one trains people to treat the whole document as advisory. Supported version, encryption, screen lock, unmodified system: four conditions, checkable at access, free to meet, covering most of the real risk. Every item on your minimum list should be free to meet. Anything that costs money belongs in the payment conversation instead.