Skip to main content

infrastructureVersion 1SOC2ISO27001NIST800-171

Endpoint Security Policy

Baseline controls for laptops and mobile devices that process Rex Black data.

Download PDFSHA-256 36a635d139c91046…

Endpoint Security Policy

1. Purpose

Establishes baseline controls for every laptop, desktop, and mobile device that processes Rex Black data.

2. Device classes

Class Usage
Managed Rex Black-issued laptop; MDM-enrolled.
BYOD approved Personally owned laptop enrolled in MDM.
Mobile Personally owned phone / tablet with minimal work access (email, MFA).
Unmanaged Prohibited for Rex Black work.

3. Baseline controls (Managed / BYOD laptops)

  1. Full-disk encryption: FileVault (macOS) or BitLocker (Windows) enabled. Recovery keys escrowed in MDM.
  2. Screen lock: automatic within 15 minutes of idle; password required on wake.
  3. OS version: current major release; security updates applied within 14 days of release (7 days for Critical-rated fixes).
  4. EDR: Rex Black-approved endpoint detection agent installed and reporting.
  5. Firewall: host firewall enabled; no unneeded inbound ports.
  6. No local admin for routine use; elevate only when needed.
  7. Password manager / Vault is the approved secret store; no plaintext credential files.
  8. Backups: for local-only artifacts: encrypted backup to an approved location. For work artifacts: stored in approved cloud (Google Drive, Rex Black systems) not laptop-only.
  9. Prohibited software: cracked software, unsanctioned remote access tools, unapproved VPNs, crypto miners.

4. Mobile devices

  1. Screen lock with ≥ 6-digit PIN or biometric.
  2. OS up to date with security patches; unsupported OS versions not allowed to access Rex Black email.
  3. Remote-wipe capability enabled (iOS Find My / Google Find Device or MDM).
  4. No storing of Confidential or Restricted data on the phone.

5. Browser hygiene

  1. Use a currently supported browser (Chrome / Edge / Safari / Firefox).
  2. Extensions are limited to an approved list; personal browsing extensions are not installed on work profiles.
  3. Work browser profile separate from personal browsing where possible.

6. BYOD conditions

  1. The Rex Black MDM profile can enforce encryption, passcode, remote wipe of work data (selective wipe), and software inventory visibility; it does not access personal files, photos, or messages.
  2. Personnel may revoke enrollment at any time by surrendering Rex Black data access.

7. Theft / loss

  1. Reported to security@rexblack.com immediately (phone tree if after-hours).
  2. MDM remote-wipe executed.
  3. All credentials on the device rotated.
  4. Incident logged and learned-from.

8. Roles & responsibilities

Role Responsibility
Security Officer Baseline management; MDM; approved software list.
All personnel Maintain compliant devices; report incidents.

9. References

  • 014-remote-work-policy.md
  • 015-physical-security-policy.md
  • 018-vulnerability-management-policy.md

10. Revision history

Version Date Author Approver Change
1.0 2026-04-17 S.O. CEO Initial policy

Approval

This policy has been reviewed and is hereby approved for the named version and effective date above.

Approved by Myles Bai
Title Chief Executive Officer, Rex Black LLC
Email myles@rexblack.com
Approval date 2026-04-17
Effective date 2026-04-17
Next review due 2027-04-17

Digital signature of record: the CEO's electronic approval is captured in the platform audit log (event kind admin.policy.approved) with hash-chained integrity under the M-C1 control. The hash-chained audit log entry for this document is the canonical signature of record; this printed block exists for print/review convenience.

← Back to the trust center