infrastructureVersion 1SOC2ISO27001NIST800-171
Endpoint Security Policy
Baseline controls for laptops and mobile devices that process Rex Black data.
Download PDFSHA-256 36a635d139c91046…
Endpoint Security Policy
1. Purpose
Establishes baseline controls for every laptop, desktop, and mobile device that processes Rex Black data.
2. Device classes
| Class | Usage |
|---|---|
| Managed | Rex Black-issued laptop; MDM-enrolled. |
| BYOD approved | Personally owned laptop enrolled in MDM. |
| Mobile | Personally owned phone / tablet with minimal work access (email, MFA). |
| Unmanaged | Prohibited for Rex Black work. |
3. Baseline controls (Managed / BYOD laptops)
- Full-disk encryption: FileVault (macOS) or BitLocker (Windows) enabled. Recovery keys escrowed in MDM.
- Screen lock: automatic within 15 minutes of idle; password required on wake.
- OS version: current major release; security updates applied within 14 days of release (7 days for Critical-rated fixes).
- EDR: Rex Black-approved endpoint detection agent installed and reporting.
- Firewall: host firewall enabled; no unneeded inbound ports.
- No local admin for routine use; elevate only when needed.
- Password manager / Vault is the approved secret store; no plaintext credential files.
- Backups: for local-only artifacts: encrypted backup to an approved location. For work artifacts: stored in approved cloud (Google Drive, Rex Black systems) not laptop-only.
- Prohibited software: cracked software, unsanctioned remote access tools, unapproved VPNs, crypto miners.
4. Mobile devices
- Screen lock with ≥ 6-digit PIN or biometric.
- OS up to date with security patches; unsupported OS versions not allowed to access Rex Black email.
- Remote-wipe capability enabled (iOS Find My / Google Find Device or MDM).
- No storing of Confidential or Restricted data on the phone.
5. Browser hygiene
- Use a currently supported browser (Chrome / Edge / Safari / Firefox).
- Extensions are limited to an approved list; personal browsing extensions are not installed on work profiles.
- Work browser profile separate from personal browsing where possible.
6. BYOD conditions
- The Rex Black MDM profile can enforce encryption, passcode, remote wipe of work data (selective wipe), and software inventory visibility; it does not access personal files, photos, or messages.
- Personnel may revoke enrollment at any time by surrendering Rex Black data access.
7. Theft / loss
- Reported to
security@rexblack.comimmediately (phone tree if after-hours). - MDM remote-wipe executed.
- All credentials on the device rotated.
- Incident logged and learned-from.
8. Roles & responsibilities
| Role | Responsibility |
|---|---|
| Security Officer | Baseline management; MDM; approved software list. |
| All personnel | Maintain compliant devices; report incidents. |
9. References
014-remote-work-policy.md015-physical-security-policy.md018-vulnerability-management-policy.md
10. Revision history
| Version | Date | Author | Approver | Change |
|---|---|---|---|---|
| 1.0 | 2026-04-17 | S.O. | CEO | Initial policy |
Approval
This policy has been reviewed and is hereby approved for the named version and effective date above.
| Approved by | Myles Bai |
| Title | Chief Executive Officer, Rex Black LLC |
| myles@rexblack.com | |
| Approval date | 2026-04-17 |
| Effective date | 2026-04-17 |
| Next review due | 2027-04-17 |
Digital signature of record: the CEO's electronic approval is captured
in the platform audit log (event kind admin.policy.approved) with
hash-chained integrity under the M-C1 control. The hash-chained audit
log entry for this document is the canonical signature of record; this
printed block exists for print/review convenience.