Endpoint Security and Hardening Policy
Document control
| Field | Value |
|---|---|
| Document status | Active policy document |
| Owner | Security / Operations |
| Approver | Management |
| Review frequency | Annual or on material change |
| Classification | Customer-shareable |
Purpose
Protect laptops, workstations, servers, containers, and other endpoints that access or process company or customer data.
Baseline controls
Managed endpoints should use screen lock, operating system updates, anti-malware/security tooling where applicable, disk encryption where supported, least-privilege user accounts, and secure configuration.
Developer endpoints
Developer machines must protect SSH keys, API tokens, credentials, repositories, customer files, and local databases. Customer data must not be stored in unmanaged folders longer than required.
Server and container hardening
Servers and containers should use minimal packages, patched base images, restricted network exposure, externalized secrets, non-root execution where feasible, and logging/monitoring.
Portable media and BYOD
Use of portable media or unmanaged personal devices for sensitive data should be restricted. Exceptions require approval and compensating controls.
Review and exceptions
Endpoint compliance should be reviewed periodically. Exceptions must document reason, owner, compensating controls, and review date.
Evidence to maintain
Endpoint compliance report, antivirus/security tooling status, patch status, hardening checklist, device inventory, and exception register.