Endpoint and Workstation Security Policy template (SOC 2)
Establishes the baseline configuration, protection and lifecycle requirements for every laptop, desktop and mobile device used to access company systems.
Policy P19 of 22 · Owner: IT/Operations Lead · 3 criteria in the crosswalk · Apache-2.0
What this policy is for
The Endpoint and Workstation Security Policy is one of the 22 governance policies in the Policyseed set. It is owned by the IT/Operations Lead, approved by the executive you name in the intake, and reviewed on the cadence you choose. Like every policy in the set it has nine numbered sections: purpose, scope, roles, policy statements, procedures, exceptions, enforcement, review cadence and a revision history table. Sections 4 and 5 carry the substance; those are the sections the Audit Kit rewrites for your named tools.
SOC 2 criteria this policy addresses
The Policyseed crosswalk maps 3 criteria to this policy. Each row names the section an auditor would read for that criterion; the criterion pages explain what it asks in plain words and list evidence examples.
| Criterion | What it covers | Where in this policy |
|---|---|---|
| CC6.6 | Protection from external threats | Section 4 (Policy Statements) |
| CC6.7 | Data in transit and on removable media | Section 4 (Policy Statements) |
| CC6.8 | Malicious software | Section 4 (Policy Statements) |
Evidence auditors typically ask for
A policy is tested against artifacts. These are examples from the crosswalk for the criteria above, written for a small SaaS company; the Audit Kit ships the full list as an evidence checklist with an owner per row.
- Cloud security group or firewall rule export for production showing no unrestricted inbound admin ports
- WAF or edge protection configuration screenshot
- MFA enforcement screenshot for the identity provider, source control organization and cloud console
- MDM compliance report showing disk encryption and firewall enabled on all managed devices
- TLS configuration scan result for public endpoints (for example an SSL Labs report) showing TLS 1.2 or higher only
- Data handling matrix from the Data Classification Policy listing approved sharing channels per classification
- MDM policy screenshot restricting USB storage or requiring encrypted external drives
- Endpoint protection or EDR console report showing coverage of all managed devices
Full text: the Endpoint and Workstation Security Policy rendered for Northwind Cloud Inc
Below is the complete template as the generator renders it for Northwind Cloud Inc, a fictional 11-50-person remote company running Northwind on AWS, Vercel, GitHub and Okta. Every name, tool and date comes from that sample intake; your answers replace them. Section headings carry anchors so the criterion pages can link straight to the section they cite.
Sample document
Northwind Cloud Inc Endpoint and Workstation Security Policy
1. Purpose
Laptops and phones are where credentials, source code and customer data are actually handled, and they leave the building every day. This policy defines the minimum security configuration for every device used to access Northwind Cloud Inc systems, how that configuration is enforced and verified, and what happens when a device is lost, replaced or retired. It exists so that a single lost laptop or compromised workstation does not become a breach of Northwind or of its customers' data.
2. Scope
This policy applies to every laptop, desktop, tablet and smartphone (together, "endpoints") used by Northwind Cloud Inc personnel to access company email, GitHub, AWS and Vercel, GitHub Actions, Supabase, Stripe, Datadog and Slack or any system holding Northwind or customer data, whether the device is company-owned or personally owned and approved for work use. It covers procurement, configuration, ongoing protection, verification, loss, reassignment and disposal. Servers, containers and cloud workloads are covered by the Network and Infrastructure Security Policy.
3. Roles and Responsibilities
- Executive Management funds company-managed devices and endpoint tooling and approves this policy; Priya Natarajan, CEO is the approver of record.
- Security Owner (Dana Whitfield, CTO) defines the endpoint baseline, approves exceptions, reviews compliance evidence and leads the response to lost or compromised devices.
- Engineering administers Kandji, maintains the configuration profiles that enforce the baseline, and verifies that developer tooling on endpoints (SSH keys, cloud command-line tools, container runtimes) follows this policy.
- People Operations ties device issue and return to onboarding and offboarding, keeps the device assignment record current and confirms return on the offboarding checklist. The IT/Operations Lead, who owns this policy, maintains the device inventory.
- All Personnel use only approved devices for work, keep them configured as this policy requires, do not disable protections, and report loss, theft or suspected compromise to security@northwindcloud.example immediately.
4. Policy Statements
- 4.1 Access to production systems, source code and customer data is permitted only from company-owned endpoints or from personally owned endpoints that have been explicitly approved by the Security Owner and meet every requirement of this section. A personally owned device may not be used for production access unless it is enrolled in Kandji to the same standard as a company device.
- 4.2 Every endpoint is recorded in the device inventory with its serial number, assigned user, operating system and issue date. Kandji is the authoritative inventory for enrolled devices, and the IT/Operations Lead reconciles it with the HR roster quarterly.
- 4.3 Every company endpoint is enrolled in Kandji before it is issued, and enrolment may not be removed by the user. Kandji enforces the configuration in Sections 4.4 to 4.8 and reports compliance to the Security Owner.
- 4.4 Full-disk encryption (FileVault on macOS, BitLocker on Windows, LUKS on Linux and platform encryption on mobile devices) is enabled on every endpoint, with recovery keys escrowed in Kandji rather than held only by the user.
- 4.5 Endpoints lock automatically after no more than 10 minutes of inactivity and require a password, passphrase or biometric to unlock. Login passwords meet the Authentication and Password Policy, and mobile devices require a passcode of at least six digits or a biometric.
- 4.6 Operating system and browser updates install automatically. Security updates rated critical or high are applied within 7 days of release and all other security updates within 30 days. Endpoints running an operating system version that no longer receives security updates may not access company systems.
- 4.7 Every laptop and desktop runs the built-in or company-approved endpoint protection with real-time malware scanning enabled and the host firewall turned on. Alerts from endpoint protection are reviewed by the Security Owner and forwarded to Datadog where the tooling supports it.
- 4.8 Personnel work from a standard user account. Local administrator rights are granted only where a role requires them, are recorded in the device inventory and are reviewed quarterly. Software is installed only from official vendor sources or app stores, and browser extensions with access to page content require Security Owner approval.
- 4.9 All work credentials are stored in 1Password. Browser-native password saving is disabled through Kandji, and credentials may not be written down, stored in plain-text files or kept in chat history.
- 4.10 Customer data and production datasets are not stored on endpoints. Where a task requires a local copy, it is limited to the minimum data needed, kept only for the duration of the task and deleted when the task is complete. Production database dumps, backups and exports are never downloaded to a laptop.
- 4.11 Removable media (USB drives, external disks, SD cards) may not be used to store or move company or customer data; file transfer uses approved cloud storage. Where Kandji supports it, writing to removable media is blocked by policy.
- 4.12 The loss, theft or suspected compromise of any endpoint is reported to security@northwindcloud.example within one hour of discovery, as the Incident Response Policy requires. Lost devices are locked and wiped remotely through Kandji, and the Incident Response Policy applies.
- 4.13 Endpoints are wiped to the manufacturer's secure-erase standard before reassignment, return to a lessor or disposal. Devices that cannot be wiped are physically destroyed through an accredited destruction provider, and a record of the wipe or destruction is retained in the device inventory.
5. Procedures
- 5.1 Procurement and issue. The IT/Operations Lead orders company endpoints from approved suppliers, records the serial number and assigned user in the device inventory, enrols the device in Kandji using automated enrolment so that the baseline profiles apply on first boot, and hands the device over as part of onboarding. Owner: IT/Operations Lead. Timing: before the user's start date, or within one business day of a replacement request.
- 5.2 Baseline maintenance. The Security Owner maintains the written endpoint baseline (encryption, screen lock, update settings, endpoint protection, firewall, account type, blocked software) and reviews it annually. Engineering keeps the Kandji configuration profiles in step with the baseline and tests changes on a pilot group before company-wide rollout. Owner: Security Owner. Cadence: Annual.
- 5.3 Compliance verification. Each month the Security Owner reviews the Kandji compliance report, and any device out of compliance for more than seven days is blocked from company applications until remediated. Results are retained as evidence. Owner: Security Owner. Cadence: monthly.
- 5.4 Patch management. Automatic updates are enabled at issue. Kandji enforces update deadlines, and the Security Owner reviews outstanding updates weekly. Devices that miss a critical update deadline are removed from production access until updated. Owner: Security Owner. Cadence: weekly review.
- 5.5 Lost, stolen or compromised device. On report to security@northwindcloud.example, the responder locks and wipes the device in Kandji, then revokes active sessions in Okta, rotates the user's credentials and any 1Password vault items they could have read, and opens an incident record. The device is marked lost in the inventory and a replacement is issued under Section 5.1. Owner: Security Owner. Timing: containment within four hours of the report.
- 5.6 Administrator rights and software exceptions. Requests for administrator rights or non-standard software are submitted to the Security Owner with a business justification. Approved requests are recorded in the device inventory with an expiry date, and the Security Owner reviews all open grants quarterly. Owner: Security Owner. Cadence: quarterly.
- 5.7 Return and reassignment. On offboarding or replacement, the user returns the device to the IT/Operations Lead, who confirms receipt on the offboarding checklist, triggers a wipe through Kandji, and updates the inventory. Devices are not reassigned until the wipe is recorded. Owner: IT/Operations Lead. Timing: within five business days of return.
- 5.8 Disposal. Devices at end of life are wiped as in Section 5.7 and then recycled or sold through a provider that issues a certificate of data destruction for any device that cannot be verified as wiped. Certificates are filed with the inventory. Owner: IT/Operations Lead. Cadence: as devices reach end of life, with an inventory sweep each year.
- 5.9 Inventory reconciliation. Each quarter the IT/Operations Lead reconciles the device inventory against the HR roster and the Kandji device list, investigates devices with no active owner, and records the outcome. Owner: IT/Operations Lead. Cadence: quarterly.
6. Exceptions
Exceptions (for example, a research workstation that cannot run endpoint protection, or a contractor device that cannot be enrolled in Kandji) must be requested in writing to the Security Owner with the business reason and the compensating controls, and approved by Priya Natarajan, CEO. Approved exceptions are recorded in the exception register with an expiry date no more than 12 months away and are reviewed at each policy review. Disk encryption and screen lock may not be waived for any device that accesses customer data.
7. Enforcement
Devices that do not meet this policy may be blocked from company systems without notice. Personnel who disable protections, use unapproved devices for production access or fail to report a lost device are subject to disciplinary action under the Human Resources Security Policy, up to and including termination of employment or contract. Contractual remedies apply to contractors.
8. Review Cadence
The IT/Operations Lead and the Security Owner review this policy on a annual basis and whenever the device management tooling, operating system mix or working model changes materially. Each review is recorded in Section 9, and changes are communicated to all personnel within 30 days.
9. Revision History
| Version | Date | Description | Approved by |
|---|---|---|---|
| 1.0 | 2026-09-02 | Initial release | Priya Natarajan, CEO |
Frequently asked questions
- Who should own the Endpoint and Workstation Security Policy?
- In the Policyseed template the IT/Operations Lead owns the Endpoint and Workstation Security Policy: they maintain the text, run the procedures in section 5 and hold the evidence those procedures produce. The approver you name in the intake signs it, and section 8 sets the review cadence you choose (annual, semi-annual or quarterly).
- Which SOC 2 criteria does the Endpoint and Workstation Security Policy address?
- 3 criteria in the Policyseed crosswalk: CC6.6 (Protection from external threats), CC6.7 (Data in transit and on removable media) and CC6.8 (Malicious software). Each mapping points at a numbered section of this policy, and the Audit Kit exports the same mapping as an Excel crosswalk with an evidence checklist.
- Is the Endpoint and Workstation Security Policy template free to use?
- Yes. The template is Apache-2.0 licensed and the generator renders it in your browser with your company, stack and owner names filled in; nothing is stored server-side. The Audit Kit ($39 one-time) rewrites sections 4 and 5 for your named tools with Claude and adds Word documents, the crosswalk spreadsheet, acknowledgment forms and a review calendar. Refunds are available within 14 days on request. Policyseed provides governance policy templates, not legal advice; the CPA firm performs the examination.
Policyseed provides governance policy templates and AI tailoring. It is not legal advice and not a compliance guarantee. Management adopts the policies; the CPA firm performs the SOC 2 examination.