Answer yes if your organisation enforces security controls on BYOD endpoint devices to an equivalent standard of the security controls on organisation-issued devices, before access to company data or services is granted. For example, this could be done through the use of containerised MDM or UEM software. In the notes, describe the nature of the controls, the method of enforcement and any related processes. If there is a difference in the level of control between organisation-issed devices and BYOD, describe that in the notes section, including any compensating controls.
If your organisation allows employees to access company data or services using BYOD endpoint devices, those devices must be protected with technical security controls before access is granted. This is typically achieved through a Mobile Device Management (MDM) or similar technologies that can enforce policies on personal devices.
From a security perspective, the key controls include:
Requiring a PIN or biometric-based lock with a reasonable lockout time;
Ensuring all devices are encrypted;Allowing company data to be remotely wiped if a device is lost or stolen;
Controlling the download and installation of applications;
Controlling the transfer of company data on and off the device, and between secure and non-secure areas on the device.
These controls can often be enforced using third-party MDM/UEM software or through built-in capabilities within enterprise platforms such as Microsoft 365 and Google Workspace.
There are a number of ways to enforce technical security controls on endpoint devices, including those owned by employees (BYOD).
Many enterprise platforms (e.g. Microsoft 365 and Google Workspace) include built-in Mobile Device Management (MDM) features that allow you to enforce policies such as screen locks, encryption, application controls, and the ability to remotely wipe company data if a device is lost or stolen.
If your existing platforms do not support these capabilities, you can use a third-party MDM/UEM solution to manage and secure both company-owned and employee-owned devices across your environment.