Overview
Ratio is a virtual organisation and panel members are allowed to use their own devices for work. This Device Security Policy is based on best practices adopted around the world in all industry sectors. The purpose of the policy is to ensure that devices are secured against the most basic software vulnerabilities as well as unauthorised physical access (including theft, snooping etc.).
Ratio staff, contracted staff (finance, marketing etc) and panel members are required to comply with this Device Security Policy.
Password and Device Access Requirements
Disk Encryption Requirements
The benefit of disk encryption is that in the event of a laptop being stolen, data is not readable if the disk is removed and placed in another computer.
Most modern operating systems support disk encryption, and the feature can often be enabled after the machine is installed and in use.
NB: Once setup, ensure that if you use a recovery key, that it is safely backed up.
Anti‐Virus Requirements
All Laptops must have an Anti‐Virus program installed and active for disk, and if available, web‐access. This is non‐negotiable.
If you have never had an anti‐virus installed on an older‐laptop that has been used for some time, please ensure that you perform a full system scan once the AV program has been installed and has had its virus signature DB updated.
Software Updates
All employees, contractors and panel members must ensure that all operating system and core application (e.g. MS Office etc.) software updates are turned on and that they are installed either automatically by the system updater software, or manually when notifications of updates become available.
When critical vulnerabilities for an operating system are discovered and staff are alerted, any updates which address these vulnerabilities must be installed as soon as they become available.