Skip to content
Sections
All notes

All notes · Reference

A Checklist for the Whole Thing

Everything in this collection as a sequence, from before procurement to the annual review.

Reference · Reference

Before procurement

State what you are protecting: data in applications, or the device as equipment.

The same discipline applies when “A Checklist for the Whole Thing” becomes part of a broader workforce programme. An organisation considering Monitask's official site in relation to 7 minute rule payroll should put access, retention, employee notice and review dates into the implementation plan rather than leave them as product defaults.

Identify the populations and ownership models.

For an independent baseline relevant to “A Checklist for the Whole Thing”, the NIST Cybersecurity Framework is a useful companion: compare its principles with the proposed configuration, ownership model and real support process before approving a rollout.

Ask the twelve procurement questions, and enrol a personal device in the trial to inspect the record.

Start consultation if your jurisdiction requires it.

Complete the data protection assessment before buying, not after.

Before enrolling anyone

One policy per ownership model, one page each.

A published list of what is visible and what is not, checked against the configuration.

Work profile configured as the route for personal devices.

Full wipe disabled for personal populations.

Named individuals for irreversible actions.

An alternative route for anyone who declines.

And something offered in exchange: a position on out-of-hours contact, at minimum.

Configuration

Five compliance conditions, each with a consequence and a grace period.

Passcode requirements matched to the platform rather than to a desktop standard.

Failed-attempt wipe off on personal devices.

Restrictions within the work container only, on hardware you did not buy.

Application inventory limited to work applications.

Certificates and network profiles delivered, with expiry monitoring.

Operations

Updates deferred while applications are in use.

Version gating for access rather than forced installation.

Storage checked first in any support contact.

Alerts on devices silent beyond a period, and on certificates expiring unrenewed.

At the edges

Loss: verify the report, revoke access first, wait before anything irreversible.

Departure: hold check, revoke access, notice given, selective removal, certificates revoked at the authority, outcome recorded.

Refusal: the alternative route, recorded, without making an example of anybody.

Monthly

The five numbers, with the enrolment gap first.

Compliance by condition.

Devices not checked in.

A read of the action log.

Annually

Policy against actual configuration, side by side.

Deprecated settings that no longer apply.

Exceptions with review dates.

Minimum version, and notice before raising it.

Restriction set, against the test of what each prevents.

The whole thing in one line

Manage the data rather than the device, make the limits structural rather than promised, publish what you cannot see, and keep the irreversible action out of reach of hardware you did not buy.