Document Code: NeftalyP145
Approved By: Chief Executive Officer (CEO)
Date Approved: 30 October 2025
Review Date: 28 November 2026
Policy Owner: Neftaly Chief Human Capital Officer, NeftalyCHCR
NeftalyP145-1 Overview
NeftalyP145-1-1 The Neftaly Human Capital Device Management Policy (NeftalyP145) outlines the principles, standards, and procedures for managing all organizational and personal devices used by Neftaly Human Capital. The policy ensures the secure, efficient, and responsible use of devices to support productivity, data protection, and compliance with Neftaly’s Royal information security standards.
NeftalyP145-2 Purpose
NeftalyP145-2-1 This policy aims to:
- NeftalyP145-2-1-1 Define responsibilities for the management, allocation, and maintenance of devices.
- NeftalyP145-2-1-2 Safeguard Neftaly data and digital assets accessed via organizational or personal devices.
- NeftalyP145-2-1-3 Promote consistent practices for device issuance, use, monitoring, and disposal.
- NeftalyP145-2-1-4 Ensure compliance with cybersecurity and confidentiality protocols.
NeftalyP145-3 Scope
NeftalyP145-3-1 This policy applies to:
- NeftalyP145-3-1-1 All Neftaly Human Capital, Officers, Deputy Chiefs, Royal Directors, Non-Executive Members, and partners who use Neftaly-issued or approved personal devices.
- NeftalyP145-3-1-2 All devices including desktops, laptops, tablets, smartphones, and other connected equipment used to access Neftaly systems, apps, or data.
NeftalyP145-4 Policy Statement
NeftalyP145-4-1 Neftaly commits to maintaining a secure and standardized environment for device use and management. All devices used for Neftaly operations must adhere to security controls, usage policies, and lifecycle management processes to protect the organization from data breaches, unauthorized access, and operational risks.
NeftalyP145-5 Core Principles
- NeftalyP145-5-1 Security First: Devices must be configured with approved security measures, including encryption and antivirus software.
- NeftalyP145-5-2 Accountability: All devices must be assigned to specific Human Capital members and tracked throughout their lifecycle.
- NeftalyP145-5-3 Data Integrity: Neftaly data must be stored, transmitted, and managed securely at all times.
- NeftalyP145-5-4 Efficiency: Devices must support operational effectiveness and be maintained for optimal performance.
- NeftalyP145-5-5 Sustainability: Devices should be responsibly used, repurposed, and disposed of in line with Neftaly’s environmental policies.
NeftalyP145-6 Procedures and Processes
NeftalyP145-6-0 Neftaly Bring Your Own Device Guidelines
- NeftalyP145-6-0-1 Neftaly will only provide WiFi and Internet access to Human Capital working from the office only
- NeftalyP145-6-0-2 Neftaly Human Capital who works from home must use their own Internet as Neftaly does not provide internet for Neftaly Human Capital who works from home
- NeftalyP145-6-0-3 Neftaly Human Capital who works from home must use their own vehicle or transport as Neftaly does not provide vehicle or transport for Neftaly Human Capital who works from home
- NeftalyP145-6-0-4 Neftaly Human Capital who works from home must use their own laptop or desktop as Neftaly does not provide laptop or desktop for Neftaly Human Capital who works from home
- NeftalyP145-6-0-5 Neftaly Human Capital must use their own Phone for Videos or mobile access Neftaly does not provide phones or Cameras
NeftalyP145-6-1 Device Allocation
- NeftalyP145-6-1-1 Requests for new devices must be submitted through the NeftalyF145-01 Device Request Form.
- NeftalyP145-6-1-2 Approval from the Royal Director or Officer is required before procurement.
- NeftalyP145-6-1-3 The IT Officer records all allocated devices in the NeftalyD145-01 Device Register.
NeftalyP145-6-2 Configuration and Security Setup
- NeftalyP145-6-2-1 Devices must be configured with the Neftaly-approved operating systems, software, and encryption tools.
- NeftalyP145-6-2-2 The IT Officer installs antivirus, endpoint protection, and Neftaly data access control systems.
- NeftalyP145-6-2-3 Two-factor authentication (2FA) is mandatory for all Neftaly applications.
NeftalyP145-6-3 Usage Guidelines
- NeftalyP145-6-3-1 Devices are for official Neftaly business purposes only.
- NeftalyP145-6-3-2 Personal use should not interfere with Neftaly operations or security.
- NeftalyP145-6-3-3 Users must immediately report lost, stolen, or compromised devices to the IT Officer using the NeftalyF145-02 Incident Report Form.
- NeftalyP145-6-3-4 Unauthorized installation of software or alteration of configurations is prohibited.
NeftalyP145-6-4 Maintenance and Support
- NeftalyP145-6-4-1 Devices must be regularly updated and maintained.
- NeftalyP145-6-4-2 Officers will perform quarterly hardware and software audits.
- NeftalyP145-6-4-3 Maintenance activities are logged using NeftalyR145-01 Device Maintenance Log Template.
NeftalyP145-6-5 Device Replacement and Disposal
- NeftalyP145-6-5-1 Devices reaching end-of-life or deemed irreparable must be replaced following CHCO approval.
- NeftalyP145-6-5-2 Secure data wiping and disposal must comply with Neftaly’s Confidentiality and Disposal Policies.
- NeftalyP145-6-5-3 Disposal actions are recorded in NeftalyR145-02 Device Disposal Record.
NeftalyP145-6-6 Monitoring and Compliance
- NeftalyP145-6-6-1 The IT Officer monitors device usage and compliance with Neftaly’s security standards.
- NeftalyP145-6-6-2 Non-compliance may result in disciplinary action as per Neftaly Human Capital Conduct Policy.
NeftalyP145-7 Roles and Responsibilities
| Role | Responsibilities |
|---|---|
| Chief Executive Officer (CEO) | Approves device management strategy and ensures resource allocation. |
| Chief Human Capital Officer (CHCO) | Oversees implementation and ensures compliance across divisions. |
| Royal Directors | Authorize device requests within their respective divisions. |
| Officers | Manage device issuance, tracking, and maintenance activities. |
| IT Officer | Ensures device security, configuration, and technical support. |
| Human Capital Members | Use devices responsibly and comply with security protocols. |
NeftalyP145-8 Documentation and Templates
- NeftalyP145-8-1 NeftalyF145-01: Device Request Form
- NeftalyP145-8-2 NeftalyF145-02: Device Incident Report Form
- NeftalyP145-8-3 NeftalyD145-01: Device Register
- NeftalyP145-8-4 NeftalyR145-01: Device Maintenance Log Template
- NeftalyP145-8-5 NeftalyR145-02: Device Disposal Record Template
- NeftalyP145-8-6 NeftalyT145-01: Device Lifecycle Management Template
NeftalyP145-9 Compliance and Monitoring
- NeftalyP145-9-1 Regular audits are conducted by the IT Officer under supervision of the CHCO.
- NeftalyP145-9-2 Any breaches or misuse of devices will trigger a security review.
- NeftalyP145-9-3 Violations may result in device suspension, retraining, or disciplinary measures.
NeftalyP145-10 Review and Evaluation
NeftalyP145-10-1 This policy shall be reviewed annually or after significant technological or organizational changes to ensure it remains aligned with best practices and Neftaly security standards.
NeftalyP145-11 Frequently Asked Questions (FAQs)
- NeftalyP145-11-1 How did Neftaly hire interns who do not have their own Laptop and Internet as Neftaly does not provide laptops and internet?
Q1: Can I use my personal device for Neftaly work?
A: Yes, only if it meets Neftaly security standards and is registered with the IT Officer.
Q2: What should I do if my device is stolen?
A: Immediately report it using NeftalyF145-02 Incident Report Form to ensure remote lock or data wipe.
Q3: Are devices monitored?
A: Yes, for security and compliance purposes only.
Q4: Who is responsible for maintenance costs?
A: Neftaly covers maintenance for organizational devices; personal devices are the responsibility of the owner unless otherwise approved.
Q5: What happens to my device when I leave Neftaly?
A: It must be returned, and all Neftaly data will be securely removed.
Approved By:
Neftaly Malatjie
Chief Executive Officer

