KUR 1 — Managed LPHD Security
- Requirement status
- Candidate
- Capability maturity
- Demonstrated at pilot scale
A consistent device-security baseline, controlled identity, private access and rapid removal of access.
- User need
- Units require locally purchased Android handheld devices to be prepared, issued and operated to a consistent security baseline.
- Required outcome
- Approved devices and users are attributable, protected services are accessed through a controlled private path, and access can be removed when no longer authorised.
- Proposed thresholds
- An approved baseline is applied to every issued device.
- Every device and user has a unique attributable identity.
- Protected services are restricted to approved managed devices.
- A central device and account record is maintained.
- Network and service access can be removed within 15 minutes of an authorised revoke instruction.
- A revoked device can no longer access protected services.
- Future objective
- Automated provisioning, compliance reporting, controlled remote lock and wipe, role-based administration, central monitoring and exception alerts.
- Current position
- Ten pilot devices have operated using the current managed baseline and private service boundary. Device check-in, service revoke and controlled wipe have been technically demonstrated. Formal assurance and validation at larger scale remain outstanding.
- Proposed validation
- Conduct a phased device trial and confirm that all issued phones meet the approved baseline, are linked to an authorised user and can be revoked within the proposed response time.
