Business IT projects · Across Québec Request a quoteFrançais

Device management

Device management covers the full life of your company's computers: preparation and setup, updates, secure configuration, inventory, employee onboarding and offboarding, and finally retiring and wiping devices at end of life. The goal is devices that are up to date, known and configured the same way.

Updated on

The Canadian Centre for Cyber Security's baseline cyber security controls for small and medium organizations call for, among other things, applying patches automatically (BC.2.1), using secure configurations (BC.4.1), restricting administrative privileges (BC.12.1 and BC.12.2) and to "remove accounts and/or functionality when employees no longer require these for their tasks" (BC.12.3). Device management puts these controls into practice on every device.

Short answer

You describe your devices, your employees and how you work: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. The scope, tools and responsibilities are set with you.

What the quote should cover

  • The devices covered: desktops, laptops, tablets and company-issued phones
  • Preparing new devices from a standard configuration
  • Managing operating system and software updates
  • Encryption of laptops and mobile devices
  • The onboarding and offboarding procedure, including removal of access
  • An up-to-date inventory and your access to it
  • Retiring end-of-life devices, including wiping the data

The life cycle of a device

  1. Purchase or receipt of the device, and entry into the inventory
  2. Preparation from a standard configuration: system, software, security
  3. Handover to the employee, with their access and accounts
  4. Updates and follow-up throughout its use
  5. Recovery at departure or replacement, and removal of access
  6. Data wiping, then reuse, recycling or destruction

Updates and standard configuration

The Centre calls for enabling automatic patching for operating systems and applications (BC.2.1). For software and hardware that cannot update automatically, it calls for a risk assessment to decide whether to replace them and, if they are kept, a business process to ensure regular manual updates (BC.2.2). Have the quote specify how updates are deployed, who checks that they have been applied and what is done about a device that stops updating.

A standard configuration makes support and security easier: the same core software and the same settings. The Centre recommends changing default passwords and disabling unnecessary features (BC.4.1). It also calls for employees not to use an administrator account for everyday work: administrator accounts are used only for administrative tasks (BC.12.2). Malware protection falls under endpoint protection, which can be part of the same contract or a separate one.

Encryption and mobile devices

A lost or stolen laptop should not expose your data. The Centre calls for encrypting sensitive information on mobile devices (BC.8.4) and encrypting removable media (BC.13.1). For phones and tablets, it recommends choosing an ownership model, separating work and personal data and considering an enterprise mobility management solution (BC.8.1 to BC.8.5).

Ask the quote to explain how encryption is enabled, where recovery keys are stored and who can access them. Also have it specify what can be done remotely on a lost device, such as locking or wiping it, and with which management tool, for example Microsoft Intune.

Onboarding, offboarding and inventory

An employee's departure is a sensitive moment. The Centre calls for removing accounts and access that employees no longer need (BC.12.3) and considering a centralized authorization control system (BC.12.4). The offboarding procedure should include disabling accounts, recovering devices, transferring useful files and removing access to online services. It also applies to accounts protected by multi-factor authentication.

The inventory is the foundation for everything else. The Centre's organizational controls in fact include determining the value of information systems and assets (section 2.3). A useful inventory shows, for each device, its user, location, purchase date, warranty and update status. Require access to it and its handover at the end of the contract.

End of life and data wiping

According to the Centre's publication ITSAP.40.006, a factory reset makes data inaccessible through the user interface but does not truly delete it. The Centre describes more reliable methods: overwriting and secure erase, crypto erase, which is suitable when encryption was used from the start of the media's life cycle, and, for highly sensitive information, overwriting and secure erase combined with physical destruction. It also recommends disconnecting the device from online accounts.

The quote should specify the wiping method planned, who performs it and what proof you receive. If the devices hold personal information, Quebec's Act respecting the protection of personal information in the private sector provides for its destruction or anonymization once the purposes for which it was collected are achieved (s. 23).

Questions to ask yourself before requesting a quote

  • How many desktops, laptops and mobile devices does the company own?
  • Do you have an up-to-date inventory, even a partial one?
  • Do employees use personal devices for work?
  • Who in your company announces arrivals and departures?
  • Do employees currently have administrator rights on their computers?
  • What do you currently do with end-of-life devices?

Pitfalls to avoid

  • Updates described as automatic, with no check that they are applied
  • Unencrypted laptops, or recovery keys held by a single person
  • An employee departure without removal of their access to online services
  • An inventory kept by the provider alone, which you cannot access
  • Devices resold or recycled after a simple reset
  • Administrator rights left with every employee

What to specify in your request

  • The number and type of devices, and their operating systems
  • The number of employees and sites, and whether people work remotely
  • Your main software
  • Your current device management tools, if any
  • The approximate frequency of arrivals and departures
  • Requirements from a client, insurer or contract that must be met

You can then describe your project: the team will contact you to clarify your needs and provide a quote.

Frequently asked questions

What is the difference between device management and endpoint protection?

Device management covers the device life cycle: preparation, updates, inventory, onboarding and offboarding, end of life. Endpoint protection focuses on detecting and blocking threats. The two complement each other and can be part of the same contract.

Can updates be automatic?

Yes. The Canadian Centre for Cyber Security calls for enabling automatic patching (BC.2.1) and, for devices that do not allow it, assessing whether to replace them or to plan regular manual updates (BC.2.2). Have the quote specify how update installation is checked.

What should happen when an employee leaves?

Disable their accounts, recover their devices, transfer their useful files and remove their access to online services. The Centre calls for removing accounts and access that employees no longer need (BC.12.3). The quote should describe this procedure.

Is a reset enough before recycling a computer?

No. According to the Canadian Centre for Cyber Security, a factory reset makes data inaccessible through the interface without truly deleting it. It recommends methods such as secure erase, crypto erase or physical destruction depending on the sensitivity of the data.

Can employees' phones be managed?

Yes, depending on the model chosen. The Centre recommends defining an ownership model for mobile devices, separating work and personal data and considering an enterprise mobility management solution (BC.8.1 to BC.8.5).

Device management

User support and fleet management

Request a quote