- The USB ports, CD Drive, and other ports on the laptop should be disabled.
- Internet access should generally be precluded.
- Wi-Fi access should be through approved secured means.
- The hard disk must be encrypted.
- Strong authentication should be required for access to the laptop (e.g., biometric authentication).
- Designated security software (e.g., firewall, anti-virus, anti-malware, etc.) must be installed on each computer.
- The agreement should set forth specific requirements for secure and irreversible erasure of data on completion of work (e.g., methods at least as protective as the DoD 5220-22-M Standard).
- Restrictions should be included regarding the vendor’s ability to have any laptops serviced or any components replaced without appropriate protections in place to ensure data is secured.
- Strict limitations should be included regarding the applications that can be installed on the laptop.
- Each laptop should include tracking software in the event of loss and the ability to remotely erase the entire contents of the hard disk.
- The contract should require immediate reporting of any instance in which the security of the laptop is compromised, including instances in which the laptop is out of the consultant’s control for any material period of time.
- In the event any breach of security or confidentiality by the consultant requires notification to a consumer under any privacy law, the contract should make clear the company has sole control over the timing, content, and method of notification and consultant should be required to reimburse the company for its out-of-pocket costs in providing the notification.

Data Center Directions Virtual Conference
Attend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.
The Surest Path to Effective and Efficient Compliance
In this webcast, we explore why and how with best practices, practical tips and solutions that work to ease your compliance challenge.


