The organisation should establish and maintain policy for its approved tools for internal voice, video, and text communication. These tools should be used in various scenarios, including data transfer, remote access, and teleworking. The selection of these tools should be based on defined security criteria, such as the availability of end-to-end encryption, strong access controls and MFA support. The policy should clearly communicate which tools are approved for different types of internal communication, especially when sensitive data is involved. The use of unapproved communication applications for work purposes should be prohibited.
Employees should be trained accordingly and informed of the risks associated with using unapproved communication tools for work-related activities (e.g. possible data breaches or unauthorized access to sensitive information). Regular reviews of the approved tools list should be conducted to ensure their continued security and suitability.