A.8.1 User end point devices
Protect information stored on, processed by or reachable through user endpoints.
20
artefacts
6
held by a system
5
at each review
moderate
to go live
Endpoint management (MDM / EDR)
where the evidence lives
teal = a system already holds it · olive = produced at each review
system holds itEvidence a system already holds
- Laptop and desktop assignment logs · Endpoint management (MDM / EDR)
- Configuration baseline documents · Endpoint management (MDM / EDR)
- Security agent installation logs · Endpoint management (MDM / EDR)
- Mobile device enrollment logs · Endpoint management (MDM / EDR)
- Remote wipe request logs · Endpoint management (MDM / EDR)
- Phishing simulation results related to device security · Endpoint management (MDM / EDR)
periodic reviewEvidence produced at each review
- Decommissioned device disposal records · Endpoint management (MDM / EDR)
- Encryption key management records · Key management / PKI
- MDM solution configuration screenshots · Endpoint management (MDM / EDR)
- User training attendance sheets for endpoint security · Endpoint management (MDM / EDR)
- Periodic security reminder communications · HR system / LMS
governing documentDocuments that govern the control
- Asset register of endpoint devices · Policy repository / GRC workspace
- BYOD registration forms · Policy repository / GRC workspace
- Endpoint antivirus deployment reports · Policy repository / GRC workspace
- Patch management compliance reports · Policy repository / GRC workspace
- Full-disk encryption policy · Policy repository / GRC workspace
- Encrypted device compliance audit · Policy repository / GRC workspace
- Exceptions list for unencrypted devices · Policy repository / GRC workspace
- Policy for mobile device usage · Policy repository / GRC workspace
- Signed acknowledgment of acceptable use policy · HR system / LMS
First move
Start with the 6 of 20 artefacts that already live in a system (Endpoint management (MDM / EDR)); keep the periodic reviews but log each one as a dated record with a named reviewer.
Common gaps auditors find
- Incomplete device inventory
- Inconsistent encryption enforcement
- Irregular patching of endpoints
- Lack of BYOD controls
Do this for your whole sheet
Paste the rows you run your controls from and get this mapping for every control at once, with the periodic-review ones flagged and a first move per row. No account for the first run.
Build my evidence sheetA.7.14 Secure disposal or re-use of equipment · A.8.2 Privileged access rights