CIS Controls v8
CIS Control 4: Secure Configuration of Enterprise Assets and Software

CIS Controls v8 CIS-4.11: Enforce Remote Wipe Capability on Portable End-User Devices

Be able to wipe enterprise data remotely from portable end-user devices the enterprise owns, and do so when judged necessary, for example when a device is lost or stolen or when its user stops supporting the enterprise.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 37 controls across 15 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO 27001:2022 · 5 controls

  • 5.11 Return of assets
  • 6.7 Remote working
  • 7.9 Security of assets off-premises
  • 8.1 User end point devices
  • 8.10 Information deletion

FedRAMP High · 4 controls

  • AC-19 Access Control for Mobile Devices
  • CM-2(7) Configure Systems and Components for High-Risk Areas
  • MP-2 Media Access
  • MP-4 Media Storage

FedRAMP Moderate · 4 controls

  • AC-19 Access Control for Mobile Devices
  • CM-2(7) Configure Systems and Components for High-Risk Areas
  • MP-2 Media Access
  • MP-4 Media Storage

NIST SP 800-53 Rev 5 · 4 controls

ISO 27002:2022 · 3 controls

  • 6.7 Remote working
  • 7.9 Security of assets off-premises
  • 8.1 User endpoint devices

SOC 2 · 3 controls

  • SOC2-C1.2 C1.2 Disposing of confidential information
  • SOC2-CC6.5 CC6.5 Protecting data on assets until disposal
  • SOC2-P4.3 P4.3 Securely disposing of personal information
  • ANSSI-HYG-30 Apply Physical Protection Measures to Mobile Devices
  • ANSSI-HYG-33 Adopt Security Policies Dedicated to Mobile Terminals

CMMC 2.0 · 2 controls

HIPAA Security Rule · 2 controls

ISO 27701:2019 · 2 controls

  • 6.3.2 Mobile devices and teleworking
  • 6.5.3 Media handling

NIST SP 800-66 Rev 2 · 2 controls

  • ISM-1887 Remote locate and wipe for mobile devices
  • 03.01.18 Access Control for Mobile Devices

PCI DSS 4.0 · 1 control

  • 3.5.1.2 3.5.1.2 Disk or partition encryption only on removable media

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in CIS Control 4: Secure Configuration of Enterprise Assets and Software

You are reading one control. How much of CIS Controls v8 have you already done?

CIS Controls v8 CIS-4.11 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of CIS Controls v8 your existing evidence covers. Hold ISO 27001:2022 and 102 of 153 CIS Controls v8 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 240 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 37 it maps to, and the evidence behind each claim, over MCP and REST.