ISO 27002:2022
Technological controls – ISO 27002:2022

ISO 27002:2022 8.1: User endpoint devices

Information that sits on, is handled by or can be reached through user endpoint devices is to be protected. Purpose: guard information against the risks that come with using such devices. Guidance: set a topic-specific policy on securely configuring and handling endpoints, communicated to relevant staff, that considers: which information types and classifications a device may handle; device registration; physical protection; limits on installing software, for example controlled remotely by administrators; software and version requirements and how updates are applied, such as automatic updating; rules for connecting to information services, public networks or other off-site networks, for example requiring a personal firewall; access control; encryption of storage; malware protection; remote disabling, wiping or lockout; backup; use of web services and applications; user behaviour analytics (8.16); use of removable devices and whether physical ports such as USB can be disabled; and partitioning that keeps organizational information and software apart from other content on the device. For information too sensitive to be stored locally, add safeguards such as blocking offline downloads and local storage like SD cards. Enforce the policy through configuration management (8.9) or automated tools wherever possible. Users should know the requirements and their own duties: end sessions and stop services when finished; protect devices physically and logically when not in use and not leave devices with important information unattended; take care in public places, open offices and meeting areas, for example using privacy filters and avoiding reading confidential material where others can see; and guard devices against theft in vehicles, hotels and venues. A procedure for lost or stolen devices should reflect legal, regulatory, contractual (including insurance) and other requirements. Where personal devices (BYOD) are allowed, also consider separating personal and business use with supporting software; giving access only after users accept their duties, give up ownership of business data and agree to remote wiping, with regard to PII law; policies preventing disputes over intellectual property created on private equipment; access to private devices for checks or investigations, which law may block; and licensing terms that can make the organization liable for software on privately owned devices. For wireless, set procedures on configuring connections, such as disabling weak protocols, and on using connections with enough bandwidth for backups and updates. Other information: protections depend on whether devices stay inside secured premises or face outside threats; wireless backups can fail through limited bandwidth or devices being offline at backup time; some ports such as USB-C cannot be disabled because they carry power and display.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 101 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ISM-0687 ASD-approved platforms for classified mobility
  • ISM-0863 Blocking unapproved application installation
  • ISM-0869 Encrypting mobile device storage
  • ISM-1195 Common Criteria evaluated MDM solutions
  • ISM-1867 Evaluated mobile platforms and ASD configuration
  • ISM-1887 Remote locate and wipe for mobile devices
  • ISM-1888 Password-based lock screens on mobile devices
  • ISM-2095 Unapproved AI agents on privately-owned devices

FedRAMP High · 8 controls

  • AC-11 Device Lock
  • AC-11(1) Device Lock | Pattern-hiding Displays (AC-11(1))
  • AC-19 Access Control for Mobile Devices
  • AC-19(5) Full Device or Container-Based Encryption
  • CM-11 User-Installed Software
  • CM-2(7) Configure Systems and Components for High-Risk Areas
  • CM-7 Least Functionality
  • SC-28 Protection of Information at Rest

FedRAMP Moderate · 8 controls

  • AC-11 Device Lock
  • AC-11(1) Device Lock | Pattern-hiding Displays (AC-11(1))
  • AC-19 Access Control for Mobile Devices
  • AC-19(5) Full Device or Container-Based Encryption
  • CM-11 User-Installed Software
  • CM-2(7) Configure Systems and Components for High-Risk Areas
  • CM-7 Least Functionality
  • SC-28 Protection of Information at Rest
  • ASD37-04 User application hardening (Essential)
  • ASD37-13 Control removable storage media (Very Good)
  • ASD37-24 Non-persistent virtualised sandboxed environment (Very Good)
  • ASD37-25 Software firewall - inbound (Very Good)
  • ASD37-26 Software firewall - outbound (Very Good)
  • ASD37-29 Host-based IDS/IPS (Very Good)
  • ASD37-30 Endpoint detection and response (Very Good)

CIS Controls v8 · 7 controls

  • CIS-10.1 Deploy and Maintain Anti-Malware Software
  • CIS-3.6 Encrypt Data on End-User Devices
  • CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices
  • CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices
  • CIS-4.12 Separate Enterprise Workspaces on Mobile End-User Devices
  • CIS-4.5 Implement and Manage a Firewall on End-User Devices
  • CIS-9.1 Ensure Use of Only Fully Supported Browsers and Email Clients

NIST SP 800-53 Rev 5 · 7 controls

SOC 2 · 7 controls

  • SOC2-C1.1 C1.1 Identifying and maintaining confidential information
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.4 CC6.4 Restricting physical access to facilities and assets
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-CC7.1 CC7.1 Detecting configuration changes and new vulnerabilities
  • ANSSI-HYG-07 Authorise Network Connection Only for Managed Equipment
  • ANSSI-HYG-14 Apply a Minimum Security Level Across the Whole Estate
  • ANSSI-HYG-17 Enable and Configure the Local Firewall on Workstations
  • ANSSI-HYG-29 Limit Administration Rights on Workstations to Operational Need
  • ANSSI-HYG-33 Adopt Security Policies Dedicated to Mobile Terminals
  • NIST-CSF-ID.AM-01 Inventories of hardware managed by the organization are maintained
  • NIST-CSF-PR.AA-06 Physical access to assets is managed, monitored, and enforced commensurate with risk
  • NIST-CSF-PR.DS-01 The confidentiality, integrity, and availability of data-at-rest are protected
  • NIST-CSF-PR.PS-01 Configuration management practices are established and applied
  • NIST-CSF-PR.PS-03 Hardware is maintained, replaced, and removed commensurate with risk
  • ASBv3-GS-9 Define and implement endpoint security strategy
  • ASBv3-PA-6 Use privileged access workstations
  • ES-1 Use Endpoint Detection and Response (EDR)
  • ES-2 Use modern anti-malware software

UK Cyber Essentials · 4 controls

  • CE-FW.6 Host-Based Firewall for Remote Workers
  • CE-MP.1 Anti-Malware Software Deployed
  • CE-SC.1 Remove or Disable Unused Software
  • CE-SC.9 Device Unlocking Credentials and Brute-Force Protection

CMMC 2.0 · 2 controls

HIPAA Security Rule · 2 controls

ISO 27001:2022 · 2 controls

  • 7.9 Security of assets off-premises
  • 8.1 User end point devices

NIST SP 800-171 Rev 3 · 2 controls

NIST SP 800-66 Rev 2 · 2 controls

  • 21.4.7.C.02 21.4.7.C.02 Integrated approach to BYOD security
  • 21.4.9.C.01 21.4.9.C.01 Block jail-broken or rooted devices

PCI DSS 4.0 · 2 controls

  • 1.5.1 1.5.1 Security controls on dual-connected devices
  • 12.2.1 12.2.1 Rules for acceptable use of end-user technology
  • E8-UAH-ML2 User Application Hardening - Maturity Level 2
  • AUCDR-IS-2 Secure the network and systems within the data environment

C5 (Germany) · 1 control

  • C5-AM-02 Acceptable Use and Safe Handling of Assets Policy

IEC 62443 · 1 control

  • 62443-3-3-FR2-SR-2-5 Session Lock and Termination

ISO/IEC 27011:2024 · 1 control

  • 27011-8.1 User Endpoint Devices

NIS2 Directive · 1 control

  • Art.21.2.g Basic cyber hygiene practices and cybersecurity training

NIST SP 800-172 · 1 control

  • 3.1.2e Restrict Access to Organization-Owned, Provisioned, or Issued Information Resources

NIST SP 800-218 · 1 control

  • P2-4.3.3 P2-4.3.3 Rules for personally owned devices used remotely

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Technological controls – ISO 27002:2022

You are reading one control. How much of ISO 27002:2022 have you already done?

ISO 27002:2022 8.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.

Query this from an agent

The graph holds this control, the 101 it maps to, and the evidence behind each claim, over MCP and REST.