Information that sits on, is handled by or can be reached through user endpoint devices is to be protected. Purpose: guard information against the risks that come with using such devices. Guidance: set a topic-specific policy on securely configuring and handling endpoints, communicated to relevant staff, that considers: which information types and classifications a device may handle; device registration; physical protection; limits on installing software, for example controlled remotely by administrators; software and version requirements and how updates are applied, such as automatic updating; rules for connecting to information services, public networks or other off-site networks, for example requiring a personal firewall; access control; encryption of storage; malware protection; remote disabling, wiping or lockout; backup; use of web services and applications; user behaviour analytics (8.16); use of removable devices and whether physical ports such as USB can be disabled; and partitioning that keeps organizational information and software apart from other content on the device. For information too sensitive to be stored locally, add safeguards such as blocking offline downloads and local storage like SD cards. Enforce the policy through configuration management (8.9) or automated tools wherever possible. Users should know the requirements and their own duties: end sessions and stop services when finished; protect devices physically and logically when not in use and not leave devices with important information unattended; take care in public places, open offices and meeting areas, for example using privacy filters and avoiding reading confidential material where others can see; and guard devices against theft in vehicles, hotels and venues. A procedure for lost or stolen devices should reflect legal, regulatory, contractual (including insurance) and other requirements. Where personal devices (BYOD) are allowed, also consider separating personal and business use with supporting software; giving access only after users accept their duties, give up ownership of business data and agree to remote wiping, with regard to PII law; policies preventing disputes over intellectual property created on private equipment; access to private devices for checks or investigations, which law may block; and licensing terms that can make the organization liable for software on privately owned devices. For wireless, set procedures on configuring connections, such as disabling weak protocols, and on using connections with enough bandwidth for backups and updates. Other information: protections depend on whether devices stay inside secured premises or face outside threats; wireless backups can fail through limited bandwidth or devices being offline at backup time; some ports such as USB-C cannot be disabled because they carry power and display.
This control maps to 101 controls across 30 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
You are reading one control. How much of ISO 27002:2022 have you already done?
ISO 27002:2022 8.1 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27002:2022 your existing evidence covers. Hold NIST SP 800-53 Rev 5 and 79 of 93 ISO 27002:2022 controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 180 were rejected on the NIST SP 800-53 Rev 5 pair alone.