ISO 27701:2019
PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

ISO 27701:2019 6.3.2: Mobile devices and teleworking

Mobile device and teleworking arrangements must be set so that using mobile devices does not lead to personal data being compromised.

Maintained by Gerard Blokdyk

What else in your programme already covers this

This control maps to 56 controls across 19 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

CIS Controls v8 · 7 controls

  • CIS-12.7 Ensure Remote Devices Utilize a VPN and are Connecting to an Enterprise’s AAA Infrastructure
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-14.8 Train Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks
  • CIS-4.1 Establish and Maintain a Secure Configuration Process
  • CIS-4.10 Enforce Automatic Device Lockout on Portable End-User Devices
  • CIS-4.11 Enforce Remote Wipe Capability on Portable End-User Devices
  • CIS-4.12 Separate Enterprise Workspaces on Mobile End-User Devices

CMMC 2.0 · 5 controls

NIST SP 800-53 Rev 5 · 5 controls

  • NIST800-AC-17 AC-17 Remote Access
  • NIST800-AC-19 AC-19 Access Control for Mobile Devices
  • NIST800-IA-2 IA-2 Identification and Authentication (Organizational Users)
  • NIST800-SC-8 SC-8 Transmission Confidentiality and Integrity
  • SP800-53-AC Access Control Family

PCI DSS 4.0 · 5 controls

  • 1.5.1 1.5.1 Security controls on dual-connected devices
  • 12.2.1 12.2.1 Rules for acceptable use of end-user technology
  • 8.4.3 8.4.3 MFA for remote access that could reach CDE
  • 5.2.1 5.2.1 Anti-malware deployed on all system components
  • 8.1.1 8.1.1 Requirement 8 policies and procedures maintained

SOC 2 · 5 controls

  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC6.6 CC6.6 Protection against threats from outside the system boundary
  • SOC2-CC6.8 CC6.8 Preventing and detecting unauthorised or malicious software
  • SOC2-P5.1 P5.1 Data subject access

ISO 27001:2022 · 4 controls

  • 5.10 Acceptable use of information and other associated assets
  • 6.7 Remote working
  • 7.9 Security of assets off-premises
  • 8.1 User end point devices

FedRAMP High · 3 controls

  • AC-19 Access Control for Mobile Devices
  • AC-19(5) Full Device or Container-Based Encryption
  • PE-17 Alternate Work Site

FedRAMP Moderate · 3 controls

  • AC-19 Access Control for Mobile Devices
  • AC-19(5) Full Device or Container-Based Encryption
  • PE-17 Alternate Work Site
  • ES-1 Use Endpoint Detection and Response (EDR)
  • IM-7 Restrict resource access based on conditions
  • CJIS-15 Mobile Devices
  • CJIS-5.13 Mobile Devices

ISO 27002:2022 · 2 controls

  • 6.7 Remote working
  • 7.9 Security of assets off-premises
  • NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
  • NIST-CSF-PR.IR-01 Networks and environments are protected from unauthorized logical access and usage

NIST SP 800-161 Rev 1 · 2 controls

NIST SP 800-171 Rev 3 · 2 controls

C5 (Germany) · 1 control

  • C5-AM-02 Acceptable Use and Safe Handling of Assets Policy

HIPAA Security Rule · 1 control

ISO 27017:2015 · 1 control

  • 6.2 Mobile devices and teleworking

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PIMS-specific guidance related to ISO/IEC 27002, ISO 27701:2019

You are reading one control. How much of ISO 27701:2019 have you already done?

ISO 27701:2019 6.3.2 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of ISO 27701:2019 your existing evidence covers. Hold SOC 2 and 58 of 108 ISO 27701:2019 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 289 were rejected on the SOC 2 pair alone.

Query this from an agent

The graph holds this control, the 56 it maps to, and the evidence behind each claim, over MCP and REST.