NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices
Mobile Device Security Controls

NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices MD124-CTL-02: Device Encryption

Enable full-device encryption on all managed mobile devices. Ensure encryption keys are properly managed and protected.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 163 controls across 94 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ISO/IEC 27043:2015 · 4 controls

  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-19 Certificate management
  • ISO27043-20 Key lifecycle management

ISO/SAE 21434 · 4 controls

  • ISO21434-16 Cryptographic policy and key management
  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-19 Certificate management

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

ISO/IEC 23837:2023 · 3 controls

  • 23837-1.2 Normative references
  • 23837-1.5.2 Cryptographic module requirements
  • 23837-1.5.3 Network device testing requirements

NIST SP 800-53 Rev 5 · 3 controls

  • QRCM-1.2 Quantum-Vulnerable Identification
  • QRCM-3.1 Hybrid Solution Deployment (2025-2030)
  • QRCM-4.2 TLS 1.3 Adoption
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection

ISO 27799:2025 · 2 controls

  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-16 Transmission security and encryption
  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • NAIC-2 Information Security Program (ISP) - Section 4

NIST SP 800-92 · 2 controls

  • NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance
  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation

PTES · 2 controls

  • PTESPHASE-2 Intelligence Gathering (OSINT)
  • PTESPHASE-3 Threat Modeling
  • CISABD-1 Take Ownership of Customer Security Outcomes
  • SBD-DEV-04 Phishing-Resistant Authentication
  • OB-SEC.2 Transport Layer Security
  • OB-SEC.4 Certificate Management
  • US-ITAR-EAR-DS-01 Technical Data Protection
  • US-ITAR-EAR-DS-02 Cloud and Storage

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • ASD37-17 TLS encryption between email servers (Limited)

BSI IT-Grundschutz · 1 control

  • BSI-08 Cryptographic protection of data

Bahrain PDPL · 1 control

  • FFIEC-09 Encryption and key management

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • 62351-9 Cyber security key management

ISO/IEC 27010:2015 · 1 control

  • 27010-10.1 Cryptographic Protection

ISO/IEC 27011:2024 · 1 control

  • 27011-8.3 Cryptography and key management

ISO/IEC 27400:2022 · 1 control

  • 27400-6.2 Device Identity and Authentication
  • 29115-7.4 Level of Assurance 4 (LoA4)
  • MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS

MITRE ATT&CK · 1 control

MTCS (Singapore) · 1 control

  • MTCS-Operations-Physical-Network-Tier-III-Data-Centre-Hardening-Patching-Network-Segmentation-DDoS MTCS Operations + Physical + Network + Tier III Data Centre + Hardening + Patching + Segmentation + DDoS

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-Sensitive-Personal-Data-Section-40-Health-Religious-Political-Sexual-Children-Explicit-Consent Malaysia PDPA Sensitive Personal Data + Section 40 + Health + Religious + Political + Children + Explicit Consent

Mauritius DPA · 1 control

  • MU-DPA-Sensitive-Personal-Data-Section-24-Health-Biometric-Genetic-Sexual-Section-25-Children-16 Mauritius DPA Sensitive Data + Section 24 + Health + Biometric + Genetic + Sexual + Section 25 + Children 16

Mexico LFPDPPP · 1 control

  • MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent
  • MN-CDPA-Universal-Opt-Out-GPC-Sensitive-Data-Section-325O-02-Consumer-Health-Data-Children-Known-Child-Transgender Minnesota CDPA Universal Opt-Out + GPC + Sensitive + Section 325O.02 + Consumer Health Data + Children + Known Child + Transgender
  • MT-CDPA-Universal-Opt-Out-Mechanism-1-January-2025-GPC-Global-Privacy-Control-Mandatory-Recognition Montana CDPA Universal Opt-Out Mechanism + 1 January 2025 + GPC + Global Privacy Control + Mandatory Recognition
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-122 · 1 control

  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit

NIST SP 800-123 · 1 control

  • NISTSP123-4 Server Cryptography - Encryption, Key Management, Certificates

NIST SP 800-137 · 1 control

  • NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring

NIST SP 800-144 · 1 control

  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access

NIST SP 800-145 · 1 control

  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 1 control

NIST SP 800-190 · 1 control

  • NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification

NIST SP 800-88 · 1 control

  • NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase
  • NHPA-6 Reasonable Data Security and Breach Response
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGOB-3 API Security Standards, mTLS, and Encryption
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery

OWASP SAMM · 1 control

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management

OpenSSF Scorecard · 1 control

  • OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PCI P2PE · 1 control

  • PCI-P2PE-09 Encryption and key management

PCI PIN Security · 1 control

  • PCI-PIN-09 Encryption and key management

PCI SSF · 1 control

  • PCI-SSF-09 Encryption and key management

PDPA Singapore · 1 control

  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 1 control

  • PDPATH-5 Security Measures and Data Protection

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information

Qatar DPL · 1 control

  • QATAR-5 Security of Processing
  • SHAREASSESS-3 Network Security, Endpoint, Data Protection

SLSA · 1 control

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • SOC-CY-C2 Encryption and Data Protection

Saudi Arabia PDPL · 1 control

  • SA-PDPL-13 Encryption of personal data
  • IM8-CLD.2 Cloud Security Controls

South Korea ISMS-P · 1 control

  • ISMSP-SYS-02 Encryption Implementation

Taiwan PDPA · 1 control

  • TAIWAN-2 Consent, Notice, Sensitive Data
  • TEXASTDPSA-2 Consumer Rights

Uruguay DPL · 1 control

  • URUGUAY-3 Sensitive Data, Health Data, Children

Vietnam PDPD · 1 control

  • VIETNAMPDP-2 Consent and Notice

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-2 Consumer Rights
  • VP-2 Holder Binding

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Mobile Device Security Controls

Query this from an agent

The graph holds this control, the 163 it maps to, and the evidence behind each claim, over MCP and REST.