Frameworks / NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices / MD124-POL-03 NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices
Mobile Device Policies
NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices MD124-POL-03: Mobile Data Protection Policy Define data protection requirements for mobile devices including encryption, data loss prevention, and restrictions on sensitive data storage and transmission.
What else in your programme already covers this This control maps to 595 controls across 201 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
CH-FADP-13 Right to object and request blocking CH-FADP-19 Transparency and proactive information CH-FADP-21 Data protection impact assessments FADP-16 FDPIC Independence and Functions FADP-5 Definitions (Article 5) FADP-7 Data Protection Impact Assessment (Articles 9-10) FADP-9 Data Protection Advisor (Articles 14-15) NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-4 Sensitive Data Processing Consent and Childrens Protections NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NDPA-7 Data Protection Assessments and Processor Contracts NDPA-8 Nebraska Attorney General Enforcement, Permanent 30-Day Cure, and Penalties NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles NG-NDPA-4 Data Subject Rights and Automated Decision-Making NG-NDPA-5 Security of Processing, Breach Notification, and DPIA NG-NDPA-7 Cross-Border Data Transfers and International Cooperation NG-NDPA-8 Enforcement, Penalties, Data Controllers of Major Importance (DCMI), and Compliance AT-DSG-10 Section 29 - Liability and right to compensation / civil jurisdiction AT-DSG-12 Section 62 - Administrative penalties AT-DSG-2 Section 2 - Scope and application AT-DSG-7 Section 18 - Establishment of the Data Protection Authority AT-DSG-8 Section 22 - Functions and powers of the DPA NRC7354-2 Critical Digital Asset (CDA) Identification, Scope, and Boundary NRC7354-4 Security Controls Implementation per NRC RG 5.71 Appendix B/C RG5.71-C.3 Cyber Security Training RG5.71-C.5 Recovery and Restoration RG5.71-C.6 Configuration Management AZ-DPA-15 Article 17 - Dispute resolution AZ-DPA-2 Article 2 - Basic Concepts AZ-DPA-6 Article 6 - State regulation in personal data protection 1.2 Operating System Privileged Account Control 1.3 Virtualisation Platform Protection 3.3 Configure Data Access Control Lists BB-DPA-1 Section 1 - Short Title BB-DPA-2 Section 2 - Interpretation BB-DPA-4 Section 4 - Principles Relating to Processing DA-1 Enterprise Data Architecture DIQ-2 Data Quality Management RMD-1 Reference Data Management 6.5 Preparing and Distributing Audit Report 6.6 Confidentiality or non-disclosure agreements 6.7 Conducting Audit Follow-up NISTPF-4 Communicate-P - Privacy Notice, Transparency, and Individual Awareness NISTPF-7 Protect-P Maintenance and Protective Technology (PR.MA-P, PR.PT-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP144-3 Data Classification, Handling, and Sovereignty NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access NISTSP145-3 Rapid Elasticity Characteristic and Capacity Management NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework NISTSP146-6 Cloud Security and Privacy Recommendations NISTSP146-7 Service Level, Performance, Reliability, Interoperability, and Portability NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity NISTSP92-1 Log Management Programme, Policy, Roles, and Operational Runbooks NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NHPA-6 Reasonable Data Security and Breach Response NHPA-7 Data Protection Assessments and Processor Contracts NHPA-8 AG Formella Enforcement, Permanent 60-Day Cure, and Penalties ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management ORANWG11-6 Security Test Specifications, Certification, and Conformance OREGONCPA-5 Data Protection Assessments, Privacy by Design, Security Practices OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs OREGONCPA-8 Cure Period, Attorney General Enforcement, Training, Compliance Monitoring PDPASG-1 Accountability, Records, DPO Appointment, and Training PDPASG-4 Children's Data, DPIA, and Privacy by Design PDPASG-5 Protection, Accuracy, and Security of Personal Data PDPATH-4 DPIA, Privacy by Design, Children's Data PDPATH-5 Security Measures and Data Protection PDPATH-7 DPO, Records of Processing, Retention, Marketing, Training PICSGMP-2 Chapter 2: Personnel - Qualified Personnel, Key Responsibilities, Training PICSGMP-5 Chapter 5: Production Operations and Material Management PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management POPIASA-4 Special Personal Information, Children, Information Quality, Documentation POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations POPIASA-7 Information Officer, Records of Processing, Notification, Training NORWAY-4 DPIA, Privacy by Design, Records of Processing NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control NORWAY-7 DPO, Cooperation with Datatilsynet, Retention, Marketing, Training NZPRV-2 IPP 5 Storage and Security of Personal Information NZPRV-6 IPP 13 Unique Identifiers, Privacy Impact Assessment, Privacy by Design NZPRV-8 Privacy Officer, OPC Cooperation, Compliance Notices, Complaints, Training UGA-3 Accountability Principle UGA-6 Personal Data Protection Office UGA-7 Data Protection Officer ASD37-17 TLS encryption between email servers (Limited) ASD37-27 Outbound data loss prevention (Very Good) MLE.1 Machine Learning Requirements Analysis MLE.3 Machine Learning Training CJIS-8 Media Protection CJIS-9 System and Communications Protection FFIEC-05 Roles and responsibilities definition FFIEC-09 Encryption and key management FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c)) FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2) 6.6 Confidentiality or non-disclosure agreements 6.7 Conducting Audit Follow-up NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions NAIC-2 Information Security Program (ISP) - Section 4 STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding NIST-CSF-DE.AE-08 Incidents are declared when adverse events meet the defined incident criteria NIST-CSF-PR.AA-05 Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties NISTSP115-1 Scope, Methodology, and Assessment Planning NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit NISTSP122-8 Continuous Monitoring, Training, and Privacy Programme Governance NISTSP123-4 Server Cryptography - Encryption, Key Management, Certificates NISTSP123-8 Governance, Policies, and ISMS Integration NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring NISTSP61-2 Computer Security Incident Response Team (CSIRT) Structure and Staffing NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence NISTSP63R4-1 Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase NJDPA-7 Data Protection Assessments and Processor Contracts NJDPA-8 AG Platkin Enforcement, 18-Month Cure Sunset, and Division of Consumer Affairs NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security NGNDPR-6 Data Protection Officer, DPCOs, and Processor Obligations OSFIB13-1 Governance, Risk Management, and Three Lines of Defense OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management OSSFSC-1 Branch Protection, Code Review, and Repository Governance OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements PSDTWO-2 SCA Exemptions and Risk-Based Authentication PERU-3 Data Subject Rights (ARCO), Habeas Data, Automated Decisions PERU-7 DPO, Records, Retention, Marketing, Training QATAR-5 Security of Processing QATAR-7 DPO, Records, Retention, Marketing, Training SUPCHAIN-1 Build Integrity - Source, Build, Provenance SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule SOC2-CC4.2 COSO principle 17: Evaluates and communicates deficiencies in a timely manner SOC2-CC7.4 Responds to identified security incidents through defined procedures C1 Organizational Boundary C3 Scope 1 and 2 Coverage CISABD-1 Take Ownership of Customer Security Outcomes SBD-DEV-04 Phishing-Resistant Authentication APPI-A34 Request for Correction, Addition or Deletion 9.1 Risk communication and consultation 4.4.1 Resources, Roles, Responsibility, and Authority BSI-08 Cryptographic protection of data CA-9 Internal System Connections CA-9 Internal System Connections ICP-1 Objectives, Powers and Responsibilities of the Supervisor 9.1 Risk communication and consultation 9.1 Risk communication and consultation NIS2I-5 Cyber Hygiene, Training, Cryptography, and Human Resources Security CA-9 Internal System Connections CA-9 Internal System Connections CA-9 Internal System Connections NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication NRFCS-1 Retail Cybersecurity Governance, Policy, and Regulatory Change Management NGCB-7 Patron and Employee Data Protection + Data Inventory + Vendor Management NZISM-3 Personnel Security, Physical Security, and Cryptography NGOB-3 API Security Standards, mTLS, and Encryption AUNDB-A3 Eligible Data Breach Determination and Serious Harm Threshold OECDAI-5 Data Governance, Training Data Quality, Privacy, and Bias Mitigation OMANCS-4 Data Protection, Cryptography, and Privacy Alignment PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working 2.2.2 Vendor default accounts are managed as follows: • If the vendor default account(s) will be used, the default password is changed per Requirement 8.3.6. • If the vendor default account(s) will not be used, PARAGUAY-5 Security of Processing, Data Integrity, Information Security PHILCC-1 Computer Crime Offences (Illegal Access, Interference, Misuse of Devices) RCEPEC-1 Online Personal Information Protection (12.13) SCA-S2 Interpretation and Definitions STUDPRV-2 Data Subject Rights for Students and Parents TEF-2 Openness and Transparency UKAI-2 Sector-Specific Regulator Engagement D.1 Incident Response Planning UNESCOAI-2 Principles 4-7: Sustainability, Privacy, Human Oversight, Transparency UNICEFAI-4 Transparency, Explanation, Adult Capacity SO2.2 Digital health architecture blueprint Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Mobile Device Policies Query this from an agent The graph holds this control, the 595 it maps to, and the evidence behind each claim, over MCP and REST.