Frameworks / NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices / MD124-POL-04 NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices
Mobile Device Policies
NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices MD124-POL-04: Mobile Device Lifecycle Management Establish procedures for the complete lifecycle of mobile devices including procurement, provisioning, operation, incident response, and secure disposal.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 21 May 2026 What else in your programme already covers this This control maps to 341 controls across 149 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
API1164-17 Wireless and Field Communications API1164-18 Field Device Security API1164-19 Safety Instrumented Systems Interface API1164-21 TSA Pipeline Security Directive Alignment API1164-22 Configuration management for OT systems API1164-23 Change management procedures IEC62443-16 Incident response plan for operational disruptions IEC62443-17 Recovery plan for critical systems IEC62443-20 Exercises and drills for OT incidents IEC62443-21 Supply chain risk management for critical components IEC62443-22 Configuration management for OT systems IEC62443-23 Change management procedures ISO27019-16 Incident response plan for operational disruptions ISO27019-18 Reporting obligations to authorities ISO27019-20 Exercises and drills for OT incidents ISO27019-22 Configuration management for OT systems ISO27019-23 Change management procedures ISO27019-24 Vulnerability assessment for critical systems NIST-CSF-GV.SC-01 A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders NIST-CSF-ID.AM-04 Inventories of services provided by suppliers are maintained NIST-CSF-ID.IM-04 Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved NIST-CSF-ID.RA-10 Critical suppliers are assessed prior to acquisition NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process NIST-CSF-RS.MA-01 The incident response plan is executed in coordination with relevant third parties once an incident is declared BSI-01 Account management and provisioning BSI-18 Incident response planning and testing BSI-20 Incident reporting and notification BSI-21 Forensic analysis capabilities NDPA-1 Applicability, Scope, and Carve-Outs NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation NDPA-6 Reasonable Security Practices and Incident Response NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission NG-NDPA-2 Lawful Basis, Consent, and Data Protection Principles NG-NDPA-5 Security of Processing, Breach Notification, and DPIA NG-NDPA-6 Data Protection Officer, DPCO, and Processor Agreements SOCI-CIRMP-PHYSICAL CIRMP hazard vector: Physical security and natural hazards SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain SOCI-S30CB Statutory incident response planning SOCI-S35AB Ministerial authorisation for government assistance CPS230-13 Board Accountability for Operational Risk Management CPS230-27 Identification and Escalation of Incidents and Near Misses CPS230-49 Internal Audit Review of Proposed Critical Operation Outsourcing AEO-2 Demonstrated Compliance with Customs Requirements AEO-4 Financial Viability P2-S1 Partnership IS.AR.215 Information Security Incident Response IS.D.OR.225 External Reporting of Information Security Events IS.I.OR.225 External Reporting FFIEC-23 Regulatory reporting requirements FFIEC-24 Customer notification procedures FFIEC-25 Post-incident review and improvement ISO-20400-7.3 Supplier selection ISO-20400-7.4 Contract management and review ISO-20400-7.5 Reviewing and learning ISO-22320-5.2 Incident management process ISO-22320-B Annex B: Incident management plan structure ISO-22320-C Annex C: Incident management task examples 27010-15.1 Incident Management 27010-16.1 Continuity of Sharing 27010-9.2 Authentication of Sources MTCS-Asset-IAM-Cryptography-Multi-Tier-Asset-Inventory-RBAC-MFA-PAM-FIPS-HSM-Quantum-Safe MTCS Asset Mgmt + IAM + Cryptography + Asset Inventory + RBAC + MFA + PAM + FIPS + HSM + Quantum-Safe MTCS-Incident-Business-Continuity-CSC-Data-Protection-72-Hour-Notification-BCP-DR-PDPA MTCS Incident + Business Continuity + CSC Data Protection + 72-Hour Notification + BCP + DR + PDPA MTCS-Logging-Monitoring-Compliance-Audit-SLA-Configuration-SIEM-SOAR-Cloud-Monitoring-CSPM MTCS Logging + Monitoring + Compliance + Audit + SLA + Configuration + SIEM + SOAR + CSPM NISTPF-1 Identify-P - Business Environment, Data Processing Inventory, Ecosystem, and Risk Assessment NISTPF-5 Protect-P Access Control (PR.AC-P) NISTPF-8 Protect-P Information Protection Processes (PR.PO-P) OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery OSFIB13-7 Incident Reporting to OSFI and Regulatory Coordination OSFIB13-8 Metrics, Monitoring, Continuous Improvement, Maturity PCI-P2PE-21 Incident detection and classification PCI-P2PE-22 Incident response and containment PCI-P2PE-25 Post-incident review and improvement PCI-PIN-23 Regulatory reporting requirements PCI-PIN-24 Customer notification procedures PCI-PIN-25 Post-incident review and improvement PCI-SSF-21 Incident detection and classification PCI-SSF-24 Customer notification procedures PCI-SSF-25 Post-incident review and improvement RMI-DD-3 Red Flag Review RMI-MS-2 Cobalt Standard RMI-RMAP-2 Risk-Based Audit Approach PICERL-C2 System Backup PICERL-C3 Long-Term Containment PICERL-L3 Plan Improvement SII-P2-09 Outsourcing Requirements SII-P2-12 Written Policies SII-P3-06 SFCR Section B: System of Governance ISMSP-AC-02 User Account Management ISMSP-PI-03 Third-Party Provision and Outsourcing ISMSP-SYS-05 Incident Response APPI-A41 Preparation and Handling of Pseudonymized Personal Information APPI-A43 Preparation of Anonymized Personal Information CPS234-21 Implementation of Information Security Controls CPS234-25 Internal Audit Review of Information Security Controls ASD37-31 Hunt to discover incidents (Very Good) ASD37-33 Capture network traffic (Limited) CPG-6.A Vendor and Supplier Incident Reporting CPG-6.B Supply Chain Incident Reporting UAE-PDPL-Art.10 Data Protection Officer (DPO) (UAE PDPL Article 10) UAE-PDPL-Art.18_19_20_21 Security measures, controller/processor relationship, DPIA (UAE PDPL Articles 18-21) A.1 Point-of-Care Testing Additional Requirements ISO-15189-6.8 Externally provided products and services ISO28001-PC-03 Supply Chain Incident Reporting ISO28001-PC-04 Supply Chain Continuity Planning ISO27003-4.2 Understanding the needs and expectations of interested parties ISO27003-8.1 Operational planning and control 30111-3 Terms and definitions 30111-5.2 Vulnerability handling team MY-PDPA-Cross-Border-Transfer-Section-129-Whitelist-Abolition-2024-Adequacy-SCC-BCR-Processor-Direct-Marketing Malaysia PDPA Cross-Border + Section 129 + Whitelist Abolition 2024 + Adequacy + SCC + BCR + Processor + Marketing MY-PDPA-Security-Principle-Retention-Data-Integrity-Breach-Notification-72-Hour-Section-12B-2024-Amendment Malaysia PDPA Security + Retention + Data Integrity + Breach Notification 72 Hour + Section 12B + 2024 Amendment NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010) NERCCIP-6 Incident Reporting and Response Planning + Recovery Plans (CIP-008 + CIP-009) NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation NISTSP144-8 Monitoring, Incident Response, Exit Strategy, and Compliance NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity NJDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal NJDPA-6 Reasonable Data Security and Incident Response OMANCS-3 Identity and Access Management, Authentication, Privileged Access OMANCS-6 Security Monitoring, Detection, Incident Response, and OmanCERT Notification OPENBANK-7 Logging, Monitoring, Regulatory Reporting, SLA, Availability OPENBANK-8 Incident Detection, Response, Customer Notification, Post-Incident Review, BCM PASONE-3 Personnel Security, Vetting, Awareness, and Training PASONE-6 Incident Management, Audit, Handover, Operational Phase, Decommissioning PSDTWO-3 Common and Secure Communication, API Access for AISPs and PISPs PSDTWO-4 Fraud Reporting and Incident Management PERU-7 DPO, Records, Retention, Marketing, Training PERU-8 Breach Notification, ANPD Cooperation, Sanctions, Compliance QATAR-5 Security of Processing QATAR-8 Breach Notification, Compliance, Enforcement SASB-1 Business Model + Innovation (BMI) SASB-BMI-3 Supply Chain Management SOC2-CC7.4 CC7.4 Responding to security incidents SOC2-CC7.5 CC7.5 Recovering from security incidents SSAE18-CC7.4 CC7.4 - Incident Response SSAE18-CC7.5 CC7.5 - Incident Recovery SA-PDPL-16 Data breach notification requirements SA-PDPL-17 Security incident response procedures IM8-RES.3 Incident Response IM8-TPM.4 Supply Chain Risk Management PIPA-CPO-DPO-Privacy-Officer-PIA-Personal-Information-Impact-Assessment-Articles-31-33 Korea PIPA CPO + DPO + Privacy Officer + PIA + Personal Information Impact Assessment + Articles 31-33 PIPA-Sensitive-Information-Unique-ID-Resident-Registration-Numbers-CCTV-Articles-23-24-25 Korea PIPA Sensitive Information + Unique ID + RRN + CCTV + Articles 23-25 D.1 Incident Response Planning D.2 Incident Reporting UK-TSA-MON-02 Incident Notification UK-TSA-NET-03 Supply Chain Security CFR211-J-184 Section 211.184 - Component, Drug Product Container, Closure, and Labeling Records PMF-M.4 Privacy Incident Management AS9100D-8.4 Control of Externally Provided Processes, Products, Services 4.4.7 Emergency and Incident Response AWWA-2.3 Account Management ACQ.4 Supplier Monitoring Mat 03 Responsible Sourcing of Materials BB-DPA-20 Sections 50-60 - Registration and Responsibilities CA-12 Deploys Through Policies and Procedures CA-ITSG33-SC-01 Security Control Catalogue CJIS-19 Supply Chain Risk Management CAT-D5-1 Incident planning and strategy FTC-Safeguards-IR-Plan-BoardReporting-FTC-Notification Written Incident Response Plan + Board Reporting + FTC Breach Notification (16 CFR 314.4(h), (i), (j)) Sapin2-Pillar4-ThirdParty-DueDiligence Pillar 4 - Third-Party Due Diligence (Clients, Suppliers, Intermediaries, M&A) ICAO-ANX17-Chap4-Cargo-Mail-Catering-Stores-Supplies-RegulatedAgent-KnownConsignor ICAO Annex 17 Chapter 4 - Cargo + Mail + Catering + Stores + Supplies Security + Regulated Agent + Known Consignor + Supply Chain ISO22316-14 Supply chain continuity ISO-26000-6.6 Fair operating practices ISO-41001-8.4 Control of outsourced processes and services ISO-50001-8.3 Procurement ISO20000-11 Incident management ISO23894-A.6 AI System Security 27011-5.6 Supplier relationships and telecom supply chain ISO27043-12 User access management and provisioning 27400-6.5 Security monitoring and incident response ISO21434-12 User access management and provisioning ISO22317-14 Supply chain continuity ISO22318-14 Supply chain continuity ITIL4-11 Incident management MU-DPA-Governance-DPO-Designation-Section-25-DPO-ROPA-DPIA-Codes-Section-38-Commissioner-Registration Mauritius DPA Governance + DPO + ROPA + DPIA + Codes Section 38 + Commissioner Registration MX-LFPDPPP-Governance-Officer-Reglamento-47-50-Security-Manual-57-Risk-Assessment-61-Self-Regulation-Parameters-2014 Mexico LFPDPPP Governance + Officer + Reglamento 47 + Security Manual 50 + Risk Assessment 57 + Self-Regulation Parameters 2014 MN-CDPA-Chief-Privacy-Officer-Section-325O-06-MN-UNIQUE-Designation-Privacy-Programme-Training Minnesota CDPA Chief Privacy Officer + Section 325O.06 + MINNESOTA-UNIQUE Designation + Privacy Programme + Training MT-CDPA-Sensitive-Data-MCA-30-14-2802-Opt-In-Children-13-Parental-Consent-Minors-13-16-Opt-In Montana CDPA Sensitive Data + MCA 30-14-2802 + Affirmative Opt-In + Children Under 13 Parental + Minors 13-16 Opt-In NFPA1600-6.3 Emergency Response Operations NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material NISTSP123-3 Authentication, Access Control, and Account Management NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition NISTSP61-5 Containment, Eradication, and Recovery NISTSP63R4-4 Authenticator Lifecycle: Binding, Recovery, Replacement, Suspension, Revocation NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control NRFCS-7 Detection, Logging, Incident Response, Breach Notification, and Fraud Detection NGCB-6 Incident Response, 72-Hour NGCB Notification, and Independent Investigation NHPA-6 Reasonable Data Security and Breach Response NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security NGOB-5 Fraud Monitoring, Incident Notification, and Reporting to CBN ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management OECDMNE-5 Environment, Climate, and Biodiversity OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns OREGONCPA-3 Consent, Sensitive Data, Children and Teen Protections PDPASG-8 Data Breach Notification, Incident Response, and Enforcement PDPATH-8 Data Breach Notification, Complaints, Compliance, Enforcement PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations PTESPHASE-2 Intelligence Gathering (OSINT) PNGCYBER-4 Incident Response, Investigation, Evidence Preservation, Data Retention NORWAY-8 Breach Notification, Complaints, Compliance, Enforcement NZPRV-7 Notifiable Privacy Breach Scheme PSPF-DIR-001-2024 Direction 001-2024: Foreign Ownership, Control or Influence - Technology Assets SAEIGHT-7 Management System, Worker Engagement, Continuous Improvement SHAREASSESS-2 Access Control, Identity, Authentication SUPCHAIN-1 Build Integrity - Source, Build, Provenance SOC-CY-S2 System Operations GT-3 Supply Chain Compromise TSAPIPE-2 OT/IT Network Segmentation and Access Control TAIWAN-3 Data Subject Rights TANZANIA-4 Security and Cross-Border TSSR-NOT-2 Security Incident Notification TEXASTDPSA-2 Consumer Rights TRINIDAD-3 Data Subject Rights UKOPRES-5 Third-Party Risk, Concentration Risk UKGDPRREG-3 Controller and Processor (Articles 24-43) UKGAMBLE-4 Resilience and Incident Response OB-OPS.4 Incident Management SEMD-PS-3 Supply Chain Security CYB-5 Cyber Incident Response Plan URUGUAY-4 Security and Cross-Border VIETNAMPDP-2 Consent and Notice VIRGINIAVCDPA-3 Sensitive Data Consent and Children Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Mobile Device Policies Query this from an agent The graph holds this control, the 341 it maps to, and the evidence behind each claim, over MCP and REST.