NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices
Mobile Device Security Technologies

NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices MD124-TECH-05: VPN and Secure Communication

Configure VPN or per-app VPN for mobile devices accessing enterprise resources. Ensure all enterprise traffic is encrypted.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 201 controls across 98 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-22 Network segmentation (Excellent)
  • ASD37-25 Software firewall - inbound (Very Good)
  • AWWA-3.1 Network Segmentation
  • AWWA-3.2 Remote Access Security
  • AWWA-3.4 Encryption and Data Protection

FedRAMP Rev 5 · 3 controls

  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

ISO/IEC 27043:2015 · 3 controls

  • ISO27043-17 Encryption of data at rest
  • ISO27043-18 Encryption of data in transit
  • ISO27043-27 Network security management

ISO/SAE 21434 · 3 controls

  • ISO21434-17 Encryption of data at rest
  • ISO21434-18 Encryption of data in transit
  • ISO21434-27 Network security management
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection
  • FFIEC-06 Network security and segmentation
  • FFIEC-09 Encryption and key management

ISO 27799:2025 · 2 controls

  • ISO27799-02 ePHI encryption at rest and in transit
  • ISO27799-16 Transmission security and encryption

ISO/IEC 27011:2024 · 2 controls

  • 27011-6.3 Awareness and Training
  • 27011-8.2 Network security and segregation

MITRE ATT&CK · 2 controls

MTCS (Singapore) · 2 controls

  • MTCS-Incident-Business-Continuity-CSC-Data-Protection-72-Hour-Notification-BCP-DR-PDPA MTCS Incident + Business Continuity + CSC Data Protection + 72-Hour Notification + BCP + DR + PDPA
  • MTCS-Operations-Physical-Network-Tier-III-Data-Centre-Hardening-Patching-Network-Segmentation-DDoS MTCS Operations + Physical + Network + Tier III Data Centre + Hardening + Patching + Segmentation + DDoS
  • NAIC-1 NAIC Model Law Adoption, Scope, and Licensee Definitions
  • NAIC-2 Information Security Program (ISP) - Section 4
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTPF-8 Protect-P Information Protection Processes (PR.PO-P)

NIST SP 800-123 · 2 controls

  • NISTSP123-4 Server Cryptography - Encryption, Key Management, Certificates
  • NISTSP123-6 Network Security and Server Communications

NIST SP 800-137 · 2 controls

  • NISTSP137-5 Vulnerability + Patch + Configuration Status Monitoring
  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

NIST SP 800-144 · 2 controls

  • NISTSP144-2 Cloud Architecture, Service Selection, and Tenant Isolation
  • NISTSP144-5 Identity and Access in Cloud, Federation, and Privileged Access

NIST SP 800-145 · 2 controls

  • NISTSP145-6 Deployment Model Classification (Private, Community, Public, Hybrid)
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-4 IaaS Operational Recommendations and Workload Hardening
  • NISTSP146-6 Cloud Security and Privacy Recommendations

NIST SP 800-190 · 2 controls

NIST SP 800-61 Rev. 3 · 2 controls

  • NISTSP61-3 Preparation: Communications, Toolkits, Training, Exercises, Threat Intelligence
  • NISTSP61-4 Detection and Analysis: Sources, Triage, Categorisation, Prioritisation

NIST SP 800-88 · 2 controls

  • NISTSP88-4 Cryptographic Erase, Key Management, and Verification of Erase
  • NISTSP88-8 Cloud-Resident Data, Hosted Storage, and Scope Boundaries

NIST SP 800-92 · 2 controls

  • NISTSP92-3 Log Infrastructure: Architecture, Centralisation, Transport Security, SIEM Governance
  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NDPA-1 Applicability, Scope, and Carve-Outs
  • NDPA-7 Data Protection Assessments and Processor Contracts
  • NZISM-3 Personnel Security, Physical Security, and Cryptography
  • NZISM-5 Network Security, System Hardening, and Application Security
  • NG-NDPA-1 Scope, Applicability, and Establishment of Nigeria Data Protection Commission
  • NG-NDPA-7 Cross-Border Data Transfers and International Cooperation

OWASP SAMM · 2 controls

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management
  • OMANCS-4 Data Protection, Cryptography, and Privacy Alignment
  • OMANCS-5 Network, Endpoint, System Development, and Configuration Security

OpenSSF Scorecard · 2 controls

  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns
  • OSSFSC-6 Signed Releases, Provenance, Trusted Publishing, Binary Artifacts

PCI P2PE · 2 controls

  • PCI-P2PE-06 Network security and segmentation
  • PCI-P2PE-09 Encryption and key management

PCI PIN Security · 2 controls

  • PCI-PIN-06 Network security and segmentation
  • PCI-PIN-09 Encryption and key management

PCI SSF · 2 controls

  • PCI-SSF-06 Network security and segmentation
  • PCI-SSF-09 Encryption and key management

PSD2 SCA · 2 controls

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication

PTES · 2 controls

  • PTESPHASE-3 Threat Modeling
  • PTESPHASE-4 Vulnerability Analysis
  • SHAREASSESS-3 Network Security, Endpoint, Data Protection
  • SHAREASSESS-4 Vulnerability Management, Patching, Application Security

SLSA · 2 controls

  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • SUPCHAIN-3 Dependency Verification and SBOM
  • IM8-CLD.2 Cloud Security Controls
  • IM8-SEC.3 Network Security

South Korea ISMS-P · 2 controls

  • ISMSP-AC-04 Network Access Control
  • ISMSP-SYS-02 Encryption Implementation
  • US-ITAR-EAR-DS-01 Technical Data Protection
  • US-ITAR-EAR-DS-02 Cloud and Storage

API 1164 · 1 control

  • API1164-13 Business Continuity and Recovery

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion

BSI IT-Grundschutz · 1 control

  • BSI-08 Cryptographic protection of data

Bahrain PDPL · 1 control

  • CAT-D3-1 Preventative controls
  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • 62351-9 Cyber security key management

IEC 62443 · 1 control

  • IEC62443-13 Network security monitoring
  • ISO28001-PS-01 Facility Security

ISO/IEC 27010:2015 · 1 control

  • 27010-13.1 Communications Security

ISO/IEC 27019:2024 · 1 control

  • ISO27019-13 Network security monitoring

ISO/IEC 27400:2022 · 1 control

  • 27400-6.2 Device Identity and Authentication
  • MDS2-PHI-Data-Handling-DATA-Storage-STCF-Transmission-TXCF-TXIG-Encryption-FIPS MDS2 PHI Handling + DATA + STCF Storage + TXCF Transmission + TXIG Integrity + Encryption + FIPS

Malaysia PDPA 2010 · 1 control

  • MY-PDPA-Sensitive-Personal-Data-Section-40-Health-Religious-Political-Sexual-Children-Explicit-Consent Malaysia PDPA Sensitive Personal Data + Section 40 + Health + Religious + Political + Children + Explicit Consent

Mauritius DPA · 1 control

  • MU-DPA-Sensitive-Personal-Data-Section-24-Health-Biometric-Genetic-Sexual-Section-25-Children-16 Mauritius DPA Sensitive Data + Section 24 + Health + Biometric + Genetic + Sexual + Section 25 + Children 16

Mexico LFPDPPP · 1 control

  • MX-LFPDPPP-Sensitive-Article-3-VI-Genetic-Health-Sexual-Religious-Article-9-Minors-18-Parental-Consent Mexico LFPDPPP Sensitive Data + Article 3 Section VI + Genetic + Health + Sexual + Religious + Article 9 Minors + Parental Consent
  • MN-CDPA-Universal-Opt-Out-GPC-Sensitive-Data-Section-325O-02-Consumer-Health-Data-Children-Known-Child-Transgender Minnesota CDPA Universal Opt-Out + GPC + Sensitive + Section 325O.02 + Consumer Health Data + Children + Known Child + Transgender
  • MT-CDPA-Universal-Opt-Out-Mechanism-1-January-2025-GPC-Global-Privacy-Control-Mandatory-Recognition Montana CDPA Universal Opt-Out Mechanism + 1 January 2025 + GPC + Global Privacy Control + Mandatory Recognition
  • MMCL-5 Content Moderation, Removal Requests, and Lawful Access

NERC CIP · 1 control

  • NERCCIP-5 System Security Management + Configuration Change Management and Vulnerability Assessments (CIP-007 + CIP-010)

NIST SP 1800-32 · 1 control

  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-122 · 1 control

  • NISTSP122-5 PII Security Controls - Encryption, Access Control, Storage, Audit

NIST SP 800-63-4 · 1 control

  • NISTSP63R4-5 Federation: Assertions, Trust Agreements, RP Validation, Pseudonymous Identifiers

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication
  • NISTSP82-2 OT Risk Assessment and Threat/Vulnerability Identification
  • NHPA-6 Reasonable Data Security and Breach Response
  • NJDPA-7 Data Protection Assessments and Processor Contracts
  • NGNDPR-5 Security of Personal Data, Breach Notification, and DPIA under NDPR Section 2.6-Security
  • NGOB-3 API Security Standards, mTLS, and Encryption
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul

OSFI B-13 · 1 control

  • OSFIB13-3 Cyber Security: Identification, Protection, Detection, Response, Recovery
  • OPENBANK-3 Mutual TLS, Token Binding, Request Signing (JWS), Key Management
  • OREGONCPA-7 Processor Contracts, Cross-Border Transfers, DPAs
  • PASONE-4 Technical Security: CDE Configuration, BIM Tools, Encryption, Aggregation, Mobile Working

PDPA Singapore · 1 control

  • PDPASG-5 Protection, Accuracy, and Security of Personal Data

PDPA Thailand · 1 control

  • PDPATH-5 Security Measures and Data Protection

POPIA · 1 control

  • POPIASA-5 Security Safeguards, Encryption, Access Control, Operator Obligations
  • NORWAY-5 Security of Processing, Encryption, Pseudonymization, Access Control

Peru DPL · 1 control

  • PERU-7 DPO, Records, Retention, Marketing, Training

Privacy Act 2020 · 1 control

  • NZPRV-2 IPP 5 Storage and Security of Personal Information

Qatar DPL · 1 control

  • QATAR-5 Security of Processing
  • SOC-CY-C2 Encryption and Data Protection

Saudi Arabia PDPL · 1 control

  • SA-PDPL-13 Encryption of personal data
  • CISABD-1 Take Ownership of Customer Security Outcomes
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control

Taiwan PDPA · 1 control

  • TAIWAN-2 Consent, Notice, Sensitive Data
  • TEXASTDPSA-2 Consumer Rights
  • OB-SEC.2 Transport Layer Security
  • CPSC-CS.1 Network Security for Connected Products

Uruguay DPL · 1 control

  • URUGUAY-3 Sensitive Data, Health Data, Children

Vietnam PDPD · 1 control

  • VIETNAMPDP-2 Consent and Notice

Virginia CDPA · 1 control

  • VIRGINIAVCDPA-2 Consumer Rights

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Mobile Device Security Technologies

Query this from an agent

The graph holds this control, the 201 it maps to, and the evidence behind each claim, over MCP and REST.