NIST SP 800-124 Rev 2 — Mobile Device Security
NIST Special Publication 800-124 Revision 2 provides guidelines for managing and securing mobile devices in enterprise environments. Covers mobile device management (MDM), mobile threat defense, app vetting, BYOD policies, and enterprise mobility management. Addresses smartphones, tablets, and other mobile devices used to process, store, or transmit organizational data.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (11)
Data Protection
| Code | Title |
|---|---|
| 800-124r2-4.1 | Data Protection on Mobile Devices |
| 800-124r2-4.2 | Data Communication Protection |
| 800-124r2-4.3 | Lost or Stolen Device Procedures |
Deployment Models
| Code | Title |
|---|---|
| 800-124r2-6.1 | BYOD Considerations |
| 800-124r2-6.2 | Corporate Owned Device Models |
Governance
| Code | Title |
|---|---|
| 800-124r2-2.2 | Mobile Device Policy |
Identity
| Code | Title |
|---|---|
| 800-124r2-8.1 | Identity and Access Integration |
Lifecycle
| Code | Title |
|---|---|
| 800-124r2-7.1 | Mobile Device Lifecycle Management |
| 800-124r2-7.2 | Mobile Device Decommissioning |
Mobile Device Policies
Organizational policies for mobile device usage, BYOD, and data protection
| Code | Title |
|---|---|
| MD124-POL-01 | Mobile Device Security Policy |
| MD124-POL-02 | BYOD Policy |
| MD124-POL-03 | Mobile Data Protection Policy |
| MD124-POL-04 | Mobile Device Lifecycle Management |
Mobile Device Security Controls
Technical security controls for mobile device configuration and protection
| Code | Title |
|---|---|
| MD124-CTL-01 | Device Authentication and Lock |
| MD124-CTL-02 | Device Encryption |
| MD124-CTL-03 | Remote Wipe Capability |
| MD124-CTL-04 | OS and Application Updates |
| MD124-CTL-05 | Jailbreak/Root Detection |
| MD124-CTL-06 | Network Security for Mobile |
Mobile Device Security Technologies
Enterprise mobility management, mobile threat defense, and app security technologies
| Code | Title |
|---|---|
| MD124-TECH-01 | Enterprise Mobility Management (EMM) |
| MD124-TECH-02 | Mobile Threat Defense (MTD) |
| MD124-TECH-03 | Mobile Application Vetting |
| MD124-TECH-04 | Mobile Application Management (MAM) |
| MD124-TECH-05 | VPN and Secure Communication |
Monitoring and Response
| Code | Title |
|---|---|
| 800-124r2-5.1 | Mobile Threat Defense Monitoring |
| 800-124r2-5.2 | Mobile Operating System Updates |
| 800-124r2-5.3 | User Awareness for Mobile Risks |
| 800-124r2-8.2 | Continuous Compliance Reporting |
Risk Management
| Code | Title |
|---|---|
| 800-124r2-2.1 | Mobile Device Threat Model |
Technical Controls
| Code | Title |
|---|---|
| 800-124r2-3.1 | Enterprise Mobility Management Deployment |
| 800-124r2-3.2 | Device Authentication and Enrollment |
| 800-124r2-3.3 | Device Hardening Baselines |
| 800-124r2-3.4 | Mobile Application Vetting |
| 800-124r2-3.5 | Mobile Application Allow and Deny Lists |
Your Compliance Coverage
If you comply with NIST SP 800-124 Rev 2 — Mobile Device Security, you already cover:
ISO 27043
29%
10 controls mapped
Compare →OWASP MASVS
29%
10 controls mapped
Compare →TISAX — Trusted Information Security Assessment Exchange
29%
10 controls mapped
Compare →+ 618 more: 3GPP Security (29%), ISO 27002:2022 (29%)
See all 621 mapped frameworks ↓Maps to 621 other frameworks
Frequently Asked Questions
What is NIST SP 800-124 Rev 2 — Mobile Device Security?
NIST SP 800-124 Rev 2 — Mobile Device Security is a compliance framework from United States with 11 domains and 34 controls. NIST Special Publication 800-124 Revision 2 provides guidelines for managing and securing mobile devices in enterprise environments. Covers mobile device management (MDM), mobile threat defense, app vetting, BYOD policies, and enterprise mobility management. Addresses smartphones, tablets, and other mobile devices used to process, store, or transmit organizational data. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NIST SP 800-124 Rev 2 — Mobile Device Security have?
NIST SP 800-124 Rev 2 — Mobile Device Security has 34 controls organised across 11 domains. The largest domains are Mobile Device Security Controls (6 controls), Mobile Device Security Technologies (5 controls), Technical Controls (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NIST SP 800-124 Rev 2 — Mobile Device Security map to?
NIST SP 800-124 Rev 2 — Mobile Device Security maps to 621 other compliance frameworks. The top mapping partners are ISO 27043 (29% coverage), OWASP MASVS (29% coverage), TISAX — Trusted Information Security Assessment Exchange (29% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NIST SP 800-124 Rev 2 — Mobile Device Security compliance?
Start your NIST SP 800-124 Rev 2 — Mobile Device Security compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-124 Rev 2 — Mobile Device Security requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 34 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required