NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices
NIST Special Publication 800-124 Revision 2 provides guidelines for managing the security of mobile devices (including smartphones, tablets, and other portable computing devices) in enterprise environments. It outlines security controls, configuration baselines, and best practices for mobile device management (MDM), mobile application security, BYOD policies, mobile threat defense, and enterprise mobility management, aligning with NIST SP 800‑53 security control families.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (11)
Data Protection
| Code | Title |
|---|---|
| 800-124r2-4.1 | Data Protection on Mobile Devices |
| 800-124r2-4.2 | Data Communication Protection |
| 800-124r2-4.3 | Lost or Stolen Device Procedures |
Deployment Models
| Code | Title |
|---|---|
| 800-124r2-6.1 | BYOD Considerations |
| 800-124r2-6.2 | Corporate Owned Device Models |
Governance
| Code | Title |
|---|---|
| 800-124r2-2.2 | Mobile Device Policy |
Identity
| Code | Title |
|---|---|
| 800-124r2-8.1 | Identity and Access Integration |
Lifecycle
| Code | Title |
|---|---|
| 800-124r2-7.1 | Mobile Device Lifecycle Management |
| 800-124r2-7.2 | Mobile Device Decommissioning |
Mobile Device Policies
Organizational policies for mobile device usage, BYOD, and data protection
| Code | Title |
|---|---|
| MD124-POL-01 | Mobile Device Security Policy |
| MD124-POL-02 | BYOD Policy |
| MD124-POL-03 | Mobile Data Protection Policy |
| MD124-POL-04 | Mobile Device Lifecycle Management |
Mobile Device Security Controls
Technical security controls for mobile device configuration and protection
| Code | Title |
|---|---|
| MD124-CTL-01 | Device Authentication and Lock |
| MD124-CTL-02 | Device Encryption |
| MD124-CTL-03 | Remote Wipe Capability |
| MD124-CTL-04 | OS and Application Updates |
| MD124-CTL-05 | Jailbreak/Root Detection |
| MD124-CTL-06 | Network Security for Mobile |
Mobile Device Security Technologies
Enterprise mobility management, mobile threat defense, and app security technologies
| Code | Title |
|---|---|
| MD124-TECH-01 | Enterprise Mobility Management (EMM) |
| MD124-TECH-02 | Mobile Threat Defense (MTD) |
| MD124-TECH-03 | Mobile Application Vetting |
| MD124-TECH-04 | Mobile Application Management (MAM) |
| MD124-TECH-05 | VPN and Secure Communication |
Monitoring and Response
| Code | Title |
|---|---|
| 800-124r2-5.1 | Mobile Threat Defense Monitoring |
| 800-124r2-5.2 | Mobile Operating System Updates |
| 800-124r2-5.3 | User Awareness for Mobile Risks |
| 800-124r2-8.2 | Continuous Compliance Reporting |
Risk Management
| Code | Title |
|---|---|
| 800-124r2-2.1 | Mobile Device Threat Model |
Technical Controls
| Code | Title |
|---|---|
| 800-124r2-3.1 | Enterprise Mobility Management Deployment |
| 800-124r2-3.2 | Device Authentication and Enrollment |
| 800-124r2-3.3 | Device Hardening Baselines |
| 800-124r2-3.4 | Mobile Application Vetting |
| 800-124r2-3.5 | Mobile Application Allow and Deny Lists |
Your Compliance Coverage
If you comply with NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices, you already cover:
ISO 27043
29%
10 controls mapped
Compare →OWASP MASVS
29%
10 controls mapped
Compare →TISAX - Trusted Information Security Assessment Exchange
29%
10 controls mapped
Compare →+ 618 more: 3GPP Security (29%), ISO 27002:2022 (29%)
See all 621 mapped frameworks ↓Maps to 621 other frameworks
Frequently Asked Questions
What is NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices?
NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices is a compliance framework from United States with 11 domains and 34 controls. NIST Special Publication 800-124 Revision 2 provides guidelines for managing the security of mobile devices (including smartphones, tablets, and other portable computing devices) in enterprise environments. It outlines security controls, configuration baselines, and best practices for mobile device management (MDM), mobile application security, BYOD policies, mobile threat defense, and enterprise mobility management, aligning with NIST SP 800‑53 security control families. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices have?
NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices has 34 controls organised across 11 domains. The largest domains are Mobile Device Security Controls (6 controls), Mobile Device Security Technologies (5 controls), Technical Controls (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices map to?
NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices maps to 621 other compliance frameworks. The top mapping partners are ISO 27043 (29% coverage), OWASP MASVS (29% coverage), TISAX - Trusted Information Security Assessment Exchange (29% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices compliance?
Start your NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 34 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 768 frameworks.
Get Started Free →Free forever — no credit card required