Protect the information stored on or accessed through user devices like laptops and phones, including configuration, encryption and handling of lost devices.
What an auditor, or Sekit's evidence engine, asks for.
Endpoint protection console
The antivirus or advanced protection (EDR) tool installed on devices, and proof that it is deployed and up to date across the fleet.
Disk encryption evidence
The proof that laptops and devices handling sensitive data have full-disk encryption (BitLocker, FileVault or similar).
Device hardening baseline
The secure-configuration standard applied to devices when handed out (default settings, disabled services) and how compliance is checked.
Mobile device management configuration
The tool that manages work phones and tablets, able to enforce security rules and remotely wipe a lost device.
From the Sekit evidence catalog
In practice
Endpoint risk at SMEs usually traces back to devices that were never fully enrolled: a founder's personal laptop with company email, a contractor's phone that was never added to the mobile management system, or a machine handed out before disk encryption was standard. FileVault or BitLocker status often gets checked once at purchase and never verified again, so a device can drift out of compliance after a repair or reimage without anyone noticing. A working setup enforces screen lock and encryption centrally through the device management platform, reads fleet-wide status from that platform instead of trusting self-reported checklists, and can remotely wipe a lost device the moment it is reported missing.
Common gaps
Personal devices used for company email are never enrolled in MDM, so encryption and passcode rules cannot be verified or enforced.
Disk encryption was checked at purchase but never revisited, so a device reimaged after a repair can silently lose its encrypted state.
Nobody can produce a current list of enrolled devices, so a lost or stolen laptop cannot be confirmed as wiped.
Questions your auditor will ask
How do you confirm disk encryption is enabled across the whole device fleet?
The device management platform reports encryption status centrally, so we read fleet-wide compliance instead of trusting individual devices.
What happens to company data when an employee's phone is lost?
The MDM platform triggers a remote wipe of company data on the device the moment the loss is reported.
Is there a baseline configuration applied to every new device?
Yes, the device hardening baseline disables unnecessary services and applies the approved settings before a device ships to a user.
Are personal phones used for work required to enroll in mobile management?
Yes, any phone accessing work email, files, or chat must be enrolled in the mobile management system before access is granted.
Where regulation demands it
NIS2 9.1 requires a cryptography policy covering encryption on endpoint devices, and ENS mp.eq.2 requires workstations to lock automatically after inactivity.
ENS mp.si.4 addresses the transport of devices carrying sensitive data, which full-disk encryption and MDM controls directly protect.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.