SekitCrosswalk
ISO/IEC 27001:2022 · derived mapping target

A.8.1User endpoint devices

Protect the information stored on or accessed through user devices like laptops and phones, including configuration, encryption and handling of lost devices.

Mapped from the Sekit CSF

The Sekit controls that cover this requirement, lens by lens.

RCF-0081Session management · TechnicalsupportsThe session management technical facet enforces automatic screen lock and timeout on every device through central configuration, one control A.8.1 expects on user endpoints.RCF-0096Encryption at rest · TechnicalsupportsThe encryption-at-rest technical facet enforces full-disk encryption on endpoint devices, addressing the data-protection half of what A.8.1 requires for user devices.RCF-0146Configuration baselines · ProcesssupportsThe configuration baseline process facet applies the approved device settings at deployment and after significant changes, keeping A.8.1's hardening requirement current over time.RCF-0151MDM/MAM · PolicysupportsThe MDM policy facet requires any work-connected phone or tablet to enroll in mobile management first, the written rule A.8.1 needs for mobile endpoints.RCF-0152MDM/MAM · ProcesssupportsThe MDM process facet enrolls every work-connected mobile device before it reaches company data and keeps enrolment records matched to reality.RCF-0153MDM/MAM · TechnicalenablesThe MDM technical facet enables passcode, encryption, and OS-version rules to be enforced on enrolled devices, plus a remote wipe for a lost or offboarded device.RCF-0161Device hardening · ProcesssupportsThe device hardening process facet disables unnecessary services and applies the approved tightening steps at build time, part of A.8.1's configuration expectation.RCF-0164Disk encryption · ProcesssupportsThe disk encryption process facet verifies encryption is enabled and recovery keys are escrowed on every in-scope device, the operational check A.8.1 needs.RCF-0165Disk encryption · TechnicalenablesThe disk encryption technical facet enables fleet-wide encryption status to be read from the management platform rather than taken on trust device by device.

NIST CSF 2.0 counterparts

Reached through the Sekit CSF controls both map to — a mapping, not a formal equivalence.

Cyber Essentials counterparts

Evidence that proves this control

What an auditor, or Sekit's evidence engine, asks for.

Endpoint protection console
The antivirus or advanced protection (EDR) tool installed on devices, and proof that it is deployed and up to date across the fleet.
Disk encryption evidence
The proof that laptops and devices handling sensitive data have full-disk encryption (BitLocker, FileVault or similar).
Device hardening baseline
The secure-configuration standard applied to devices when handed out (default settings, disabled services) and how compliance is checked.
Mobile device management configuration
The tool that manages work phones and tablets, able to enforce security rules and remotely wipe a lost device.
From the Sekit evidence catalog

In practice

Endpoint risk at SMEs usually traces back to devices that were never fully enrolled: a founder's personal laptop with company email, a contractor's phone that was never added to the mobile management system, or a machine handed out before disk encryption was standard. FileVault or BitLocker status often gets checked once at purchase and never verified again, so a device can drift out of compliance after a repair or reimage without anyone noticing. A working setup enforces screen lock and encryption centrally through the device management platform, reads fleet-wide status from that platform instead of trusting self-reported checklists, and can remotely wipe a lost device the moment it is reported missing.

Common gaps

Personal devices used for company email are never enrolled in MDM, so encryption and passcode rules cannot be verified or enforced.
Disk encryption was checked at purchase but never revisited, so a device reimaged after a repair can silently lose its encrypted state.
Nobody can produce a current list of enrolled devices, so a lost or stolen laptop cannot be confirmed as wiped.

Questions your auditor will ask

How do you confirm disk encryption is enabled across the whole device fleet?
The device management platform reports encryption status centrally, so we read fleet-wide compliance instead of trusting individual devices.
What happens to company data when an employee's phone is lost?
The MDM platform triggers a remote wipe of company data on the device the moment the loss is reported.
Is there a baseline configuration applied to every new device?
Yes, the device hardening baseline disables unnecessary services and applies the approved settings before a device ships to a user.
Are personal phones used for work required to enroll in mobile management?
Yes, any phone accessing work email, files, or chat must be enrolled in the mobile management system before access is granted.

Where regulation demands it

NIS2 9.1 requires a cryptography policy covering encryption on endpoint devices, and ENS mp.eq.2 requires workstations to lock automatically after inactivity.
ENS mp.si.4 addresses the transport of devices carrying sensitive data, which full-disk encryption and MDM controls directly protect.

Related controls

Via the shared Sekit CSF topic, not the framework's own index.

Ask Sekura: “What evidence proves A.8.1?”
Also via MCP, free with account