GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

INF-017 Managed Endpoint Baseline

Tier 1+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Every endpoint used to access, process or store organisational or customer data is enrolled in centralised device management and recorded in an endpoint inventory with its user, platform and current compliance state. Enrolled devices encrypt their storage, lock the screen automatically after a defined period of inactivity and conceal displayed content until the user re-authenticates, run only applications from an approved list and take operating system and application updates through change management. Removable media and peripheral connections are restricted to approved devices and connection ports and interfaces that are not needed are disabled. A device that is lost or whose user leaves can be located and wiped remotely. Every device is sanitised so that stored data cannot be recovered before it is disposed of or reissued.

Rationale

The laptop is the one piece of infrastructure a cloud-native provider still owns outright. It holds copies of production data, source code and live session tokens. The coverage review found the endpoint requirements of four frameworks read against production-system controls that do not cover them, which is why NIST AC-11, ISO 8.1 and CSA UEM-08 move here. INF-009 holds malware and endpoint detection tooling on the same devices, INF-008 holds patching of production systems, DAT-017 holds detection and prevention of data exfiltration, DAT-008 holds retention and deletion of the data itself and HRS-008 holds the rules for the person using the device away from the office. The device management platform is a single evidence source for most of this control: enrolment, encryption state, lock policy, installed applications and wipe capability are all readable from it, which is what makes the compliance export the primary artefact.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
HIPAA Business Associate (US)stablerequiredrole duty

164.310(c) makes workstation security a required standard over every device that reaches the data, and the 164.304 definition of workstation reaches the electronic media stored around it. The disposal and media re-use specifications at 164.310(d)(2) are required rather than addressable.

NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (44)

DCS-02Off-Site Equipment Disposal Policy and Proceduresfull
UEM-01Endpoint Devices Policy and Proceduresfull
UEM-02Application and Service Approvalfull
UEM-03Compatibilityinformative
UEM-04Endpoint Inventoryfull
UEM-06Automatic Lock Screenfull
UEM-07Operating Systemsfull
UEM-08Storage Encryptionfull
UEM-11Data Loss Preventionpartial
UEM-12Remote Locatefull
UEM-13Remote Wipefull
DCS-02Off-Site Equipment Disposal Policy and Proceduresfull
UEM-01Endpoint Devices Policy and Proceduresfull
UEM-02Application and Service Approvalfull
UEM-03Compatibilityinformative
UEM-04Endpoint Inventoryfull
UEM-06Automatic Lock Screenfull
UEM-07Operating Systemsfull
UEM-08Storage Encryptionfull
UEM-11Data Loss Preventionpartial
UEM-12Remote Locatefull
UEM-13Remote Wipefull
HIPAA-164.310.bWorkstation Useinformative
HIPAA-164.310.cWorkstation Securityfull
HIPAA-164.310.d.1Device and Media Controlspartial
HIPAA-164.310.d.2.iDisposalfull
HIPAA-164.310.d.2.iiMedia Re-usefull
HIPAA-164.310.d.2.iiiAccountabilityinformative
HIPAA-164.312.a.2.iiiAutomatic Logoffinformative
7.10Storage mediapartial
7.14Secure disposal or re-use of equipmentfull
7.9Security of assets off-premisesfull
8.1User endpoint devicesfull
NIS2-CIR-12.3Removable Media Policypartial
AC-11Device Lockfull
AC-11(1)Device Lock | Pattern-hiding Displaysfull
AC-19Access Control for Mobile Devicesfull
AC-19(5)Access Control for Mobile Devices | Full Device or Container-based Encryptionfull
AC-20(2)Use of External Systems | Portable Storage Devices — Restricted Usepartial
CM-7(9)Least Functionality | Prohibiting The Use of Unauthorized Hardwarepartial
MP-7Media Usepartial
SC-41Port and I/O Device Accessfull
SR-12Component Disposalpartial
CC6.5Logical and Physical Protections Over Physical Assetsfull

Evidence (3)

system_exporttechnicalautomated

Device compliance export from the endpoint management platform listing every enrolled device with its user, platform, operating system version, storage encryption state, lock policy state and last check-in.

Example: Endpoint management compliance report, 2026-09-02, listing 214 enrolled devices with encryption, lock and update status per device and the count of devices failing each check.

Test: Export the device compliance report and the current workforce list. Verify: (1) every person with access to organisational or customer data has at least one enrolled device or a recorded exception, (2) storage encryption is on for every enrolled device, (3) the screen lock policy is applied to every enrolled device within the defined inactivity period, (4) devices are running a supported operating system version within the defined update window, (5) devices that have not checked in beyond the defined period have a recorded disposition.

configurationtechnicalautomated

Endpoint management policy configuration showing the enforced settings: encryption, inactivity lock and content concealment, the approved application list, removable media and peripheral restrictions, disabled ports and the remote locate and wipe capability.

Example: Configuration profiles applied to the macOS and Windows device groups, exported 2026-09-02, with the enforced setting and its scope for each item in the endpoint standard.

Test: Read the configuration profiles applied to each managed platform. Verify: (1) each requirement in the endpoint standard maps to an enforced setting rather than to guidance, (2) the lock policy conceals displayed content and requires re-authentication, (3) application installation is limited to the approved list or approved sources, (4) removable media and peripheral connections are restricted and unused ports are disabled, (5) remote locate and remote wipe are enabled on the platforms that support them, (6) a sampled device reports the profile as applied rather than pending.

recorddocumentmanual

Device disposal and reissue records showing, for each device leaving service or changing user, the sanitisation method applied and the verification of the result.

Example: Asset disposal register for 2026, listing 18 devices with the sanitisation method, the operator, the verification date and the certificate of destruction where a third party carried it out.

Test: Request the disposal and reissue records for the period and reconcile them against the endpoint inventory. Verify: (1) every device removed from the inventory has a disposal or reissue record, (2) each record names the sanitisation method and a verification of the result rather than an intention, (3) records exist for devices returned by leavers as well as for retired hardware, (4) where a third party performed the destruction, a certificate is held and names the devices.

Questions (3)

boolean

Is every endpoint used to access organisational or customer data enrolled in centralised device management?

Enrolment is what makes the rest of this control testable from one export. Personal devices used for work count; if they are permitted without enrolment, the answer is no.

multi

Which of the following are enforced on managed endpoints by the management platform?

Storage encryptionAutomatic screen lock that conceals displayed contentInstallation limited to an approved application list or approved sourcesOperating system and application updates delivered through change managementRemovable media and peripheral connections restrictedRemote locateRemote wipeVerified sanitisation before disposal or reissueNone of the above

Count a setting only where the platform enforces it and reports compliance. A rule written in the endpoint standard and left to the user is not enforcement.

select

How is the endpoint inventory kept accurate?

The platform enrols devices automatically and the inventory is reconciled against the workforce list on a defined cycleThe inventory is reconciled against the workforce list on a defined cycleThe inventory is updated when a device is issued or returnedThe inventory is compiled when it is asked forThere is no endpoint inventory

Options run from strongest to weakest. The failure this measures is the device nobody removed when its user left, which only a reconciliation against the workforce list finds.