INF-017 Managed Endpoint Baseline
Description
Every endpoint used to access, process or store organisational or customer data is enrolled in centralised device management and recorded in an endpoint inventory with its user, platform and current compliance state. Enrolled devices encrypt their storage, lock the screen automatically after a defined period of inactivity and conceal displayed content until the user re-authenticates, run only applications from an approved list and take operating system and application updates through change management. Removable media and peripheral connections are restricted to approved devices and connection ports and interfaces that are not needed are disabled. A device that is lost or whose user leaves can be located and wiped remotely. Every device is sanitised so that stored data cannot be recovered before it is disposed of or reissued.
Rationale
The laptop is the one piece of infrastructure a cloud-native provider still owns outright. It holds copies of production data, source code and live session tokens. The coverage review found the endpoint requirements of four frameworks read against production-system controls that do not cover them, which is why NIST AC-11, ISO 8.1 and CSA UEM-08 move here. INF-009 holds malware and endpoint detection tooling on the same devices, INF-008 holds patching of production systems, DAT-017 holds detection and prevention of data exfiltration, DAT-008 holds retention and deletion of the data itself and HRS-008 holds the rules for the person using the device away from the office. The device management platform is a single evidence source for most of this control: enrolment, encryption state, lock policy, installed applications and wipe capability are all readable from it, which is what makes the compliance export the primary artefact.
Applicability (9 profiles)
164.310(c) makes workstation security a required standard over every device that reaches the data, and the 164.304 definition of workstation reaches the electronic media stored around it. The disposal and media re-use specifications at 164.310(d)(2) are required rather than addressable.
Framework Mappings (44)
| DCS-02 | Off-Site Equipment Disposal Policy and Procedures | full |
| UEM-01 | Endpoint Devices Policy and Procedures | full |
| UEM-02 | Application and Service Approval | full |
| UEM-03 | Compatibility | informative |
| UEM-04 | Endpoint Inventory | full |
| UEM-06 | Automatic Lock Screen | full |
| UEM-07 | Operating Systems | full |
| UEM-08 | Storage Encryption | full |
| UEM-11 | Data Loss Prevention | partial |
| UEM-12 | Remote Locate | full |
| UEM-13 | Remote Wipe | full |
| DCS-02 | Off-Site Equipment Disposal Policy and Procedures | full |
| UEM-01 | Endpoint Devices Policy and Procedures | full |
| UEM-02 | Application and Service Approval | full |
| UEM-03 | Compatibility | informative |
| UEM-04 | Endpoint Inventory | full |
| UEM-06 | Automatic Lock Screen | full |
| UEM-07 | Operating Systems | full |
| UEM-08 | Storage Encryption | full |
| UEM-11 | Data Loss Prevention | partial |
| UEM-12 | Remote Locate | full |
| UEM-13 | Remote Wipe | full |
| HIPAA-164.310.b | Workstation Use | informative |
| HIPAA-164.310.c | Workstation Security | full |
| HIPAA-164.310.d.1 | Device and Media Controls | partial |
| HIPAA-164.310.d.2.i | Disposal | full |
| HIPAA-164.310.d.2.ii | Media Re-use | full |
| HIPAA-164.310.d.2.iii | Accountability | informative |
| HIPAA-164.312.a.2.iii | Automatic Logoff | informative |
| 7.10 | Storage media | partial |
| 7.14 | Secure disposal or re-use of equipment | full |
| 7.9 | Security of assets off-premises | full |
| 8.1 | User endpoint devices | full |
| NIS2-CIR-12.3 | Removable Media Policy | partial |
| AC-11 | Device Lock | full |
| AC-11(1) | Device Lock | Pattern-hiding Displays | full |
| AC-19 | Access Control for Mobile Devices | full |
| AC-19(5) | Access Control for Mobile Devices | Full Device or Container-based Encryption | full |
| AC-20(2) | Use of External Systems | Portable Storage Devices — Restricted Use | partial |
| CM-7(9) | Least Functionality | Prohibiting The Use of Unauthorized Hardware | partial |
| MP-7 | Media Use | partial |
| SC-41 | Port and I/O Device Access | full |
| SR-12 | Component Disposal | partial |
| CC6.5 | Logical and Physical Protections Over Physical Assets | full |
Evidence (3)
Device compliance export from the endpoint management platform listing every enrolled device with its user, platform, operating system version, storage encryption state, lock policy state and last check-in.
Example: Endpoint management compliance report, 2026-09-02, listing 214 enrolled devices with encryption, lock and update status per device and the count of devices failing each check.
Test: Export the device compliance report and the current workforce list. Verify: (1) every person with access to organisational or customer data has at least one enrolled device or a recorded exception, (2) storage encryption is on for every enrolled device, (3) the screen lock policy is applied to every enrolled device within the defined inactivity period, (4) devices are running a supported operating system version within the defined update window, (5) devices that have not checked in beyond the defined period have a recorded disposition.
Endpoint management policy configuration showing the enforced settings: encryption, inactivity lock and content concealment, the approved application list, removable media and peripheral restrictions, disabled ports and the remote locate and wipe capability.
Example: Configuration profiles applied to the macOS and Windows device groups, exported 2026-09-02, with the enforced setting and its scope for each item in the endpoint standard.
Test: Read the configuration profiles applied to each managed platform. Verify: (1) each requirement in the endpoint standard maps to an enforced setting rather than to guidance, (2) the lock policy conceals displayed content and requires re-authentication, (3) application installation is limited to the approved list or approved sources, (4) removable media and peripheral connections are restricted and unused ports are disabled, (5) remote locate and remote wipe are enabled on the platforms that support them, (6) a sampled device reports the profile as applied rather than pending.
Device disposal and reissue records showing, for each device leaving service or changing user, the sanitisation method applied and the verification of the result.
Example: Asset disposal register for 2026, listing 18 devices with the sanitisation method, the operator, the verification date and the certificate of destruction where a third party carried it out.
Test: Request the disposal and reissue records for the period and reconcile them against the endpoint inventory. Verify: (1) every device removed from the inventory has a disposal or reissue record, (2) each record names the sanitisation method and a verification of the result rather than an intention, (3) records exist for devices returned by leavers as well as for retired hardware, (4) where a third party performed the destruction, a certificate is held and names the devices.
Questions (3)
Is every endpoint used to access organisational or customer data enrolled in centralised device management?
Enrolment is what makes the rest of this control testable from one export. Personal devices used for work count; if they are permitted without enrolment, the answer is no.
Which of the following are enforced on managed endpoints by the management platform?
Count a setting only where the platform enforces it and reports compliance. A rule written in the endpoint standard and left to the user is not enforcement.
How is the endpoint inventory kept accurate?
Options run from strongest to weakest. The failure this measures is the device nobody removed when its user left, which only a reconciliation against the workforce list finds.