OPS-04Secure Operations
Endpoint and device protection
Devices with access to organizational data are hardened, patched, encrypted and recoverable.
Why it exists
The laptop is the office.
What usually proves it
Device inventory, configuration baseline, encryption evidence.
Smaller organizations
MDM or a documented baseline with proof for each device.
Mapped to
- Fully addressedSOC 2 Trust Services Criteria · CC6.8
- Fully addressedISO/IEC 27001 Annex A · A.8.1
- Fully addressedNIST Cybersecurity Framework · PR.PS-01
- Fully addressedPCI DSS · 5.2
- Fully addressedHIPAA Security Rule · 164.310(c)
- Partially addressedGDPR · Art. 32(1)(a) — Encryption named as an example measure.
- Deliberately absentEU AI Act — Not addressed.
- Deliberately absentNIST AI Risk Management Framework — Not addressed at control level.