OPS-04Secure Operations

Endpoint and device protection

Devices with access to organizational data are hardened, patched, encrypted and recoverable.

Why it exists

The laptop is the office.

What usually proves it

Device inventory, configuration baseline, encryption evidence.

Smaller organizations

MDM or a documented baseline with proof for each device.

Mapped to

  • Fully addressedSOC 2 Trust Services Criteria · CC6.8
  • Fully addressedISO/IEC 27001 Annex A · A.8.1
  • Fully addressedNIST Cybersecurity Framework · PR.PS-01
  • Fully addressedPCI DSS · 5.2
  • Fully addressedHIPAA Security Rule · 164.310(c)
  • Partially addressedGDPR · Art. 32(1)(a) — Encryption named as an example measure.
  • Deliberately absentEU AI Act — Not addressed.
  • Deliberately absentNIST AI Risk Management Framework — Not addressed at control level.