Skip to content
compliancebase
ISO 27001A.8 — User endpoint devices

A.8.1

User endpoint devices

ISO 27001 · ISO/IEC 27001:2022 · Last verified August 2026

Objective

Implement security measures for user endpoint devices appropriate to the information accessed.

Points of focus

  • Endpoint inventory
  • MDM baseline (encryption, lock, patch)
  • Conditional access to sensitive apps
  • Separate personal vs corporate where needed

Implementation notes

Require MDM for email and production SSO. Remove local admin by default; use just-in-time elevation. Prefer ChromeOS/managed macOS for support roles that handle customer data. Assign a named owner in the SoA, tie operating evidence to mdm compliance report, and sample the control during internal audit before Stage 2 fieldwork.

Audit tip: Show compliance % encrypted/patched and deny rules for noncompliant devices accessing admin apps.

Evidence auditors typically request:

  • MDM compliance report
  • Endpoint security standard
  • Conditional access policies
  • Exception register for noncompliant devices

Common gaps

  • Shadow IT laptops
  • Unpatched OS on admin workstations
  • Local admin rights for all engineers

Cross-Framework Mapping

FrameworkRequirementImplementation note
ISO 27001A.8.1This control
SOC 2CC6.1, CC6.8Related SOC 2 themes (CC6.1, CC6.8) — map in your crosswalk; not identical requirements.
HIPAA§164.312(a)(1)Related HIPAA themes (§164.312(a)(1)) — map in your crosswalk; not identical requirements.

Primary sources

Frequently Asked Questions

Yes if they access in-scope systems — require MDM or VDI.

Strongly expected for SaaS production access; document the tool and coverage.

A.6.7 is remote working rules; A.8.1 is the technical endpoint control set.

Even without owned data centers, user endpoint devices still applies to how you operate endpoints, IdP, cloud consoles, and vendor services in scope. Exclude controls in the SoA only with a documented, risk-based rationale.

Start with mdm compliance report, assign a named control owner, and retain dated samples from your ticketing or GRC system — not one-off screenshots assembled before audit fieldwork.

Framework versions referenced in this page:

  • ISO/IEC 27001ISO/IEC 27001:2022

Last verified: August 2026 · Primary sources linked above