What is ISO 27001 Annex A 8.1 – User Endpoint Devices?
ISO 27001 Annex A 8.1 focuses on protecting user endpoint devices that access, process, store, or transmit organizational information.
Endpoint devices are the devices employees, contractors, and other authorized users use to connect to company systems.
Examples include:
- Laptops
- Desktop computers
- Mobile phones
- Tablets
- Workstations
- Thin clients
- Corporate-managed devices
- In some environments, personally owned devices used for business purposes
These devices can access sensitive systems such as:
- Cloud applications
- Source-code repositories
- Customer systems
- CRM
- HR systems
- Financial applications
- VPN
- SaaS platforms
- Production environments
Simple explanation: If a device can access company information, the organization needs appropriate security controls to protect that device and the information it can access.
Why is ISO 27001 Annex A 8.1 Important?
Modern organizations often have more information flowing through laptops and mobile devices than through traditional office servers.
A single employee laptop may have access to:
- Customer information
- Company email
- Source code
- Internal documents
- Cloud applications
- VPN
- Security tools
- Business applications
- Credentials or authentication sessions
If that endpoint is stolen, compromised, misconfigured, or infected with malware, an attacker may use it as a starting point for a larger security incident.
Common endpoint risks
| Risk | Example |
|---|---|
| Device theft | Employee laptop stolen from a vehicle |
| Malware | Malicious software compromises the endpoint |
| Phishing | Employee enters credentials into a fake website |
| Unpatched software | Vulnerability exploited through outdated software |
| Weak authentication | Device account protected by weak credentials |
| Unencrypted storage | Lost laptop exposes locally stored information |
| Unauthorized software | User installs risky applications |
| USB malware | Malicious removable device infects endpoint |
| Excessive privileges | Standard user has unnecessary administrative access |
| Remote-work exposure | Device used from insecure locations |
| Lost mobile device | Business email remains accessible |
| Unsupported software | Old OS no longer receives security updates |
Simple principle: An endpoint is not just an employee’s computer—it is a gateway to organizational information and systems.
What Does Annex A 8.1 Require?
Organizations should establish appropriate security measures for user endpoint devices based on:
- Information sensitivity
- Business requirements
- Threat environment
- Device type
- Device ownership
- User role
- Access privileges
- Remote-working requirements
- Regulatory requirements
- Customer requirements
- Organizational risk
The organization should define and enforce rules for the secure use of endpoint devices.
Controls may include:
- Device inventory
- Endpoint configuration standards
- Strong authentication
- Encryption
- Automatic screen locking
- Endpoint protection
- Anti-malware
- Patch management
- Application controls
- Firewall configuration
- Device management
- Mobile device management
- Remote wipe
- Backup
- Logging and monitoring
- Secure configuration
- Administrative privilege management
- Lost/stolen-device reporting
The controls should be proportionate to risk.
A five-person startup does not necessarily need the same endpoint-management architecture as a large bank.
What Are User Endpoint Devices?
A useful way to understand this control is:
Any device used by a user to access organizational information or systems may need to be considered an endpoint.
Common endpoint categories
| Device | Typical Use |
|---|---|
| Laptop | General business/development |
| Desktop | Office operations |
| Mobile phone | Email/MFA/business applications |
| Tablet | Business applications |
| Developer workstation | Source code and development |
| Administrator workstation | Privileged administration |
| Thin client | Remote/cloud applications |
| BYOD device | Business access from personal device |
The organization should determine which device types fall within the scope of its ISMS.
Activities Required to Implement A.8.1
1. Create an Endpoint Inventory
The organization should know what endpoints are being used to access organizational information.
For example:
| Asset ID | Device | User | OS | Ownership | Encryption | EDR/AV | Status |
|---|---|---|---|---|---|---|---|
| LAP-001 | Laptop | Employee A | Windows | Company | Enabled | Enabled | Active |
| LAP-002 | Laptop | Employee B | macOS | Company | Enabled | Enabled | Active |
| MOB-014 | Mobile | Employee C | Android | Company | Enabled | MDM | Active |
| LAP-020 | Laptop | Developer | Linux | Company | Enabled | EDR | Active |
The exact fields can vary according to organizational requirements.
2. Define Endpoint Security Standards
Create a baseline for company-managed devices.
For example:
Standard endpoint configuration
- Supported operating system
- Security updates enabled
- Disk encryption enabled
- Screen lock enabled
- Endpoint protection enabled
- Firewall enabled
- Standard user privileges
- Secure configuration
- Approved applications
- Automatic updates where appropriate
- Device management enabled
- Strong authentication
- Secure backup where required
This provides a consistent security baseline.
3. Use Supported Operating Systems
Endpoints should use operating systems that receive security updates and remain appropriate for the organization’s risk profile.
Avoid keeping unsupported operating systems simply because:
“The laptop still works.”
An unsupported operating system may no longer receive important security patches.
4. Enable Encryption
Endpoint storage should be protected against unauthorized access, particularly when devices are:
- Lost
- Stolen
- Transported outside the office
- Used remotely
- Assigned to employees handling sensitive information
Examples include:
- BitLocker
- FileVault
- Full-disk encryption
- Platform-supported encryption
Encryption requirements should align with organizational risk and device capabilities.
5. Configure Automatic Screen Lock
Endpoints should automatically lock after an appropriate period of inactivity.
This helps prevent someone from accessing information when the employee leaves the device unattended.
For example:
Employee leaves desk
→ Screen automatically locks
→ Authentication required
→ Unauthorized person cannot simply use the open session
This also connects closely with A.7.7 Clear Desk and Clear Screen.
6. Deploy Endpoint Protection
Depending on risk, endpoint protection may include:
- Endpoint Detection and Response (EDR)
- Anti-malware
- Antivirus
- Host firewall
- Behavioral detection
- Application control
- Device control
- Security monitoring
The objective is not merely to install software.
The organization should also consider:
- Whether it is active
- Whether it receives updates
- Whether alerts are monitored
- Whether users can disable it
- Whether exceptions are documented
7. Apply Security Updates and Patches
Endpoints should be regularly patched.
Important areas include:
- Operating system
- Browsers
- Office applications
- Development tools
- Security software
- VPN clients
- Drivers
- Other business-critical software
A basic patch-management workflow could be:
Identify
→ Assess
→ Test where appropriate
→ Deploy
→ Verify
→ Handle exceptions
8. Control Administrative Privileges
Users should not automatically receive local administrator privileges.
For example:
A normal employee may need:
- Browser
- Office applications
- CRM
- Collaboration tools
They may not need:
- Unrestricted software installation
- System configuration privileges
- Security-control modification privileges
Reducing unnecessary administrative privileges can limit the impact of malware or compromised accounts.
9. Control Software Installation
Organizations should define how applications can be installed on endpoints.
Possible approaches include:
- Approved software lists
- Application allowlisting
- Managed software deployment
- IT approval
- Restricted administrator privileges
- Software inventory
- Removal of unauthorized software
For startups, a simple approved-software process may be sufficient.
10. Protect Endpoint Credentials and Authentication
Endpoint security should work together with identity and access controls.
Consider:
- Strong passwords
- MFA
- Password managers
- Device authentication
- Biometric authentication where appropriate
- Secure storage of authentication information
- Session timeout
- Privileged-account controls
A secure endpoint with weak authentication can still create significant risk.
11. Secure Remote and Hybrid Working
Modern endpoints frequently operate outside the office.
Users may work from:
- Home
- Coworking spaces
- Hotels
- Airports
- Customer premises
- Cafes
- Other locations
Therefore, endpoint controls should remain effective outside the organization’s premises.
This connects A.8.1 with:
- A.6.7 Remote Working
- A.7.9 Security of Assets Off-Premises
- A.8.20 Network Security
- A.8.21 Security of Network Services
12. Manage Lost or Stolen Devices
The organization should define what users must do when a device is lost or stolen.
Example:
Employee loses laptop
↓
Immediately reports incident
↓
IT/security identifies device
↓
Account/session access reviewed
↓
Device locked or remotely wiped where technically possible
↓
Credentials/tokens revoked where necessary
↓
Security incident assessed
↓
Incident recorded
This should be part of the organization’s incident-management process.
13. Manage Mobile Devices
Mobile phones increasingly provide access to sensitive organizational information.
Controls may include:
- Mobile Device Management (MDM)
- Device encryption
- Screen lock
- Biometric authentication
- Application controls
- Remote wipe
- Security updates
- Device inventory
- Separation of business and personal data where appropriate
14. Consider BYOD
Some startups allow employees to use personal devices.
If BYOD is permitted, the organization should define:
- Which systems can be accessed
- Minimum device security requirements
- Whether MDM is required
- Whether company data can be stored locally
- Authentication requirements
- Security update requirements
- Lost-device reporting
- Company data removal when employment ends
- Privacy considerations
Do not simply state:
“Employees may use personal devices.”
Define the security requirements.
15. Define Endpoint Exceptions
There may be legitimate exceptions.
For example:
- Developer needs special software
- Legacy application requires an older configuration
- Specialized engineering device cannot use standard EDR
- Temporary troubleshooting requires administrator privileges
Exceptions should be:
- Documented
- Approved
- Risk assessed
- Time-bound where possible
- Reviewed
Startup Example
Imagine a 60-person SaaS startup.
Employees use:
- Windows laptops
- MacBooks
- Android/iOS phones
- Google Workspace
- GitHub
- Slack
- AWS
- CRM
- VPN
The company implements a simple endpoint baseline:
Laptop controls
- Company-managed devices
- Full-disk encryption
- EDR/endpoint protection
- Automatic screen lock
- Supported OS versions
- Automatic security updates
- Standard user accounts
- Firewall enabled
- MFA for cloud applications
- Asset inventory
Mobile controls
- Device PIN/biometric authentication
- Encryption
- Security updates
- MDM for corporate devices
- Remote wipe capability
- Business application controls
Lost device
Employees must report loss immediately.
IT/security then:
- Identifies the device
- Reviews access
- Revokes sessions where appropriate
- Initiates remote lock/wipe if available
- Assesses potential information exposure
- Records the incident
This is a practical A.8.1 implementation without requiring a large enterprise endpoint-security team.
Example Endpoint Security Baseline
| Security Requirement | Minimum Expectation |
|---|---|
| Device inventory | Required |
| Supported OS | Required |
| Security updates | Enabled |
| Disk encryption | Required where supported/appropriate |
| Screen lock | Enabled |
| Endpoint protection | Enabled |
| Firewall | Enabled where appropriate |
| MFA | Required for important systems |
| Local admin rights | Restricted |
| Approved software | Defined |
| Asset ownership | Recorded |
| Lost-device reporting | Defined |
| Remote wipe | Where technically appropriate |
| Security monitoring | Risk-based |
| BYOD requirements | Defined if BYOD is allowed |
Endpoint Risk Assessment Example
| Threat | Vulnerability | Potential Impact | Control |
|---|---|---|---|
| Laptop theft | No encryption | Data exposure | Full-disk encryption |
| Malware | No endpoint protection | System compromise | EDR/AV |
| Exploited vulnerability | Unpatched OS | Unauthorized access | Patch management |
| Unauthorized use | No screen lock | Information exposure | Automatic lock |
| Malicious software | Admin privileges | Higher compromise impact | Least privilege |
| Lost mobile | No device management | Data exposure | MDM/remote wipe |
| Phishing | Weak authentication | Account compromise | MFA |
| Unauthorized software | No application control | Malware exposure | Approved software |
| BYOD | Unknown security state | Data leakage | BYOD policy/controls |
Audit Evidence for A.8.1
An auditor may request evidence such as:
Asset Management
- Endpoint inventory
- Asset register
- Device assignment records
- Device ownership records
Technical Configuration
- Encryption status
- EDR/AV deployment
- Patch status
- OS version reports
- Firewall configuration
- Screen-lock configuration
- MDM compliance reports
Access Management
- MFA configuration
- Local administrator review
- Privileged access records
- User-device assignments
Operational Evidence
- Endpoint security policy
- Endpoint configuration standard
- Patch-management records
- Security alerts
- Lost-device incidents
- Device compliance reports
- Exception records
BYOD
Where applicable:
- BYOD policy
- Approved-device records
- MDM records
- Data-removal evidence
Audit Checklist for A.8.1
| Audit Question | Yes/No | Evidence |
|---|---|---|
| Are user endpoint devices identified? | ||
| Is there an endpoint inventory? | ||
| Are endpoint owners identified? | ||
| Are supported operating systems defined? | ||
| Are security updates applied? | ||
| Is endpoint protection deployed? | ||
| Is disk encryption enabled where appropriate? | ||
| Is automatic screen locking configured? | ||
| Are local administrator privileges restricted? | ||
| Is software installation controlled? | ||
| Is MFA used for important systems? | ||
| Are mobile devices covered? | ||
| Is BYOD addressed where applicable? | ||
| Is lost/stolen-device reporting defined? | ||
| Can devices be remotely locked or wiped where appropriate? | ||
| Are endpoint security exceptions documented? | ||
| Are endpoint security configurations periodically reviewed? | ||
| Are endpoint incidents monitored and investigated? |
Common Mistakes
1. Buying antivirus and considering A.8.1 complete
A.8.1 is broader than antivirus.
It covers the overall security of user endpoint devices.
2. No endpoint inventory
You cannot effectively secure devices that you do not know exist.
3. Allowing unrestricted administrator access
Giving every employee local administrator privileges can increase the impact of malware and unauthorized software.
4. Ignoring mobile phones
Business information is increasingly accessed from smartphones.
5. Ignoring BYOD
If employees can access company information from personal devices, the organization should understand and manage the associated risks.
6. No patch-management evidence
Saying:
“We regularly update our laptops.”
is weaker than demonstrating actual patch/compliance records.
7. Allowing unsupported operating systems
Old operating systems may create unnecessary security exposure.
8. No lost-device procedure
A company should know what happens when an employee loses a laptop or phone.
9. Users can disable security controls
Endpoint protection that users can easily disable may not provide effective protection.
10. No exception management
Not every device will always meet the standard.
The organization should document and manage legitimate exceptions rather than ignoring them.
Practical Startup Implementation Model
A startup can implement A.8.1 using a simple lifecycle:
1. Inventory
Know what endpoint devices exist.
2. Assign
Know who is responsible for each device.
3. Baseline
Define minimum security requirements.
4. Configure
Apply the required security settings.
5. Protect
Use encryption, endpoint protection, MFA, patching, and other appropriate controls.
6. Monitor
Check device compliance and security status.
7. Respond
Handle malware, lost devices, theft, and endpoint incidents.
8. Review
Periodically review endpoint security.
9. Retire
Securely dispose of or re-use devices under A.7.14.
Simple startup formula:
Inventory → Baseline → Configure → Protect → Monitor → Respond → Review → Retire
Policy vs. Process vs. Evidence
A strong implementation should connect policy with actual technical evidence.
| Layer | Example |
|---|---|
| Policy | Company endpoints must meet defined security requirements |
| Standard | Laptops must use encryption, EDR, screen lock and supported OS |
| Process | IT enrolls every new laptop into endpoint management |
| Technical Control | EDR reports device compliance |
| Evidence | Endpoint compliance report |
| Exception | Developer laptop has approved exception |
| Review | Monthly/quarterly endpoint compliance review |
This gives an auditor a clear connection between the documented requirement and actual implementation.
A.8.1 and Cloud-First Startups
Cloud-first companies sometimes assume:
“We use AWS and SaaS applications, so endpoint security is not important.”
This is incorrect.
Even when production infrastructure is entirely cloud-based, employees may use endpoints to access:
- AWS
- GitHub
- Google Workspace
- Microsoft 365
- CRM
- HR systems
- Financial systems
- Security tools
- Customer environments
A compromised administrator laptop can potentially become a pathway to highly privileged cloud accounts.
Therefore:
Cloud security does not eliminate endpoint security.
It makes endpoint security even more important for protecting access to cloud services.
A.8.1 vs A.7.9
These controls are related but different.
| A.7.9 | A.8.1 |
|---|---|
| Security of assets off-premises | Security of user endpoint devices |
| Physical/off-premises perspective | Technical endpoint perspective |
| Laptop used in hotel | Encryption, EDR, patching, configuration |
| Protects assets outside premises | Protects endpoint device and its use |
Example
An employee takes a company laptop to a hotel.
A.7.9: Protect the laptop from theft or unauthorized physical access.
A.8.1: Ensure the laptop is encrypted, patched, protected, authenticated, and securely configured.
Both controls can apply to the same device.
A.8.1 vs A.7.14
A.8.1 applies while the endpoint is actively being used.
A.7.14 applies when equipment is being:
- Re-used
- Returned
- Sold
- Donated
- Recycled
- Destroyed
Example
Laptop in use → A.8.1
Laptop retired → A.7.14
This creates a complete endpoint lifecycle.
Relationship With Other ISO 27001 Controls
| Control | Relationship |
|---|---|
| A.5.9 Inventory of information and associated assets | Identifies endpoint assets |
| A.5.10 Acceptable use | Defines appropriate use |
| A.5.12 Classification | Helps determine endpoint protection requirements |
| A.5.15 Access Control | Controls access from endpoints |
| A.5.16 Identity Management | Manages user identities accessing systems |
| A.5.17 Authentication Information | Protects authentication information |
| A.5.18 Access Rights | Controls endpoint/user privileges |
| A.6.3 Awareness and Training | Educates users about endpoint risks |
| A.6.7 Remote Working | Addresses remote-work security |
| A.6.8 Event Reporting | Supports reporting of endpoint security events |
| A.7.7 Clear Desk and Clear Screen | Protects information displayed on endpoints |
| A.7.9 Off-Premises Assets | Protects devices outside organizational premises |
| A.7.14 Secure Disposal/Re-use | Protects information when devices are retired |
| A.8.7 Protection Against Malware | Protects endpoints from malicious software |
| A.8.8 Management of Technical Vulnerabilities | Addresses endpoint vulnerabilities |
| A.8.9 Configuration Management | Establishes secure endpoint configurations |
| A.8.15 Logging | Supports monitoring where applicable |
| A.8.16 Monitoring Activities | Supports detection of suspicious activity |
| A.8.19 Installation of Software | Controls software installation |
| A.8.20 Network Security | Protects network connections used by endpoints |
| A.8.24 Use of Cryptography | Supports encryption of endpoint data |
| A.8.32 Change Management | Controls significant endpoint changes |
Useful Resources for A.8.1
1. User Endpoint Security Policy
[Insert Draft Document Link]
Defines security requirements for organizational endpoint devices.
2. Endpoint Security Baseline
[Insert Draft Document Link]
Defines minimum technical configuration requirements.
3. Endpoint Asset Register
[Insert Draft Document Link]
Records organizational endpoint devices and ownership.
4. Endpoint Hardening Checklist
[Insert Draft Document Link]
Used to verify endpoint security configurations.
5. Endpoint Compliance Checklist
[Insert Draft Document Link]
Used for periodic endpoint reviews.
6. BYOD Security Policy
[Insert Draft Document Link]
Defines security requirements for personally owned devices where permitted.
7. Lost or Stolen Device Procedure
[Insert Draft Document Link]
Defines the response to lost or stolen endpoints.
8. Endpoint Exception Register
[Insert Draft Document Link]
Records approved deviations from the endpoint baseline.
Questions an Auditor May Ask
An auditor may ask:
- How do you identify all company laptops?
- How do you know whether endpoints are encrypted?
- How do you ensure devices receive security patches?
- What endpoint protection do you use?
- Can users disable endpoint protection?
- Who has local administrator access?
- How do you control software installation?
- How do you secure mobile devices?
- Do you allow BYOD?
- If yes, how is BYOD controlled?
- What happens when a laptop is lost?
- Can you remotely lock or wipe devices?
- How do you handle unsupported operating systems?
- How do you monitor endpoint compliance?
- Can you show your latest endpoint compliance report?
- How are endpoint exceptions approved?
- What happens when an employee leaves?
- How is the device returned and processed?
- How does endpoint security protect cloud administrator access?
- Can you demonstrate that your endpoint security requirements are actually implemented?
Startup-Focused Quick Summary
For most startups, a practical A.8.1 implementation should begin with:
Endpoint inventory
Know every company-managed laptop, desktop, mobile device, and other relevant endpoint.
Security baseline
Define minimum requirements for:
- Encryption
- EDR/antivirus
- Patch management
- Screen locking
- Firewall
- MFA
- Supported OS
- Least privilege
Device management
Use centralized endpoint or mobile management where justified.
User awareness
Teach employees:
- How to recognize phishing
- How to protect devices
- What to do when a device is lost
- Why unauthorized software is risky
- How to report suspicious activity
Monitoring
Regularly check whether devices meet the baseline.
Incident response
Have a defined process for:
- Lost devices
- Malware
- Suspicious activity
- Unauthorized software
- Compromised endpoints
Lifecycle
When devices are retired, connect the process to A.7.14 Secure Disposal or Re-use of Equipment.
Startup-Focused Final Takeaway
ISO 27001 Annex A 8.1 is fundamentally about controlling the security of the devices that users rely on to access organizational information.
For a startup, you do not necessarily need an expensive enterprise endpoint-management platform.
You need to be able to answer:
- What endpoints do we have?
- Who uses them?
- What can they access?
- Are they securely configured?
- Are they patched?
- Are they encrypted?
- Are they protected against malware?
- Are administrative privileges controlled?
- What happens if a device is lost?
- How do we handle BYOD?
- How do we monitor compliance?
- What happens when the device is retired?
The practical lifecycle is:
Inventory → Assign → Baseline → Configure → Protect → Monitor → Respond → Review → Retire
The goal is not to make every endpoint perfect.
The goal is to ensure that user devices do not become an unmanaged entry point into the organization’s information, applications, or cloud infrastructure.
One-Line Summary
ISO 27001 Annex A 8.1 requires organizations to establish appropriate security controls for user endpoint devices so that laptops, desktops, mobile devices, and other endpoints are securely configured, protected, managed, monitored, and appropriately handled throughout their lifecycle.
