ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. 5. ISO 27001 Annex A - 8 ...
  5. ISO 27001 Annex A 8.1 User endpoint devices

ISO 27001 Annex A 8.1 User endpoint devices

What is ISO 27001 Annex A 8.1 – User Endpoint Devices?

ISO 27001 Annex A 8.1 focuses on protecting user endpoint devices that access, process, store, or transmit organizational information.

Endpoint devices are the devices employees, contractors, and other authorized users use to connect to company systems.

Examples include:

  • Laptops
  • Desktop computers
  • Mobile phones
  • Tablets
  • Workstations
  • Thin clients
  • Corporate-managed devices
  • In some environments, personally owned devices used for business purposes

These devices can access sensitive systems such as:

  • Email
  • Cloud applications
  • Source-code repositories
  • Customer systems
  • CRM
  • HR systems
  • Financial applications
  • VPN
  • SaaS platforms
  • Production environments

Simple explanation: If a device can access company information, the organization needs appropriate security controls to protect that device and the information it can access.


Why is ISO 27001 Annex A 8.1 Important?

Modern organizations often have more information flowing through laptops and mobile devices than through traditional office servers.

A single employee laptop may have access to:

  • Customer information
  • Company email
  • Source code
  • Internal documents
  • Cloud applications
  • VPN
  • Security tools
  • Business applications
  • Credentials or authentication sessions

If that endpoint is stolen, compromised, misconfigured, or infected with malware, an attacker may use it as a starting point for a larger security incident.

Common endpoint risks

RiskExample
Device theftEmployee laptop stolen from a vehicle
MalwareMalicious software compromises the endpoint
PhishingEmployee enters credentials into a fake website
Unpatched softwareVulnerability exploited through outdated software
Weak authenticationDevice account protected by weak credentials
Unencrypted storageLost laptop exposes locally stored information
Unauthorized softwareUser installs risky applications
USB malwareMalicious removable device infects endpoint
Excessive privilegesStandard user has unnecessary administrative access
Remote-work exposureDevice used from insecure locations
Lost mobile deviceBusiness email remains accessible
Unsupported softwareOld OS no longer receives security updates

Simple principle: An endpoint is not just an employee’s computer—it is a gateway to organizational information and systems.


What Does Annex A 8.1 Require?

Organizations should establish appropriate security measures for user endpoint devices based on:

  • Information sensitivity
  • Business requirements
  • Threat environment
  • Device type
  • Device ownership
  • User role
  • Access privileges
  • Remote-working requirements
  • Regulatory requirements
  • Customer requirements
  • Organizational risk

The organization should define and enforce rules for the secure use of endpoint devices.

Controls may include:

  • Device inventory
  • Endpoint configuration standards
  • Strong authentication
  • Encryption
  • Automatic screen locking
  • Endpoint protection
  • Anti-malware
  • Patch management
  • Application controls
  • Firewall configuration
  • Device management
  • Mobile device management
  • Remote wipe
  • Backup
  • Logging and monitoring
  • Secure configuration
  • Administrative privilege management
  • Lost/stolen-device reporting

The controls should be proportionate to risk.

A five-person startup does not necessarily need the same endpoint-management architecture as a large bank.


What Are User Endpoint Devices?

A useful way to understand this control is:

Any device used by a user to access organizational information or systems may need to be considered an endpoint.

Common endpoint categories

DeviceTypical Use
LaptopGeneral business/development
DesktopOffice operations
Mobile phoneEmail/MFA/business applications
TabletBusiness applications
Developer workstationSource code and development
Administrator workstationPrivileged administration
Thin clientRemote/cloud applications
BYOD deviceBusiness access from personal device

The organization should determine which device types fall within the scope of its ISMS.


Activities Required to Implement A.8.1

1. Create an Endpoint Inventory

The organization should know what endpoints are being used to access organizational information.

For example:

Asset IDDeviceUserOSOwnershipEncryptionEDR/AVStatus
LAP-001LaptopEmployee AWindowsCompanyEnabledEnabledActive
LAP-002LaptopEmployee BmacOSCompanyEnabledEnabledActive
MOB-014MobileEmployee CAndroidCompanyEnabledMDMActive
LAP-020LaptopDeveloperLinuxCompanyEnabledEDRActive

The exact fields can vary according to organizational requirements.


2. Define Endpoint Security Standards

Create a baseline for company-managed devices.

For example:

Standard endpoint configuration

  • Supported operating system
  • Security updates enabled
  • Disk encryption enabled
  • Screen lock enabled
  • Endpoint protection enabled
  • Firewall enabled
  • Standard user privileges
  • Secure configuration
  • Approved applications
  • Automatic updates where appropriate
  • Device management enabled
  • Strong authentication
  • Secure backup where required

This provides a consistent security baseline.


3. Use Supported Operating Systems

Endpoints should use operating systems that receive security updates and remain appropriate for the organization’s risk profile.

Avoid keeping unsupported operating systems simply because:

“The laptop still works.”

An unsupported operating system may no longer receive important security patches.


4. Enable Encryption

Endpoint storage should be protected against unauthorized access, particularly when devices are:

  • Lost
  • Stolen
  • Transported outside the office
  • Used remotely
  • Assigned to employees handling sensitive information

Examples include:

  • BitLocker
  • FileVault
  • Full-disk encryption
  • Platform-supported encryption

Encryption requirements should align with organizational risk and device capabilities.


5. Configure Automatic Screen Lock

Endpoints should automatically lock after an appropriate period of inactivity.

This helps prevent someone from accessing information when the employee leaves the device unattended.

For example:

Employee leaves desk

→ Screen automatically locks

→ Authentication required

→ Unauthorized person cannot simply use the open session

This also connects closely with A.7.7 Clear Desk and Clear Screen.


6. Deploy Endpoint Protection

Depending on risk, endpoint protection may include:

  • Endpoint Detection and Response (EDR)
  • Anti-malware
  • Antivirus
  • Host firewall
  • Behavioral detection
  • Application control
  • Device control
  • Security monitoring

The objective is not merely to install software.

The organization should also consider:

  • Whether it is active
  • Whether it receives updates
  • Whether alerts are monitored
  • Whether users can disable it
  • Whether exceptions are documented

7. Apply Security Updates and Patches

Endpoints should be regularly patched.

Important areas include:

  • Operating system
  • Browsers
  • Office applications
  • Development tools
  • Security software
  • VPN clients
  • Drivers
  • Other business-critical software

A basic patch-management workflow could be:

Identify

→ Assess

→ Test where appropriate

→ Deploy

→ Verify

→ Handle exceptions


8. Control Administrative Privileges

Users should not automatically receive local administrator privileges.

For example:

A normal employee may need:

  • Email
  • Browser
  • Office applications
  • CRM
  • Collaboration tools

They may not need:

  • Unrestricted software installation
  • System configuration privileges
  • Security-control modification privileges

Reducing unnecessary administrative privileges can limit the impact of malware or compromised accounts.


9. Control Software Installation

Organizations should define how applications can be installed on endpoints.

Possible approaches include:

  • Approved software lists
  • Application allowlisting
  • Managed software deployment
  • IT approval
  • Restricted administrator privileges
  • Software inventory
  • Removal of unauthorized software

For startups, a simple approved-software process may be sufficient.


10. Protect Endpoint Credentials and Authentication

Endpoint security should work together with identity and access controls.

Consider:

  • Strong passwords
  • MFA
  • Password managers
  • Device authentication
  • Biometric authentication where appropriate
  • Secure storage of authentication information
  • Session timeout
  • Privileged-account controls

A secure endpoint with weak authentication can still create significant risk.


11. Secure Remote and Hybrid Working

Modern endpoints frequently operate outside the office.

Users may work from:

  • Home
  • Coworking spaces
  • Hotels
  • Airports
  • Customer premises
  • Cafes
  • Other locations

Therefore, endpoint controls should remain effective outside the organization’s premises.

This connects A.8.1 with:

  • A.6.7 Remote Working
  • A.7.9 Security of Assets Off-Premises
  • A.8.20 Network Security
  • A.8.21 Security of Network Services

12. Manage Lost or Stolen Devices

The organization should define what users must do when a device is lost or stolen.

Example:

Employee loses laptop

↓

Immediately reports incident

↓

IT/security identifies device

↓

Account/session access reviewed

↓

Device locked or remotely wiped where technically possible

↓

Credentials/tokens revoked where necessary

↓

Security incident assessed

↓

Incident recorded

This should be part of the organization’s incident-management process.


13. Manage Mobile Devices

Mobile phones increasingly provide access to sensitive organizational information.

Controls may include:

  • Mobile Device Management (MDM)
  • Device encryption
  • Screen lock
  • Biometric authentication
  • Application controls
  • Remote wipe
  • Security updates
  • Device inventory
  • Separation of business and personal data where appropriate

14. Consider BYOD

Some startups allow employees to use personal devices.

If BYOD is permitted, the organization should define:

  • Which systems can be accessed
  • Minimum device security requirements
  • Whether MDM is required
  • Whether company data can be stored locally
  • Authentication requirements
  • Security update requirements
  • Lost-device reporting
  • Company data removal when employment ends
  • Privacy considerations

Do not simply state:

“Employees may use personal devices.”

Define the security requirements.


15. Define Endpoint Exceptions

There may be legitimate exceptions.

For example:

  • Developer needs special software
  • Legacy application requires an older configuration
  • Specialized engineering device cannot use standard EDR
  • Temporary troubleshooting requires administrator privileges

Exceptions should be:

  • Documented
  • Approved
  • Risk assessed
  • Time-bound where possible
  • Reviewed

Startup Example

Imagine a 60-person SaaS startup.

Employees use:

  • Windows laptops
  • MacBooks
  • Android/iOS phones
  • Google Workspace
  • GitHub
  • Slack
  • AWS
  • CRM
  • VPN

The company implements a simple endpoint baseline:

Laptop controls

  • Company-managed devices
  • Full-disk encryption
  • EDR/endpoint protection
  • Automatic screen lock
  • Supported OS versions
  • Automatic security updates
  • Standard user accounts
  • Firewall enabled
  • MFA for cloud applications
  • Asset inventory

Mobile controls

  • Device PIN/biometric authentication
  • Encryption
  • Security updates
  • MDM for corporate devices
  • Remote wipe capability
  • Business application controls

Lost device

Employees must report loss immediately.

IT/security then:

  • Identifies the device
  • Reviews access
  • Revokes sessions where appropriate
  • Initiates remote lock/wipe if available
  • Assesses potential information exposure
  • Records the incident

This is a practical A.8.1 implementation without requiring a large enterprise endpoint-security team.


Example Endpoint Security Baseline

Security RequirementMinimum Expectation
Device inventoryRequired
Supported OSRequired
Security updatesEnabled
Disk encryptionRequired where supported/appropriate
Screen lockEnabled
Endpoint protectionEnabled
FirewallEnabled where appropriate
MFARequired for important systems
Local admin rightsRestricted
Approved softwareDefined
Asset ownershipRecorded
Lost-device reportingDefined
Remote wipeWhere technically appropriate
Security monitoringRisk-based
BYOD requirementsDefined if BYOD is allowed

Endpoint Risk Assessment Example

ThreatVulnerabilityPotential ImpactControl
Laptop theftNo encryptionData exposureFull-disk encryption
MalwareNo endpoint protectionSystem compromiseEDR/AV
Exploited vulnerabilityUnpatched OSUnauthorized accessPatch management
Unauthorized useNo screen lockInformation exposureAutomatic lock
Malicious softwareAdmin privilegesHigher compromise impactLeast privilege
Lost mobileNo device managementData exposureMDM/remote wipe
PhishingWeak authenticationAccount compromiseMFA
Unauthorized softwareNo application controlMalware exposureApproved software
BYODUnknown security stateData leakageBYOD policy/controls

Audit Evidence for A.8.1

An auditor may request evidence such as:

Asset Management

  • Endpoint inventory
  • Asset register
  • Device assignment records
  • Device ownership records

Technical Configuration

  • Encryption status
  • EDR/AV deployment
  • Patch status
  • OS version reports
  • Firewall configuration
  • Screen-lock configuration
  • MDM compliance reports

Access Management

  • MFA configuration
  • Local administrator review
  • Privileged access records
  • User-device assignments

Operational Evidence

  • Endpoint security policy
  • Endpoint configuration standard
  • Patch-management records
  • Security alerts
  • Lost-device incidents
  • Device compliance reports
  • Exception records

BYOD

Where applicable:

  • BYOD policy
  • Approved-device records
  • MDM records
  • Data-removal evidence

Audit Checklist for A.8.1

Audit QuestionYes/NoEvidence
Are user endpoint devices identified?
Is there an endpoint inventory?
Are endpoint owners identified?
Are supported operating systems defined?
Are security updates applied?
Is endpoint protection deployed?
Is disk encryption enabled where appropriate?
Is automatic screen locking configured?
Are local administrator privileges restricted?
Is software installation controlled?
Is MFA used for important systems?
Are mobile devices covered?
Is BYOD addressed where applicable?
Is lost/stolen-device reporting defined?
Can devices be remotely locked or wiped where appropriate?
Are endpoint security exceptions documented?
Are endpoint security configurations periodically reviewed?
Are endpoint incidents monitored and investigated?

Common Mistakes

1. Buying antivirus and considering A.8.1 complete

A.8.1 is broader than antivirus.

It covers the overall security of user endpoint devices.


2. No endpoint inventory

You cannot effectively secure devices that you do not know exist.


3. Allowing unrestricted administrator access

Giving every employee local administrator privileges can increase the impact of malware and unauthorized software.


4. Ignoring mobile phones

Business information is increasingly accessed from smartphones.


5. Ignoring BYOD

If employees can access company information from personal devices, the organization should understand and manage the associated risks.


6. No patch-management evidence

Saying:

“We regularly update our laptops.”

is weaker than demonstrating actual patch/compliance records.


7. Allowing unsupported operating systems

Old operating systems may create unnecessary security exposure.


8. No lost-device procedure

A company should know what happens when an employee loses a laptop or phone.


9. Users can disable security controls

Endpoint protection that users can easily disable may not provide effective protection.


10. No exception management

Not every device will always meet the standard.

The organization should document and manage legitimate exceptions rather than ignoring them.


Practical Startup Implementation Model

A startup can implement A.8.1 using a simple lifecycle:

1. Inventory

Know what endpoint devices exist.

2. Assign

Know who is responsible for each device.

3. Baseline

Define minimum security requirements.

4. Configure

Apply the required security settings.

5. Protect

Use encryption, endpoint protection, MFA, patching, and other appropriate controls.

6. Monitor

Check device compliance and security status.

7. Respond

Handle malware, lost devices, theft, and endpoint incidents.

8. Review

Periodically review endpoint security.

9. Retire

Securely dispose of or re-use devices under A.7.14.

Simple startup formula:
Inventory → Baseline → Configure → Protect → Monitor → Respond → Review → Retire


Policy vs. Process vs. Evidence

A strong implementation should connect policy with actual technical evidence.

LayerExample
PolicyCompany endpoints must meet defined security requirements
StandardLaptops must use encryption, EDR, screen lock and supported OS
ProcessIT enrolls every new laptop into endpoint management
Technical ControlEDR reports device compliance
EvidenceEndpoint compliance report
ExceptionDeveloper laptop has approved exception
ReviewMonthly/quarterly endpoint compliance review

This gives an auditor a clear connection between the documented requirement and actual implementation.


A.8.1 and Cloud-First Startups

Cloud-first companies sometimes assume:

“We use AWS and SaaS applications, so endpoint security is not important.”

This is incorrect.

Even when production infrastructure is entirely cloud-based, employees may use endpoints to access:

  • AWS
  • GitHub
  • Google Workspace
  • Microsoft 365
  • CRM
  • HR systems
  • Financial systems
  • Security tools
  • Customer environments

A compromised administrator laptop can potentially become a pathway to highly privileged cloud accounts.

Therefore:

Cloud security does not eliminate endpoint security.

It makes endpoint security even more important for protecting access to cloud services.


A.8.1 vs A.7.9

These controls are related but different.

A.7.9A.8.1
Security of assets off-premisesSecurity of user endpoint devices
Physical/off-premises perspectiveTechnical endpoint perspective
Laptop used in hotelEncryption, EDR, patching, configuration
Protects assets outside premisesProtects endpoint device and its use

Example

An employee takes a company laptop to a hotel.

A.7.9: Protect the laptop from theft or unauthorized physical access.

A.8.1: Ensure the laptop is encrypted, patched, protected, authenticated, and securely configured.

Both controls can apply to the same device.


A.8.1 vs A.7.14

A.8.1 applies while the endpoint is actively being used.

A.7.14 applies when equipment is being:

  • Re-used
  • Returned
  • Sold
  • Donated
  • Recycled
  • Destroyed

Example

Laptop in use → A.8.1

Laptop retired → A.7.14

This creates a complete endpoint lifecycle.


Relationship With Other ISO 27001 Controls

ControlRelationship
A.5.9 Inventory of information and associated assetsIdentifies endpoint assets
A.5.10 Acceptable useDefines appropriate use
A.5.12 ClassificationHelps determine endpoint protection requirements
A.5.15 Access ControlControls access from endpoints
A.5.16 Identity ManagementManages user identities accessing systems
A.5.17 Authentication InformationProtects authentication information
A.5.18 Access RightsControls endpoint/user privileges
A.6.3 Awareness and TrainingEducates users about endpoint risks
A.6.7 Remote WorkingAddresses remote-work security
A.6.8 Event ReportingSupports reporting of endpoint security events
A.7.7 Clear Desk and Clear ScreenProtects information displayed on endpoints
A.7.9 Off-Premises AssetsProtects devices outside organizational premises
A.7.14 Secure Disposal/Re-useProtects information when devices are retired
A.8.7 Protection Against MalwareProtects endpoints from malicious software
A.8.8 Management of Technical VulnerabilitiesAddresses endpoint vulnerabilities
A.8.9 Configuration ManagementEstablishes secure endpoint configurations
A.8.15 LoggingSupports monitoring where applicable
A.8.16 Monitoring ActivitiesSupports detection of suspicious activity
A.8.19 Installation of SoftwareControls software installation
A.8.20 Network SecurityProtects network connections used by endpoints
A.8.24 Use of CryptographySupports encryption of endpoint data
A.8.32 Change ManagementControls significant endpoint changes

Useful Resources for A.8.1

1. User Endpoint Security Policy

[Insert Draft Document Link]

Defines security requirements for organizational endpoint devices.

2. Endpoint Security Baseline

[Insert Draft Document Link]

Defines minimum technical configuration requirements.

3. Endpoint Asset Register

[Insert Draft Document Link]

Records organizational endpoint devices and ownership.

4. Endpoint Hardening Checklist

[Insert Draft Document Link]

Used to verify endpoint security configurations.

5. Endpoint Compliance Checklist

[Insert Draft Document Link]

Used for periodic endpoint reviews.

6. BYOD Security Policy

[Insert Draft Document Link]

Defines security requirements for personally owned devices where permitted.

7. Lost or Stolen Device Procedure

[Insert Draft Document Link]

Defines the response to lost or stolen endpoints.

8. Endpoint Exception Register

[Insert Draft Document Link]

Records approved deviations from the endpoint baseline.


Questions an Auditor May Ask

An auditor may ask:

  1. How do you identify all company laptops?
  2. How do you know whether endpoints are encrypted?
  3. How do you ensure devices receive security patches?
  4. What endpoint protection do you use?
  5. Can users disable endpoint protection?
  6. Who has local administrator access?
  7. How do you control software installation?
  8. How do you secure mobile devices?
  9. Do you allow BYOD?
  10. If yes, how is BYOD controlled?
  11. What happens when a laptop is lost?
  12. Can you remotely lock or wipe devices?
  13. How do you handle unsupported operating systems?
  14. How do you monitor endpoint compliance?
  15. Can you show your latest endpoint compliance report?
  16. How are endpoint exceptions approved?
  17. What happens when an employee leaves?
  18. How is the device returned and processed?
  19. How does endpoint security protect cloud administrator access?
  20. Can you demonstrate that your endpoint security requirements are actually implemented?

Startup-Focused Quick Summary

For most startups, a practical A.8.1 implementation should begin with:

Endpoint inventory

Know every company-managed laptop, desktop, mobile device, and other relevant endpoint.

Security baseline

Define minimum requirements for:

  • Encryption
  • EDR/antivirus
  • Patch management
  • Screen locking
  • Firewall
  • MFA
  • Supported OS
  • Least privilege

Device management

Use centralized endpoint or mobile management where justified.

User awareness

Teach employees:

  • How to recognize phishing
  • How to protect devices
  • What to do when a device is lost
  • Why unauthorized software is risky
  • How to report suspicious activity

Monitoring

Regularly check whether devices meet the baseline.

Incident response

Have a defined process for:

  • Lost devices
  • Malware
  • Suspicious activity
  • Unauthorized software
  • Compromised endpoints

Lifecycle

When devices are retired, connect the process to A.7.14 Secure Disposal or Re-use of Equipment.


Startup-Focused Final Takeaway

ISO 27001 Annex A 8.1 is fundamentally about controlling the security of the devices that users rely on to access organizational information.

For a startup, you do not necessarily need an expensive enterprise endpoint-management platform.

You need to be able to answer:

  • What endpoints do we have?
  • Who uses them?
  • What can they access?
  • Are they securely configured?
  • Are they patched?
  • Are they encrypted?
  • Are they protected against malware?
  • Are administrative privileges controlled?
  • What happens if a device is lost?
  • How do we handle BYOD?
  • How do we monitor compliance?
  • What happens when the device is retired?

The practical lifecycle is:

Inventory → Assign → Baseline → Configure → Protect → Monitor → Respond → Review → Retire

The goal is not to make every endpoint perfect.

The goal is to ensure that user devices do not become an unmanaged entry point into the organization’s information, applications, or cloud infrastructure.


One-Line Summary

ISO 27001 Annex A 8.1 requires organizations to establish appropriate security controls for user endpoint devices so that laptops, desktops, mobile devices, and other endpoints are securely configured, protected, managed, monitored, and appropriately handled throughout their lifecycle.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *