Back to GRC

Endpoint security checks explained: encryption, antivirus, password, screen, and firewall

Photo by Dan Nelson on Unsplash

Endpoint security checks explained: encryption, antivirus, password, screen, and firewall

Endpoint security checks are the measurable device settings compliance teams use to prove laptops meet baseline protection—before auditors sample them or customers send security questionnaires. SecureSlate Asset Management tracks five checks that MDM enforces and GRC teams evidence: HD Encryption, Anti-Virus, Password Policy, Screen Policy, and Firewall.

If you have ever stared at a spreadsheet of "encrypted: yes/no" that nobody updated, you know why standardized checks matter. A shared definition of pass/fail—reported continuously from managed devices—turns endpoint security from a hope into an operational program.

This guide covers:

  • What each of the five SecureSlate security checks measures
  • How MDM enforces settings and detects drift
  • Which frameworks commonly reference these control themes
  • How to prioritize remediation when devices score below 5/5
  • How to collect audit-ready evidence without manual console work

Security monitoring dashboard

GIF via GIPHY

Related guides:


Key takeaways

  • Five checks, one score — SecureSlate shows X/5 status so teams prioritize fleet-wide gaps quickly.
  • MDM enforces; SecureSlate surfaces — configuration profiles apply settings; Asset Management aggregates compliance for GRC.
  • Each check maps to audit themes — confidentiality (encryption), malware defense (AV), access control (password/screen), network protection (firewall).
  • Drift is normal — OS updates, support tickets, and user changes can drop a device from 5/5; continuous monitoring catches it.
  • Evidence should span the audit period — point-in-time screenshots rarely satisfy Type II operating effectiveness tests.

What are endpoint security checks?

Endpoint security checks are pass/fail evaluations of specific device settings on employee laptops and desktops. Unlike vulnerability scans that find CVEs, these checks answer a simpler question: Is the device configured the way our security policy requires?

SecureSlate Asset Management standardizes five checks that appear repeatedly in SOC 2, ISO 27001, HIPAA, and enterprise security reviews:

Check Pass criteria (typical) Primary risk if failing
HD Encryption BitLocker or FileVault enabled Data exposure if device lost/stolen
Anti-Virus Real-time protection on; definitions current Malware infection, credential theft
Password Policy Meets length/complexity requirements Unauthorized local access
Screen Policy Auto-lock ≤15 min inactivity; password on unlock Unattended session hijacking
Firewall OS firewall enabled on all network profiles Unauthorized network connections

MDM pushes the underlying configuration profiles. SecureSlate reads compliance state—directly or via integration—and presents fleet-wide results for IT remediation and GRC evidence.


HD Encryption check

The HD Encryption check verifies that full-disk encryption protects data at rest on the primary drive.

  • Windows: BitLocker (commonly with TPM and recovery key escrow)
  • macOS: FileVault 2

Encryption matters for compliance because lost and stolen devices are common audit talking points. Frameworks typically expect reasonable measures to protect confidential data on portable media—including employee laptops.

MDM commonly enforces encryption by:

  • Requiring FileVault/BitLocker activation before granting access to corporate resources
  • Escrowing recovery keys to prevent data loss during employee turnover
  • Reporting encryption status on each check-in

A device fails this check if encryption is off, suspended, or stuck in a partial state after an OS upgrade. IT should treat failed encryption as P0—the data-at-rest control is effectively absent.

See our deep dive: Hard drive encryption compliance with BitLocker and FileVault.


Anti-Virus check

The Anti-Virus check confirms real-time malware protection is active and definition updates are current.

Compliance frameworks rarely mandate a specific vendor, but they commonly expect:

  • Real-time scanning enabled (on-access protection)
  • Definition/signature updates on a regular cadence—often daily
  • Central visibility that protection has not been disabled

MDM may deploy approved AV agents or verify that an existing corporate standard is installed and running. A device fails if AV is uninstalled, real-time protection is off, or definitions exceed your organization's staleness threshold (e.g., more than 7 days old).

Anti-virus alone is not a complete endpoint defense strategy—EDR and patching matter too—but for audit evidence, AV status is one of the most frequently sampled endpoint controls.


Password Policy check

The Password Policy check validates that local device login passwords meet organizational requirements—typically minimum length, complexity, and sometimes maximum age.

On managed devices, password rules are commonly enforced via:

  • MDM configuration profiles (macOS and Windows)
  • Active Directory or cloud directory policy for domain-joined machines
  • Platform SSO combined with local password requirements

A device fails if the effective policy is weaker than your standard—for example, a 6-character PIN when policy requires 12 characters with complexity. Failed checks often trace to outdated profiles, manual overrides, or devices that fell off MDM management.

Password policy on endpoints complements—not replaces—identity controls like MFA for SaaS applications. Auditors may sample both.

More detail: Password policy on managed devices with MDM.


Screen Policy check

The Screen Policy check ensures unattended devices lock quickly and require authentication to resume.

Typical organizational standards include:

  • Auto-lock or screen saver after ≤15 minutes of inactivity (some policies use 5 minutes for higher-risk roles)
  • Password or biometric required to unlock—not just clicking to dismiss

This control reduces "walk-away" risk in open offices, co-working spaces, and home environments where family members might access an unlocked laptop.

MDM sets idle timeout and lock behavior through OS-specific profiles. Devices fail if screen lock is disabled, timeout exceeds policy, or unlock does not require credentials.

Screen policy is easy to overlook because it feels minor—until an auditor samples a device set to "never sleep" or finds a shared kiosk without lock.


Firewall check

The Firewall check verifies the operating system firewall is enabled across all network profiles—domain, private, and public on Windows; equivalent settings on macOS.

Endpoint firewalls provide a host-level network boundary. They may block unexpected inbound connections and complement network-level controls like VPNs and zero-trust access.

Devices fail when:

  • Firewall is globally disabled
  • Public network profile allows overly permissive rules after travel
  • Third-party security tools conflict and leave firewall off

MDM compliance rules typically treat firewall-off as critical. Remediation is usually a profile re-push or scripted re-enable rather than a hardware change.


Decision table — prioritizing remediation

Not every failed check carries equal risk. Use this table to sequence IT work when fleet scores drop:

Failed check Typical severity Suggested SLA Notes
HD Encryption Critical 24 hours Data-at-rest control absent; may require key escrow verification
Anti-Virus High 48 hours Reinstall or re-enable; verify definitions after remediation
Firewall High 48 hours Often fixed via profile redeploy
Password Policy Medium 1 week May need user notification before forced password change
Screen Policy Medium 1 week Usually profile-only fix; low user friction

When multiple devices fail the same check, investigate root cause before closing tickets one-by-one. A bad MDM profile revision can drop hundreds of devices from 5/5 simultaneously.


Evidence collection workflow

Compliance owners should treat endpoint checks as continuous controls, not pre-audit fire drills:

  1. Define pass/fail — document thresholds (lock timeout, AV staleness, password length) in endpoint security policy.
  2. Connect MDM to GRC — sync compliance status into SecureSlate on a weekly cadence at minimum.
  3. Sample internally — monthly, pull five random devices and verify console matches SecureSlate status.
  4. Track remediation — every sub-5/5 device has a ticket, owner, and closure proof.
  5. Export for auditors — generate period-covering reports aligned to control IDs before fieldwork.
Evidence artifact Control theme Retention
Fleet 5/5 summary report Operating effectiveness Full audit period
MDM profile documentation Design Current version + change history
Remediation ticket samples Monitoring & response Quarterly samples for Type II
Exception register Risk acceptance Updated when scope changes

Auditors compare policy language to sampled devices. If policy says 15-minute lock and samples show 30 minutes, expect a finding—even if the fleet average looks acceptable.


SecureSlate 5/5 security checks

SecureSlate Asset Management was built for compliance teams who need clarity without becoming MDM administrators. For each enrolled device, you see:

  • Individual pass/fail for all five checks
  • Aggregate X/5 score for quick fleet assessment
  • Historical trend—did compliance improve or degrade during the audit window?
  • Export packages mapped to your control library

MDM remains the enforcement engine. SecureSlate is where GRC and IT leadership see the scoreboard, assign remediation, and produce evidence that auditors and customers accept.

Upsell path is straightforward: teams running MDM without centralized compliance visibility often discover endpoint gaps during the first external audit. Connecting Asset Management early prevents that surprise.


Streamline endpoint checks with SecureSlate

Stop rebuilding endpoint evidence from scratch every quarter. SecureSlate connects MDM data to your compliance program so the five security checks support audits, customer reviews, and internal reporting from one place.

  • Fleet dashboard — monitor HD Encryption, Anti-Virus, Password Policy, Screen Policy, and Firewall across all managed devices
  • 5/5 scoring — communicate endpoint readiness to executives in one number
  • Automated evidence — scheduled syncs replace manual MDM console exports
  • Framework mapping — tie checks to SOC 2, ISO 27001, and custom control libraries
  • Remediation workflows — assign owners when devices drop below full compliance

Get started for free


FAQ: Endpoint security checks

What does 5/5 mean in SecureSlate?

It means the device passes all five checks: HD Encryption, Anti-Virus, Password Policy, Screen Policy, and Firewall. Any failure lowers the score (e.g., 4/5).

Can users see their own check status?

Depends on your internal process. Some IT teams expose status in self-service portals; others restrict visibility to IT and GRC. SecureSlate supports fleet views for administrators.

Do we need all five checks for SOC 2?

SOC 2 does not mandate these exact labels, but the underlying themes—encryption, malware protection, access control, network boundaries—commonly appear in control descriptions and auditor samples.

How often should checks sync?

Weekly is a typical minimum for GRC evidence; daily is better for fast-moving teams or during remediation sprints.

What if a device cannot pass a check due to legacy software?

Document a compensating control or risk exception with executive approval, alternate machine, or network isolation. Auditors expect exceptions to be rare and justified—not fleet-wide.

Does SecureSlate enforce the checks?

SecureSlate surfaces compliance status and evidence. MDM enforces configuration. Together they provide enforce + prove—the pattern mature programs use.


Disclaimer (legal note)

SecureSlate is not a law firm, and this article does not constitute legal advice or create an attorney-client relationship. Security and compliance obligations vary by industry, contract, and jurisdiction—consult qualified counsel as needed.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

4.9(238 reviews)

Keep reading

Aug 12, 2026 · GRC

Antivirus requirements for SOC 2 and ISO 27001: MDM enforcement and audit evidence

Aug 12, 2026 · GRC

Building an endpoint security baseline for startups

Aug 12, 2026 · GRC

BYOD and MDM: balancing flexibility and endpoint security

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?