MDM for ISO 27001: endpoint and device controls for Annex A
MDM for ISO 27001 gives certification teams a practical way to implement Annex A controls for user endpoint devices—not just cloud infrastructure. Auditors expect documented policies, enforced configuration, and operating evidence that devices stayed compliant between surveillance audits. Spreadsheets updated before each audit cycle rarely survive Stage 2 testing.
This guide covers:
- Which Annex A controls MDM and endpoint monitoring address
- Five baseline checks (encryption, anti-virus, password policy, screen policy, firewall) mapped to ISO 27001
- Enrollment workflows for company-owned and BYOD devices
- Evidence certification bodies commonly request
- How SecureSlate Asset Management provides continuous status for surveillance audits

GIF via GIPHY
Related guides:
- MDM compliance guide
- BYOD policy
- MDM for SOC 2 Type II endpoint evidence
- Building an endpoint security baseline for startups
Key takeaways
- Annex A 8.x controls for endpoint devices require both policy design and operating evidence—not configuration alone.
- MDM enforces encryption, AV, password, screen lock, and firewall settings; SecureSlate tracks 5/5 pass status continuously.
- Statement of Applicability (SoA) must reflect which controls MDM implements and which rely on compensating measures.
- Surveillance audits test whether controls operated between certification cycles—continuous monitoring beats pre-audit exports.
- Cross-map to SOC 2 when pursuing both frameworks from one evidence library.
Annex A controls MDM supports
ISO 27001:2022 Annex A organizes controls into themes. MDM directly supports several endpoint-relevant entries:
| Annex A control (2022) | Theme | How MDM contributes |
|---|---|---|
| A.5.9 Inventory of information and other associated assets | Organizational | Device enrollment = asset inventory |
| A.5.10 Acceptable use of information | Organizational | BYOD/COBO enrollment policies |
| A.8.1 User endpoint devices | Technological | MDM enrollment and configuration |
| A.8.2 Privileged access rights | Technological | Admin privilege restrictions on endpoints |
| A.8.3 Information access restriction | Technological | Encryption enforcement |
| A.8.4 Access to source code | Technological | Developer device baseline |
| A.8.5 Secure authentication | Technological | Password policy via MDM |
| A.8.7 Protection against malware | Technological | Anti-virus deployment |
| A.8.8 Management of technical vulnerabilities | Technological | Patch compliance via MDM |
| A.8.9 Configuration management | Technological | Firewall and security profiles |
Your SoA should list each applicable control, justify inclusion or exclusion, and name the implementation method (MDM profile, manual procedure, or compensating control).
Five endpoint checks for ISO 27001
SecureSlate Asset Management monitors five checks that align with common Annex A implementation guidance:
| Check | Annex A alignment | MDM enforcement | SecureSlate evidence |
|---|---|---|---|
| HD Encryption | A.8.1, A.8.3 | FileVault / BitLocker profile | Pass/fail per device, historical |
| Anti-Virus | A.8.7 | EDR/AV deployment policy | Agent status across population |
| Password Policy | A.8.5 | Complexity, length, lockout | Config vs policy comparison |
| Screen Policy | A.8.1 | Auto-lock timeout | Timeout compliance per device |
| Firewall | A.8.9 | Host firewall profile | Enabled/locked status |
A device showing 5/5 checks passing in SecureSlate gives auditors a clear operating-effectiveness signal. Devices below 5/5 need remediation tickets with owners before your surveillance audit.
Device enrollment baseline
Certification audits fail on endpoint controls when the managed population is incomplete. Establish these rules before Stage 1:
- No production access without MDM enrollment — IdP conditional access gates on MDM compliance where supported.
- Asset inventory matches MDM enrollment — reconcile HR headcount, contractor list, and device inventory monthly.
- BYOD follows the same five checks — personal devices accessing company data must meet identical baseline; see BYOD and MDM.
- Offboarding removes devices within SLA — MDM unenrollment or remote wipe tied to HR termination workflow.
- Exceptions are documented — lab machines, legacy hardware, and executive devices need risk acceptance in the SoA.
Enrollment rate should track workforce size. A 78% enrollment rate with 22% "special cases" is a Stage 2 conversation you do not want.
Implementation workflow
- Scope devices in the ISMS boundary — include remote workers, contractors, and BYOD per your access policy.
- Draft endpoint security procedures — reference the five checks explicitly; align with your information security policy.
- Configure MDM profiles — deploy encryption, AV, password, screen lock, and firewall baselines.
- Connect MDM to SecureSlate — Asset Management syncs device status and maps to Annex A controls.
- Run internal audit — sample 10+ devices; verify 5/5 checks and documentation match.
- Stage 1 readiness review — confirm SoA reflects MDM implementation; policies approved.
- Operate continuously — weekly dashboard review; remediate non-compliant devices before surveillance.
For a broader MDM program overview, see the MDM compliance guide.
Evidence for certification audits
| Evidence type | Stage 1 (documentation) | Stage 2 / surveillance (operating) |
|---|---|---|
| Information security policy | Approved; covers endpoint requirements | Still current; version history |
| Endpoint / BYOD procedure | References five checks | Matches MDM configuration |
| Statement of Applicability | Lists A.8.x controls with justification | Updated for scope changes |
| MDM configuration exports | Profile documentation | Samples show consistent enforcement |
| SecureSlate population report | N/A (pre-certification) | 5/5 pass rates across period |
| Device samples | Enrollment list | Encryption, AV, firewall verified on samples |
| Exception register | Risk acceptance documented | Exceptions still valid; not expired |
| Offboarding records | Procedure documented | Samples show timely MDM removal |
Certification bodies typically sample 5–15 endpoints depending on organization size. Pre-build exports in SecureSlate so retrieval does not depend on one engineer's MDM console access.
Common certification gaps
- SoA excludes A.8.1 but devices access production — auditors will expand scope during Stage 2.
- Policy says one thing, MDM enforces another — password length mismatch is a recurring finding.
- No BYOD controls — personal phones with email access need the same baseline or explicit exclusion.
- Surveillance audit surprise — team exports MDM data only when the auditor arrives; no continuous history.
- Contractor devices unmanaged — third-party laptops with VPN access outside enrollment.
Roles and ownership
| Role | Typical responsibilities |
|---|---|
| ISMS manager / GRC lead | SoA maintenance, auditor liaison, control mapping |
| IT / endpoint admin | MDM configuration, enrollment, remediation |
| Information security officer | Policy approval, risk acceptance for exceptions |
| People Ops / HR | Offboarding triggers, contractor tracking |
| Internal audit | Pre-certification sampling, finding tracking |
Typical certification timeline
| Phase | Duration | Endpoint focus |
|---|---|---|
| Gap analysis | 2–4 weeks | Inventory devices; compare to five-check baseline |
| Policy & SoA | 2–4 weeks | Document endpoint controls in SoA |
| MDM deployment | 4–8 weeks | Enroll population; deploy profiles |
| SecureSlate integration | 1–2 weeks | Connect MDM; verify 5/5 dashboard |
| Internal audit | 1–2 weeks | Sample devices; close findings |
| Stage 1 | 1–2 days | Documentation review |
| Stage 2 | 3–5 days | Operating effectiveness testing |
| Surveillance (annual) | 1–2 days | Continuous evidence from SecureSlate |
Streamline with SecureSlate
SecureSlate Asset Management gives ISO 27001 teams continuous visibility into HD encryption, anti-virus, password policy, screen policy, and firewall status—mapped to Annex A controls and exportable for Stage 2 and surveillance audits.
Stop rebuilding MDM exports before every audit. Connect your MDM, track 5/5 endpoint checks, and export certification-ready evidence from one platform.
Get started for free · Free readiness score
FAQ: MDM for ISO 27001
Is MDM mandatory for ISO 27001 certification?
No—but auditors expect demonstrable control over endpoint devices. MDM is the most common implementation method for A.8.1 and related controls.
Can we certify with BYOD devices in scope?
Yes, if BYOD devices meet the same five-check baseline or have documented compensating controls. See BYOD policy.
How does SecureSlate differ from MDM reporting?
MDM shows current device state. SecureSlate tracks status over time, maps checks to Annex A controls, and exports audit evidence across surveillance periods.
Should we map the same evidence to SOC 2?
Yes—teams pursuing both frameworks reuse SecureSlate exports. See MDM for SOC 2 Type II endpoint evidence.
What enrollment rate should we target before Stage 2?
Aim for 95%+ of in-scope devices enrolled, with documented risk acceptance for remaining exceptions.
How often do surveillance audits test endpoints?
Annually in most programs. Continuous SecureSlate monitoring covers the period between audits without manual reconstruction.
Do we need separate policies for each check?
One endpoint security procedure referencing all five checks is typical. Separate policies are optional if your ISMS structure requires them.
What is the first step if we have no MDM today?
Start with device inventory and the five-check gap analysis—see building an endpoint security baseline for startups.
Disclaimer (legal note)
SecureSlate is not a law firm, and this article does not constitute legal advice or create an attorney-client relationship. Security and compliance obligations vary by industry, contract, and jurisdiction—consult qualified counsel as needed.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds
