Back to GRC

MDM for ISO 27001: endpoint and device controls for Annex A

Photo by FlyD on Unsplash

MDM for ISO 27001: endpoint and device controls for Annex A

MDM for ISO 27001 gives certification teams a practical way to implement Annex A controls for user endpoint devices—not just cloud infrastructure. Auditors expect documented policies, enforced configuration, and operating evidence that devices stayed compliant between surveillance audits. Spreadsheets updated before each audit cycle rarely survive Stage 2 testing.

This guide covers:

  • Which Annex A controls MDM and endpoint monitoring address
  • Five baseline checks (encryption, anti-virus, password policy, screen policy, firewall) mapped to ISO 27001
  • Enrollment workflows for company-owned and BYOD devices
  • Evidence certification bodies commonly request
  • How SecureSlate Asset Management provides continuous status for surveillance audits

ISO compliance planning

GIF via GIPHY

Related guides:


Key takeaways

  • Annex A 8.x controls for endpoint devices require both policy design and operating evidence—not configuration alone.
  • MDM enforces encryption, AV, password, screen lock, and firewall settings; SecureSlate tracks 5/5 pass status continuously.
  • Statement of Applicability (SoA) must reflect which controls MDM implements and which rely on compensating measures.
  • Surveillance audits test whether controls operated between certification cycles—continuous monitoring beats pre-audit exports.
  • Cross-map to SOC 2 when pursuing both frameworks from one evidence library.

Annex A controls MDM supports

ISO 27001:2022 Annex A organizes controls into themes. MDM directly supports several endpoint-relevant entries:

Annex A control (2022) Theme How MDM contributes
A.5.9 Inventory of information and other associated assets Organizational Device enrollment = asset inventory
A.5.10 Acceptable use of information Organizational BYOD/COBO enrollment policies
A.8.1 User endpoint devices Technological MDM enrollment and configuration
A.8.2 Privileged access rights Technological Admin privilege restrictions on endpoints
A.8.3 Information access restriction Technological Encryption enforcement
A.8.4 Access to source code Technological Developer device baseline
A.8.5 Secure authentication Technological Password policy via MDM
A.8.7 Protection against malware Technological Anti-virus deployment
A.8.8 Management of technical vulnerabilities Technological Patch compliance via MDM
A.8.9 Configuration management Technological Firewall and security profiles

Your SoA should list each applicable control, justify inclusion or exclusion, and name the implementation method (MDM profile, manual procedure, or compensating control).


Five endpoint checks for ISO 27001

SecureSlate Asset Management monitors five checks that align with common Annex A implementation guidance:

Check Annex A alignment MDM enforcement SecureSlate evidence
HD Encryption A.8.1, A.8.3 FileVault / BitLocker profile Pass/fail per device, historical
Anti-Virus A.8.7 EDR/AV deployment policy Agent status across population
Password Policy A.8.5 Complexity, length, lockout Config vs policy comparison
Screen Policy A.8.1 Auto-lock timeout Timeout compliance per device
Firewall A.8.9 Host firewall profile Enabled/locked status

A device showing 5/5 checks passing in SecureSlate gives auditors a clear operating-effectiveness signal. Devices below 5/5 need remediation tickets with owners before your surveillance audit.


Device enrollment baseline

Certification audits fail on endpoint controls when the managed population is incomplete. Establish these rules before Stage 1:

  1. No production access without MDM enrollment — IdP conditional access gates on MDM compliance where supported.
  2. Asset inventory matches MDM enrollment — reconcile HR headcount, contractor list, and device inventory monthly.
  3. BYOD follows the same five checks — personal devices accessing company data must meet identical baseline; see BYOD and MDM.
  4. Offboarding removes devices within SLA — MDM unenrollment or remote wipe tied to HR termination workflow.
  5. Exceptions are documented — lab machines, legacy hardware, and executive devices need risk acceptance in the SoA.

Enrollment rate should track workforce size. A 78% enrollment rate with 22% "special cases" is a Stage 2 conversation you do not want.


Implementation workflow

  1. Scope devices in the ISMS boundary — include remote workers, contractors, and BYOD per your access policy.
  2. Draft endpoint security procedures — reference the five checks explicitly; align with your information security policy.
  3. Configure MDM profiles — deploy encryption, AV, password, screen lock, and firewall baselines.
  4. Connect MDM to SecureSlate — Asset Management syncs device status and maps to Annex A controls.
  5. Run internal audit — sample 10+ devices; verify 5/5 checks and documentation match.
  6. Stage 1 readiness review — confirm SoA reflects MDM implementation; policies approved.
  7. Operate continuously — weekly dashboard review; remediate non-compliant devices before surveillance.

For a broader MDM program overview, see the MDM compliance guide.


Evidence for certification audits

Evidence type Stage 1 (documentation) Stage 2 / surveillance (operating)
Information security policy Approved; covers endpoint requirements Still current; version history
Endpoint / BYOD procedure References five checks Matches MDM configuration
Statement of Applicability Lists A.8.x controls with justification Updated for scope changes
MDM configuration exports Profile documentation Samples show consistent enforcement
SecureSlate population report N/A (pre-certification) 5/5 pass rates across period
Device samples Enrollment list Encryption, AV, firewall verified on samples
Exception register Risk acceptance documented Exceptions still valid; not expired
Offboarding records Procedure documented Samples show timely MDM removal

Certification bodies typically sample 5–15 endpoints depending on organization size. Pre-build exports in SecureSlate so retrieval does not depend on one engineer's MDM console access.


Common certification gaps

  • SoA excludes A.8.1 but devices access production — auditors will expand scope during Stage 2.
  • Policy says one thing, MDM enforces another — password length mismatch is a recurring finding.
  • No BYOD controls — personal phones with email access need the same baseline or explicit exclusion.
  • Surveillance audit surprise — team exports MDM data only when the auditor arrives; no continuous history.
  • Contractor devices unmanaged — third-party laptops with VPN access outside enrollment.

Roles and ownership

Role Typical responsibilities
ISMS manager / GRC lead SoA maintenance, auditor liaison, control mapping
IT / endpoint admin MDM configuration, enrollment, remediation
Information security officer Policy approval, risk acceptance for exceptions
People Ops / HR Offboarding triggers, contractor tracking
Internal audit Pre-certification sampling, finding tracking

Typical certification timeline

Phase Duration Endpoint focus
Gap analysis 2–4 weeks Inventory devices; compare to five-check baseline
Policy & SoA 2–4 weeks Document endpoint controls in SoA
MDM deployment 4–8 weeks Enroll population; deploy profiles
SecureSlate integration 1–2 weeks Connect MDM; verify 5/5 dashboard
Internal audit 1–2 weeks Sample devices; close findings
Stage 1 1–2 days Documentation review
Stage 2 3–5 days Operating effectiveness testing
Surveillance (annual) 1–2 days Continuous evidence from SecureSlate

Streamline with SecureSlate

SecureSlate Asset Management gives ISO 27001 teams continuous visibility into HD encryption, anti-virus, password policy, screen policy, and firewall status—mapped to Annex A controls and exportable for Stage 2 and surveillance audits.

Stop rebuilding MDM exports before every audit. Connect your MDM, track 5/5 endpoint checks, and export certification-ready evidence from one platform.

Get started for free · Free readiness score


FAQ: MDM for ISO 27001

Is MDM mandatory for ISO 27001 certification?

No—but auditors expect demonstrable control over endpoint devices. MDM is the most common implementation method for A.8.1 and related controls.

Can we certify with BYOD devices in scope?

Yes, if BYOD devices meet the same five-check baseline or have documented compensating controls. See BYOD policy.

How does SecureSlate differ from MDM reporting?

MDM shows current device state. SecureSlate tracks status over time, maps checks to Annex A controls, and exports audit evidence across surveillance periods.

Should we map the same evidence to SOC 2?

Yes—teams pursuing both frameworks reuse SecureSlate exports. See MDM for SOC 2 Type II endpoint evidence.

What enrollment rate should we target before Stage 2?

Aim for 95%+ of in-scope devices enrolled, with documented risk acceptance for remaining exceptions.

How often do surveillance audits test endpoints?

Annually in most programs. Continuous SecureSlate monitoring covers the period between audits without manual reconstruction.

Do we need separate policies for each check?

One endpoint security procedure referencing all five checks is typical. Separate policies are optional if your ISMS structure requires them.

What is the first step if we have no MDM today?

Start with device inventory and the five-check gap analysis—see building an endpoint security baseline for startups.


Disclaimer (legal note)

SecureSlate is not a law firm, and this article does not constitute legal advice or create an attorney-client relationship. Security and compliance obligations vary by industry, contract, and jurisdiction—consult qualified counsel as needed.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

4.8(195 reviews)

Keep reading

Aug 12, 2026 · GRC

Antivirus requirements for SOC 2 and ISO 27001: MDM enforcement and audit evidence

Aug 12, 2026 · GRC

Building an endpoint security baseline for startups

Aug 12, 2026 · GRC

BYOD and MDM: balancing flexibility and endpoint security

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?