Photo by Dan Nelson on Unsplash
How to pass 5/5 endpoint security checks in SecureSlate Asset Management
Endpoint security checks in SecureSlate Asset Management give GRC and IT teams a single score—X/5—for every enrolled device. Passing 5/5 means your fleet meets baseline controls for encryption, malware protection, authentication hygiene, screen lock, and host firewall—controls auditors and enterprise buyers sample repeatedly during SOC 2, ISO 27001, and due diligence.
This guide covers:
- What each of the five checks validates
- Pass criteria and common failure modes
- How MDM enforcement raises fleet-wide scores
- A remediation workflow from 3/5 to 5/5
- How to turn Asset Management data into audit evidence

GIF via GIPHY
Related guides:
- MDM compliance guide
- BYOD policy
- Screen lock policy best practices via MDM
- Laptop firewall basics for company devices
- MDM vs manual screenshots for audit evidence
- Device enrollment checklist for remote teams
Key takeaways
- SecureSlate tracks five endpoint checks: HD Encryption, Anti-Virus, Password Policy, Screen Policy, and Firewall.
- Each device shows X/5—prioritize remediation on anything below 5 before audit or customer review season.
- MDM is the enforcement backbone for remote and hybrid fleets where manual verification does not scale.
- Most failures are configuration drift, not missing tools—re-push MDM profiles and confirm agent sync.
- Asset Management evidence exports replace manual screenshot hunts for operating effectiveness.
The five endpoint checks
| # | Check | What it validates | Typical owner |
|---|---|---|---|
| 1 | HD Encryption | Full-disk encryption (FileVault, BitLocker, etc.) | IT / Endpoint |
| 2 | Anti-Virus | Approved AV installed, running, definitions current | IT / Security |
| 3 | Password Policy | Device password meets org length/complexity rules | IT / GRC |
| 4 | Screen Policy | Idle lock ≤15 min; password required on unlock | IT / Endpoint |
| 5 | Firewall | OS firewall enabled on all network profiles | IT / Endpoint |
A device scoring 5/5 passes all checks. A 3/5 device has two failing controls—SecureSlate surfaces which ones so IT can remediate without guessing.
HD Encryption
Full-disk encryption protects data at rest if a laptop is lost, stolen, or returned from a terminated employee without wipe confirmation.
Pass criteria: Device reports full-disk encryption enabled (FileVault on macOS, BitLocker or equivalent on Windows, LUKS on managed Linux).
Common failures:
- Encryption deferred at setup ("Enable later")
- External drives excluded without policy approval
- Recovery keys not escrowed in MDM (operational risk, not always a check failure)
Fix: MDM encryption payload with escrow; block productivity use until encryption completes. Include encryption verification in your device enrollment checklist.
Anti-Virus
Anti-Virus confirms malware protection is active—not merely installed.
Pass criteria: Approved antivirus or endpoint protection agent running with current definitions.
Common failures:
- Trial AV expired after purchase
- Developer machines excluded informally
- Agent uninstalled during troubleshooting and not restored
Fix: MDM-managed AV deployment; monthly compliance report; auto-remediation script to reinstall approved agent.
Password Policy
Device-level passwords are distinct from IdP/MFA—but auditors still sample local authentication settings on endpoints.
Pass criteria: Password meets organizational rules (minimum length, complexity, or passphrase standard as configured in SecureSlate).
Common failures:
- Simple PIN set locally after MDM push
- Shared kiosk accounts on test devices enrolled in production scope
- Policy updated in GRC but MDM profile not updated to match
Fix: Align MDM passcode payload with published policy; block simple passwords; audit exceptions quarterly.
Screen Policy
Screen Policy prevents unattended device access—a high-frequency audit sample for remote teams.
Pass criteria:
- Idle screen lock ≤15 minutes
- Password required on unlock
Common failures:
- Timeout set to 30+ minutes or Never
- Swipe-to-unlock without password
- Lid-close sleep without lock on wake
See the full screen lock policy best practices guide for MDM configuration by platform.
Firewall
Host firewall protects roaming devices off the corporate network.
Pass criteria: OS firewall enabled on all profiles (domain, private, and public on Windows; Application Firewall on macOS).
Common failures:
- Public profile disabled on Windows
- User turned off firewall for local development
- OS upgrade reset defaults
See laptop firewall basics for company devices for platform-specific remediation.
Remediation workflow
Use this sequence when fleet scores sit below 5/5:
- Pull Asset Management report — Sort by lowest X/5; group failures by check type.
- Identify root cause — MDM profile gap, enrollment miss, or user override?
- Batch remediate by OS — Re-push profiles fleet-wide before one-off tickets.
- Re-enroll chronic offenders — Devices that drift repeatedly may need wipe-and-rebuild.
- Validate pass — Confirm 5/5 on next sync before closing ITSM tickets.
- Document exceptions — Approved deviations with expiry and executive sign-off only.
| Starting score | Typical effort | Target timeline |
|---|---|---|
| 4/5 | Single profile tweak | 1–3 days |
| 3/5 | Multi-control MDM update | 1–2 weeks |
| 1–2/5 | Re-enrollment or rebuild | 2–4 weeks |
| Mixed fleet, no MDM | MDM rollout + enrollment | 4–8 weeks |
Programs that connect MDM with SecureSlate Asset Management typically reach >95% at 5/5 within one remediation cycle after initial enrollment.
Evidence for audits and customer reviews
| Audience | What they ask for | SecureSlate source |
|---|---|---|
| SOC 2 auditor | Device sample showing encryption, AV, lock settings | Asset Management export |
| ISO 27001 auditor | Annex A endpoint protection evidence | X/5 report + MDM sync |
| Enterprise buyer | "How do you enforce laptop security?" | Dashboard + policy mapping |
| Internal leadership | Fleet compliance KPI | % devices at 5/5 trend |
Continuous Asset Management history demonstrates operating effectiveness across a Type II observation window—stronger than screenshots collected the week before fieldwork. Compare approaches in MDM vs manual screenshots.
Pass 5/5 with SecureSlate MDM + Asset Management
SecureSlate combines MDM enrollment, five-check Asset Management monitoring, and GRC evidence workflows—so endpoint security supports audits, customer trust, and IT operations from one platform.
Get started for free · Free readiness score
FAQ: SecureSlate endpoint security checks
What does X/5 mean on the Asset Management dashboard?
X is the number of passing checks out of five (HD Encryption, Anti-Virus, Password Policy, Screen Policy, Firewall). 5/5 is full compliance with the baseline.
Can I customize pass criteria for Screen Policy or Password Policy?
Screen Policy uses the SecureSlate baseline: idle lock ≤15 minutes and password on unlock. Password Policy aligns with rules you configure in the platform. Encryption, AV, and Firewall checks follow standard enablement criteria.
Do all five checks need to pass for SOC 2?
Auditors sample subsets, but failing checks indicate control gaps that may become findings. Aim for fleet-wide 5/5 before fieldwork.
How often are checks refreshed?
Checks run on Asset Management agent sync—typically daily or on each check-in, depending on configuration.
What if one employee uses Linux?
Enroll supported Linux devices through MDM or document compensating controls. Unsupported devices should be excluded from scope with approver sign-off.
Can SecureSlate replace our MDM?
SecureSlate MDM handles enrollment and profile deployment; Asset Management validates the five checks. Using both together gives enforcement plus evidence.
Where do I start if our fleet is mostly 2/5?
Start with device enrollment and MDM profile deployment for encryption and screen lock—usually the highest-impact fixes.
Disclaimer (legal note)
SecureSlate is not a law firm, and this article does not constitute legal advice or create an attorney-client relationship. Security and compliance obligations vary by industry, contract, and jurisdiction—consult qualified counsel as needed.
Need compliance without the complexity?
SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.
Find compliance gaps in 30 seconds
