Back to GRC

How to pass 5/5 endpoint security checks in SecureSlate Asset Management

Photo by Dan Nelson on Unsplash

How to pass 5/5 endpoint security checks in SecureSlate Asset Management

Endpoint security checks in SecureSlate Asset Management give GRC and IT teams a single score—X/5—for every enrolled device. Passing 5/5 means your fleet meets baseline controls for encryption, malware protection, authentication hygiene, screen lock, and host firewall—controls auditors and enterprise buyers sample repeatedly during SOC 2, ISO 27001, and due diligence.

This guide covers:

  • What each of the five checks validates
  • Pass criteria and common failure modes
  • How MDM enforcement raises fleet-wide scores
  • A remediation workflow from 3/5 to 5/5
  • How to turn Asset Management data into audit evidence

Security checklist and compliance verification

GIF via GIPHY

Related guides:


Key takeaways

  • SecureSlate tracks five endpoint checks: HD Encryption, Anti-Virus, Password Policy, Screen Policy, and Firewall.
  • Each device shows X/5—prioritize remediation on anything below 5 before audit or customer review season.
  • MDM is the enforcement backbone for remote and hybrid fleets where manual verification does not scale.
  • Most failures are configuration drift, not missing tools—re-push MDM profiles and confirm agent sync.
  • Asset Management evidence exports replace manual screenshot hunts for operating effectiveness.

The five endpoint checks

# Check What it validates Typical owner
1 HD Encryption Full-disk encryption (FileVault, BitLocker, etc.) IT / Endpoint
2 Anti-Virus Approved AV installed, running, definitions current IT / Security
3 Password Policy Device password meets org length/complexity rules IT / GRC
4 Screen Policy Idle lock ≤15 min; password required on unlock IT / Endpoint
5 Firewall OS firewall enabled on all network profiles IT / Endpoint

A device scoring 5/5 passes all checks. A 3/5 device has two failing controls—SecureSlate surfaces which ones so IT can remediate without guessing.


HD Encryption

Full-disk encryption protects data at rest if a laptop is lost, stolen, or returned from a terminated employee without wipe confirmation.

Pass criteria: Device reports full-disk encryption enabled (FileVault on macOS, BitLocker or equivalent on Windows, LUKS on managed Linux).

Common failures:

  • Encryption deferred at setup ("Enable later")
  • External drives excluded without policy approval
  • Recovery keys not escrowed in MDM (operational risk, not always a check failure)

Fix: MDM encryption payload with escrow; block productivity use until encryption completes. Include encryption verification in your device enrollment checklist.


Anti-Virus

Anti-Virus confirms malware protection is active—not merely installed.

Pass criteria: Approved antivirus or endpoint protection agent running with current definitions.

Common failures:

  • Trial AV expired after purchase
  • Developer machines excluded informally
  • Agent uninstalled during troubleshooting and not restored

Fix: MDM-managed AV deployment; monthly compliance report; auto-remediation script to reinstall approved agent.


Password Policy

Device-level passwords are distinct from IdP/MFA—but auditors still sample local authentication settings on endpoints.

Pass criteria: Password meets organizational rules (minimum length, complexity, or passphrase standard as configured in SecureSlate).

Common failures:

  • Simple PIN set locally after MDM push
  • Shared kiosk accounts on test devices enrolled in production scope
  • Policy updated in GRC but MDM profile not updated to match

Fix: Align MDM passcode payload with published policy; block simple passwords; audit exceptions quarterly.


Screen Policy

Screen Policy prevents unattended device access—a high-frequency audit sample for remote teams.

Pass criteria:

  • Idle screen lock ≤15 minutes
  • Password required on unlock

Common failures:

  • Timeout set to 30+ minutes or Never
  • Swipe-to-unlock without password
  • Lid-close sleep without lock on wake

See the full screen lock policy best practices guide for MDM configuration by platform.


Firewall

Host firewall protects roaming devices off the corporate network.

Pass criteria: OS firewall enabled on all profiles (domain, private, and public on Windows; Application Firewall on macOS).

Common failures:

  • Public profile disabled on Windows
  • User turned off firewall for local development
  • OS upgrade reset defaults

See laptop firewall basics for company devices for platform-specific remediation.


Remediation workflow

Use this sequence when fleet scores sit below 5/5:

  1. Pull Asset Management report — Sort by lowest X/5; group failures by check type.
  2. Identify root cause — MDM profile gap, enrollment miss, or user override?
  3. Batch remediate by OS — Re-push profiles fleet-wide before one-off tickets.
  4. Re-enroll chronic offenders — Devices that drift repeatedly may need wipe-and-rebuild.
  5. Validate pass — Confirm 5/5 on next sync before closing ITSM tickets.
  6. Document exceptions — Approved deviations with expiry and executive sign-off only.
Starting score Typical effort Target timeline
4/5 Single profile tweak 1–3 days
3/5 Multi-control MDM update 1–2 weeks
1–2/5 Re-enrollment or rebuild 2–4 weeks
Mixed fleet, no MDM MDM rollout + enrollment 4–8 weeks

Programs that connect MDM with SecureSlate Asset Management typically reach >95% at 5/5 within one remediation cycle after initial enrollment.


Evidence for audits and customer reviews

Audience What they ask for SecureSlate source
SOC 2 auditor Device sample showing encryption, AV, lock settings Asset Management export
ISO 27001 auditor Annex A endpoint protection evidence X/5 report + MDM sync
Enterprise buyer "How do you enforce laptop security?" Dashboard + policy mapping
Internal leadership Fleet compliance KPI % devices at 5/5 trend

Continuous Asset Management history demonstrates operating effectiveness across a Type II observation window—stronger than screenshots collected the week before fieldwork. Compare approaches in MDM vs manual screenshots.


Pass 5/5 with SecureSlate MDM + Asset Management

SecureSlate combines MDM enrollment, five-check Asset Management monitoring, and GRC evidence workflows—so endpoint security supports audits, customer trust, and IT operations from one platform.

Get started for free · Free readiness score


FAQ: SecureSlate endpoint security checks

What does X/5 mean on the Asset Management dashboard?

X is the number of passing checks out of five (HD Encryption, Anti-Virus, Password Policy, Screen Policy, Firewall). 5/5 is full compliance with the baseline.

Can I customize pass criteria for Screen Policy or Password Policy?

Screen Policy uses the SecureSlate baseline: idle lock ≤15 minutes and password on unlock. Password Policy aligns with rules you configure in the platform. Encryption, AV, and Firewall checks follow standard enablement criteria.

Do all five checks need to pass for SOC 2?

Auditors sample subsets, but failing checks indicate control gaps that may become findings. Aim for fleet-wide 5/5 before fieldwork.

How often are checks refreshed?

Checks run on Asset Management agent sync—typically daily or on each check-in, depending on configuration.

What if one employee uses Linux?

Enroll supported Linux devices through MDM or document compensating controls. Unsupported devices should be excluded from scope with approver sign-off.

Can SecureSlate replace our MDM?

SecureSlate MDM handles enrollment and profile deployment; Asset Management validates the five checks. Using both together gives enforcement plus evidence.

Where do I start if our fleet is mostly 2/5?

Start with device enrollment and MDM profile deployment for encryption and screen lock—usually the highest-impact fixes.


Disclaimer (legal note)

SecureSlate is not a law firm, and this article does not constitute legal advice or create an attorney-client relationship. Security and compliance obligations vary by industry, contract, and jurisdiction—consult qualified counsel as needed.

Need compliance without the complexity?

SecureSlate automates ISO 27001, SOC 2, GDPR, HIPAA, and more. Built for growing teams. See it in action.

Find compliance gaps in 30 seconds

Filed under:

Author: SecureSlate Team

4.9(167 reviews)

Keep reading

Aug 12, 2026 · GRC

Antivirus requirements for SOC 2 and ISO 27001: MDM enforcement and audit evidence

Aug 12, 2026 · GRC

Building an endpoint security baseline for startups

Aug 12, 2026 · GRC

BYOD and MDM: balancing flexibility and endpoint security

View more posts
Jamie
Virtual Agent

Hi! I'm Jamie. Curious about your current compliance challenges and how automation might help your team?