Skip to main content
← All controls
CIS-10.7 / NIST SI-4 / ISO 27001:2022 A.8.16 CIS Controls v8

EDR on every endpoint

Demonstrate that every in-scope endpoint has an operational EDR agent deployed, reporting telemetry, and receiving current detection signatures without gaps in coverage.

Description

What this control does

Endpoint Detection and Response (EDR) software must be deployed on all workstations, servers, and mobile devices within the organization's asset inventory. EDR agents continuously monitor endpoint activity, detect suspicious behaviors using signature-based and behavioral analytics, provide forensic visibility into security incidents, and enable rapid containment through remote isolation or remediation actions. This control ensures that every managed endpoint has an active, up-to-date EDR sensor reporting to a centralized management console, eliminating blind spots where attackers could establish persistence undetected.

Control objective

What auditing this proves

Demonstrate that every in-scope endpoint has an operational EDR agent deployed, reporting telemetry, and receiving current detection signatures without gaps in coverage.

Associated risks

Risks this control addresses

  • Unmonitored endpoints allow attackers to establish persistent footholds without detection, enabling lateral movement and data exfiltration
  • Ransomware executes on unprotected systems without triggering alerts, leading to widespread encryption before response teams can intervene
  • Insider threats or compromised credentials are used on endpoints lacking behavioral monitoring, preventing detection of abnormal activity patterns
  • Post-compromise forensic investigations fail due to absence of endpoint telemetry logs, preventing root cause analysis and scope determination
  • Zero-day malware bypasses perimeter defenses and operates freely on endpoints without behavioral detection capabilities
  • Compliance violations occur when sensitive data is accessed or exfiltrated from endpoints outside the EDR monitoring scope
  • Shadow IT devices connect to corporate networks without security instrumentation, creating unmanaged attack surfaces

Live threat patterns this control mitigates:

HIGH Targeted Attack on Government Entities in the Middle East | Part 2 A sophisticated multi-stage campaign targets government entities in the Middle East, deploying BINDCLOAK, a previously undocumented 64-bit modular… MEDIUM TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting… HIGH Targeted Attack on Government Entities in the Middle East | Part 1 In July 2026, a threat actor with links to East Asia launched sophisticated attacks against government entities in… HIGH ClickLock Stealer: Paste Once, Lose Everything A new modular macOS information stealer named ClickLock Stealer has been discovered targeting users primarily in Europe, North… MEDIUM OkoBot framework infection chain In January 2026, researchers identified a sophisticated malware framework dubbed OkoBot that targets cryptocurrency users through a multi-stage… MEDIUM The Crown Prince, Nezha Beginning in August 2025, a sophisticated intrusion was discovered where attackers used log poisoning techniques to deploy a… CRITICAL Ransomware Extortion Post Victim posted on a ransomware leak site after refusing or delaying ransom payment. Indicates an initial-access + privilege-escalation… MEDIUM Android Trojan Abuses Commercial Rooting Tool and Steals Private Information Rootnik is an Android trojan that exploits vulnerabilities in Android 4.3 and earlier by weaponizing a Chinese commercial… MEDIUM Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor Cybersecurity researchers have disclosed details of a new Linux malware dubbed Showboat that has been put to use… CRITICAL Ransomware Incident Confirmed ransomware encryption + extortion event. Calls for the full playbook: MFA on remote access, immutable backups, EDR…

Testing procedure

How an auditor verifies this control

  1. Obtain a complete inventory of all in-scope endpoints including workstations, servers, virtual machines, and mobile devices from asset management systems or CMDBs.
  2. Export the list of all devices with active EDR agents from the EDR management console, including agent version, last check-in timestamp, and operational status.
  3. Cross-reference the asset inventory against the EDR enrollment list to identify endpoints missing EDR agents or with agents in a disconnected state.
  4. Select a representative sample of endpoints (minimum 20-30 across different OS types, business units, and locations) and remotely verify the EDR agent is running and communicating with the management server.
  5. Review EDR agent configuration policies to confirm real-time protection is enabled, telemetry collection is active, and automatic updates are configured.
  6. Query EDR logs for the sample endpoints to confirm they are generating and transmitting security event data within the past 24 hours.
  7. Verify that documented exceptions for endpoints without EDR (air-gapped systems, legacy unsupported OS, etc.) have current risk acceptance approvals from appropriate management.
  8. Test EDR detection capability by executing a safe simulation (EICAR test file or EDR vendor's built-in test tool) on a sample endpoint and confirm the alert is generated and visible in the console.
Evidence required Collect the complete asset inventory export, EDR agent enrollment report with agent status and version details, configuration policy screenshots showing protection settings, and EDR event logs for the sampled endpoints. Retain screenshots of the EDR console showing agent health dashboards, any gap analysis reports identifying unprotected endpoints, and documented risk acceptance forms for approved exceptions. Capture timestamped evidence of the detection simulation test showing the alert generated in the EDR console.
Pass criteria All endpoints in the asset inventory have an active, communicating EDR agent with current signatures and enabled real-time protection, or have documented and approved risk acceptance for any exceptions that include compensating controls.

Where this control is tested

Audit programs including this control