Skip to main content

Pro audit program · v1.0

MDM Coverage Audit

Mobile devices accessing corporate data should be managed. Quick audit on enrolment, posture and wipe capability.

  • General target area
  • NIST CSF framework
  • 6 controls in this program
  • Cyentrix Cyentrix Trusted Author

About this program

Mobile devices accessing corporate data should be managed. Quick audit on enrolment, posture and wipe capability.

Risks addressed

  • High Lost phone with cached mailbox / OneDrive data
  • High Unmanaged personal device accessing corporate apps
  • High No way to wipe corporate data on offboarding

Controls (6)

  1. All corporate phones enrolled in MDM

    High

    This control requires that all corporate-issued mobile phones are enrolled in a Mobile Device Management (MDM) platform before being deployed to employees. The MDM system enforces security policies including passcode requirements, encryption, remote wipe capabilities, application whitelisting/blacklisting, and configuration baselines.…

    How to test + evidence

    Testing procedure: Compare MDM roster against HR + mobile carrier list.

    Evidence to collect: MDM roster + delta.

  2. Conditional access blocks unenrolled devices

    High

    This control enforces conditional access policies that prevent devices not enrolled in the organization's mobile device management (MDM) or unified endpoint management (UEM) platform from accessing corporate resources such as email, file shares, or SaaS applications. When a user attempts…

    How to test + evidence

    Testing procedure: Tier-1 apps require compliant device claim from MDM.

    Evidence to collect: CA policy export.

  3. Encryption + passcode enforced

    High

    This control requires that mobile devices and endpoints accessing organizational data enforce both encryption at rest and a passcode or biometric lock. Encryption protects data confidentiality if a device is lost or stolen, while passcode enforcement prevents unauthorized physical access.…

    How to test + evidence

    Testing procedure: MDM profile requires device PIN, biometrics, disk encryption.

    Evidence to collect: MDM compliance policy.

  4. Remote wipe capability tested

    High

    Remote wipe capability testing verifies that organizations can remotely erase all data from lost, stolen, or compromised mobile devices and endpoints to prevent unauthorized data access. This control requires documented testing procedures that simulate real-world scenarios, including testing across device…

    How to test + evidence

    Testing procedure: Documented test of remote-wipe on a sample device within last 12 months.

    Evidence to collect: Wipe test report.

  5. OS version policy + non-compliant remediation

    Medium

    This control establishes and enforces a formally documented policy defining minimum acceptable operating system versions across the enterprise, coupled with a structured remediation workflow for devices running non-compliant versions. The policy typically specifies version baselines, patch currency thresholds, and exceptions…

    How to test + evidence

    Testing procedure: Devices >2 major versions behind are non-compliant and pushed to update.

    Evidence to collect: Compliance report.

  6. Containerised work profile (BYOD)

    Medium

    Containerised work profiles (also known as work profile containers or managed profiles) enforce logical separation on personally-owned mobile devices by isolating enterprise applications, data, and credentials into a separate encrypted partition or profile. This approach enables BYOD policies by allowing…

    How to test + evidence

    Testing procedure: Personal devices use work profile; corporate data isolated.

    Evidence to collect: BYOD config.