Skip to content
arrow_back
search
Annex A 8.1 verified ISO/IEC 27001:2022

Protection of User Endpoint Devices

Ensure all laptops, mobiles, and tablets are secure to protect stored information.

record_voice_over

Plain language

This control is all about keeping your devices like laptops, phones, and tablets secure. If they're not protected, sensitive information could be lost or stolen, potentially harming your organisation's reputation and finances. It's like locking the doors to your house to keep your belongings safe.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Technological controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Information stored on, processed by or accessible via user end point devices shall be protected.
verified ISO/IEC 27001:2022 Annex A 8.1
priority_high

Why it matters

If user endpoint devices are compromised, attackers can access or exfiltrate data stored on or reachable via the device, causing breaches and loss.

settings

Operational notes

Use full-disk encryption, prompt OS/app patching, EDR/anti-malware with monitoring, and device hardening (screen lock, MDM, least privilege) for endpoints.

Mapping detail

Mapping

Direction

Controls