graphgrc

END-01: Device Management (macOS MDM)

Objective

Secure employee endpoints through centralized management.

Description

All employee devices are managed through MDM. Security policies are enforced including disk encryption, screen lock, and automatic updates. Lost devices can be remotely wiped.

Implementation Details

MDM Solution: Jamf Pro or Kandji for Mac management. All devices enrolled before provision to employee.

Required Policies: FileVault enabled, screen lock after 5 minutes, automatic updates enabled, malware protection installed.

Compliance Monitoring: MDM dashboard shows device compliance. Non-compliant devices flagged and user notified.

Remote Wipe: Lost or stolen device remotely wiped via MDM. Terminated employee devices wiped within 1 hour.

Examples

Audit Evidence


Framework Mapping

SOC 2

GDPR


Referenced By

This section is automatically generated by make generate-backlinks. Do not edit manually.

Standards:

Policies: