Ga naar inhoud

ISO 27001 ·

MDM and endpoint security: ISO 27001 evidence in 2026

Endpoints — laptops, phones, tablets — are where company data leaves the building, and therefore a favourite audit sample. For ISO 27001 it is no longer enough to say “we have antivirus”; an auditor wants demonstrable control over your devices. Mobile Device Management (MDM), such as Microsoft Intune or Jamf, is the engine for that. Without MDM, you have to explicitly accept the residual risk in your management review — and that stands out.

Why endpoints are under scrutiny

The classic measures (encryption, patching, access control) only become credible once you can enforce and prove them on every device. A policy that says “all laptops are encrypted” is worthless without a report showing it is actually true. MDM delivers that report, turning your endpoint policy from a good intention into a checkable fact.

The minimum MDM evidence

For an SME, a compact set already covers a lot — and the evidence arises by itself:

  • Device compliance policy: a report with the percentage of compliant devices, and what happens to a non-compliant one.
  • Encryption: BitLocker (Windows) or FileVault (Mac) enforced and reported — not “recommended”.
  • Patch management: OS and app updates within a set SLA, with visibility of stragglers.
  • BYOD: a separate policy for personal devices, or a justified ban. Half-allowing it without rules is the worst option.

Link these sources to your ISMS and your Statement of Applicability, and export a monthly compliance report to your evidence folder.

What the auditor concretely does

Expect a sample: the auditor picks one non-compliant device from your report and asks questions. What was wrong, when was it detected, who got the ticket, was access blocked, and is it resolved? The chain from detection to remediation must be visible. In fact, a non-compliant device that was properly followed up is stronger evidence than a report claiming 100% green — because no one believes the latter.

BYOD without the headache

Personal devices are the hardest. You do not want full control over an employee’s phone, but your data must still be protected. The practical middle ground is app-level management: company data in a managed container you can wipe remotely, without touching personal photos. Record the choice made — including what you deliberately do not enforce and why — so the assessment is traceable.

Link it to the chain

Many requirements in 2026 come not from law but from your clients. Enterprise customers set contractual requirements for endpoint security, patch deadlines and incident reporting. Make sure your contract SLAs and internal policy align, and document where a customer is stricter than your own standard — your management review must consciously accept that gap or plan budget for it.

Common mistakes

  • Policy without enforcement — “laptops must be encrypted” without MDM to check it is an empty promise.
  • Claiming 100% green — unrealistic and suspicious; show instead how you follow up deviations.
  • Ignoring BYOD — personal devices reaching company data with no rules are a classic finding.
  • Never reviewing the report — collecting data without anyone acting on it does not count as control.

Getting started

Start with one compliance report from your MDM and a BYOD agreement on paper. Then schedule a monthly export to your evidence folder. That alone makes your next audit noticeably calmer. Want to know more about audit evidence? See the ISO 27001 route or take the free readiness scan.

Deep dive in the knowledge base

Run the ISO 27001 readiness scan

See where you stand before investing in documents or consultants.

Start the readiness scan

← Back to overview