Skip to content

Evidence request lists

NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices

Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Data Protection

800-124r2-4.1
Data Protection on Mobile Devices

Protect enterprise data on mobile devices through device level encryption, application containerization, and data loss prevention controls.

Artefacts an auditor will ask for
  • Encryption status reporting
  • Container configuration
  • DLP policy and incident records
  • Backup destination controls
Where this commonly fails
  • Personal and enterprise data co-mingled
  • DLP policies not enforced for messaging applications
  • Backup to personal accounts permitted
800-124r2-4.2
Data Communication Protection

Protect mobile data in transit through approved VPN, secure messaging, and TLS enforcement to enterprise resources.

Artefacts an auditor will ask for
  • Per app VPN configuration
  • Approved secure messaging applications
  • TLS version enforcement evidence
  • Traffic inspection records where applicable
Where this commonly fails
  • Split tunneling allowed for sensitive applications
  • Public Wi-Fi use without VPN
  • Legacy TLS still permitted
800-124r2-4.3
Lost or Stolen Device Procedures

Define and operate procedures for reporting and responding to lost or stolen mobile devices including remote lock, locate, and wipe.

Artefacts an auditor will ask for
  • Lost device reporting hotline or portal
  • Wipe action audit log
  • Service level metrics for response time
  • User awareness materials
Where this commonly fails
  • No service level for response time
  • Users unaware of reporting channel
  • Wipe actions not logged or reviewed

Deployment Models

800-124r2-6.1
BYOD Considerations

Apply specific controls and user agreements where personal devices access enterprise resources, including privacy considerations.

Artefacts an auditor will ask for
  • BYOD policy and acknowledgement
  • Privacy notice for managed personal devices
  • Container or workspace configuration
  • Offboarding workflow for BYOD
Where this commonly fails
  • Full device wipe risk on personal devices
  • No privacy notice provided to users
  • Offboarding misses cached enterprise data
800-124r2-6.2
Corporate Owned Device Models

Define configuration and user privacy posture for corporate owned, business only, and corporate owned personally enabled deployment models.

Artefacts an auditor will ask for
  • Deployment model decision record
  • Profiles per deployment model
  • User notice of monitoring scope
  • Asset register tagged by model
Where this commonly fails
  • Mixed models within a single profile group
  • Monitoring scope not disclosed
  • Inventory not tagged by ownership model

Governance

800-124r2-2.2
Mobile Device Policy

Establish enterprise policies covering acceptable use, ownership models, supported platforms, and security requirements for mobile devices accessing enterprise resources.

Artefacts an auditor will ask for
  • Approved mobile device policy
  • Acceptable use policy acknowledgements
  • Ownership model decision record
  • Policy exception register
Where this commonly fails
  • Policy silent on personal device use
  • No acknowledgement collection for contractors
  • Policy not updated when new operating systems are supported

Identity

800-124r2-8.1
Identity and Access Integration

Integrate mobile devices with enterprise identity platforms so that authentication, authorization, and conditional access apply consistently.

Artefacts an auditor will ask for
  • Identity provider integration evidence
  • Conditional access policies
  • Strong authentication enforcement reporting
  • Privileged access controls for mobile administrators
Where this commonly fails
  • Local accounts on devices that bypass identity provider
  • MFA exceptions for mobile users
  • Privileged actions performed from non-managed devices

Lifecycle

800-124r2-7.1
Mobile Device Lifecycle Management

Manage mobile devices through their lifecycle from procurement and provisioning to maintenance and disposal.

Artefacts an auditor will ask for
  • Procurement standard with security clauses
  • Provisioning workflow
  • Maintenance and repair process
  • Disposal and sanitization records
Where this commonly fails
  • Procurement bypasses standard channels
  • No standard handover when staff change roles
  • Disposal handled outside of asset management
800-124r2-7.2
Mobile Device Decommissioning

Decommission mobile devices through full data sanitization, account removal, and recycling or destruction aligned to media policy.

Artefacts an auditor will ask for
  • Decommissioning checklist
  • Wipe verification records
  • Recycling vendor certification
  • Asset register update evidence
Where this commonly fails
  • Wipe not verified before disposal
  • Vendor certifications not collected
  • Stale assets remain in inventory

Mobile Device Policies

MD124-POL-01
Mobile Device Security Policy

Develop a mobile device security policy addressing authorized devices, operating systems, security requirements, acceptable use, and consequences for non-compliance.

Artefacts an auditor will ask for
  • Mobile device security policy approved by leadership
  • BYOD acceptable use agreement signed by users
  • Mobile data protection policy with classification mapping
  • Device lifecycle procedure from issuance to disposal
Where this commonly fails
  • Policy not refreshed for new device classes (wearables, eSIM)
  • BYOD consent forms missing legal review
  • Data protection policy silent on offline cached data
  • Lifecycle records do not include sanitisation evidence
MD124-POL-02
BYOD Policy

Establish Bring Your Own Device policies defining requirements for personal devices accessing enterprise resources, including containerization, minimum security configurations.

Artefacts an auditor will ask for
  • Mobile device security policy approved by leadership
  • BYOD acceptable use agreement signed by users
  • Mobile data protection policy with classification mapping
  • Device lifecycle procedure from issuance to disposal
Where this commonly fails
  • Policy not refreshed for new device classes (wearables, eSIM)
  • BYOD consent forms missing legal review
  • Data protection policy silent on offline cached data
  • Lifecycle records do not include sanitisation evidence
MD124-POL-03
Mobile Data Protection Policy

Define data protection requirements for mobile devices including encryption, data loss prevention, and restrictions on sensitive data storage and transmission.

Artefacts an auditor will ask for
  • Mobile device security policy approved by leadership
  • BYOD acceptable use agreement signed by users
  • Mobile data protection policy with classification mapping
  • Device lifecycle procedure from issuance to disposal
Where this commonly fails
  • Policy not refreshed for new device classes (wearables, eSIM)
  • BYOD consent forms missing legal review
  • Data protection policy silent on offline cached data
  • Lifecycle records do not include sanitisation evidence
MD124-POL-04
Mobile Device Lifecycle Management

Establish procedures for the complete lifecycle of mobile devices including procurement, provisioning, operation, incident response, and secure disposal.

Artefacts an auditor will ask for
  • Mobile device security policy approved by leadership
  • BYOD acceptable use agreement signed by users
  • Mobile data protection policy with classification mapping
  • Device lifecycle procedure from issuance to disposal
Where this commonly fails
  • Policy not refreshed for new device classes (wearables, eSIM)
  • BYOD consent forms missing legal review
  • Data protection policy silent on offline cached data
  • Lifecycle records do not include sanitisation evidence

Mobile Device Security Controls

MD124-CTL-01
Device Authentication and Lock

Require strong device authentication (biometric + PIN/password). Configure automatic lock after inactivity period. Implement remote lock capabilities.

Artefacts an auditor will ask for
  • Mobile device enrolment and policy configuration evidence
  • Encryption attestation for managed mobile devices
  • Remote wipe procedure with execution logs
  • Patch and update compliance reports from MDM
Where this commonly fails
  • BYOD devices not subject to encryption attestation
  • Remote wipe limited to corporate workspace containers only
  • Patch compliance reporting lacks executive thresholds
  • Jailbreak detection alerts not integrated with SOC
MD124-CTL-02
Device Encryption

Enable full-device encryption on all managed mobile devices. Ensure encryption keys are properly managed and protected.

Artefacts an auditor will ask for
  • Mobile device enrolment and policy configuration evidence
  • Encryption attestation for managed mobile devices
  • Remote wipe procedure with execution logs
  • Patch and update compliance reports from MDM
Where this commonly fails
  • BYOD devices not subject to encryption attestation
  • Remote wipe limited to corporate workspace containers only
  • Patch compliance reporting lacks executive thresholds
  • Jailbreak detection alerts not integrated with SOC
MD124-CTL-03
Remote Wipe Capability

Enable remote wipe for managed devices. Configure selective wipe for BYOD to remove only enterprise data. Test wipe capabilities regularly.

Artefacts an auditor will ask for
  • Mobile device enrolment and policy configuration evidence
  • Encryption attestation for managed mobile devices
  • Remote wipe procedure with execution logs
  • Patch and update compliance reports from MDM
Where this commonly fails
  • BYOD devices not subject to encryption attestation
  • Remote wipe limited to corporate workspace containers only
  • Patch compliance reporting lacks executive thresholds
  • Jailbreak detection alerts not integrated with SOC
MD124-CTL-04
OS and Application Updates

Enforce timely OS and application updates. Define maximum allowable delay for security patches. Consider automatic update enforcement.

Artefacts an auditor will ask for
  • Mobile device enrolment and policy configuration evidence
  • Encryption attestation for managed mobile devices
  • Remote wipe procedure with execution logs
  • Patch and update compliance reports from MDM
Where this commonly fails
  • BYOD devices not subject to encryption attestation
  • Remote wipe limited to corporate workspace containers only
  • Patch compliance reporting lacks executive thresholds
  • Jailbreak detection alerts not integrated with SOC
MD124-CTL-05
Jailbreak/Root Detection

Detect and respond to jailbroken or rooted devices. Block compromised devices from accessing enterprise resources. Alert security teams.

Artefacts an auditor will ask for
  • Mobile device enrolment and policy configuration evidence
  • Encryption attestation for managed mobile devices
  • Remote wipe procedure with execution logs
  • Patch and update compliance reports from MDM
Where this commonly fails
  • BYOD devices not subject to encryption attestation
  • Remote wipe limited to corporate workspace containers only
  • Patch compliance reporting lacks executive thresholds
  • Jailbreak detection alerts not integrated with SOC
MD124-CTL-06
Network Security for Mobile

Configure secure Wi-Fi settings (WPA3/WPA2-Enterprise). Disable auto-connect to unknown networks. Implement cellular network security controls.

Artefacts an auditor will ask for
  • Mobile device enrolment and policy configuration evidence
  • Encryption attestation for managed mobile devices
  • Remote wipe procedure with execution logs
  • Patch and update compliance reports from MDM
Where this commonly fails
  • BYOD devices not subject to encryption attestation
  • Remote wipe limited to corporate workspace containers only
  • Patch compliance reporting lacks executive thresholds
  • Jailbreak detection alerts not integrated with SOC

Mobile Device Security Technologies

MD124-TECH-01
Enterprise Mobility Management (EMM)

Deploy EMM/MDM solutions to manage mobile device configuration, enforce security policies, distribute applications, and remotely manage devices.

Artefacts an auditor will ask for
  • Enterprise mobility management configuration baseline
  • Mobile threat defence telemetry and alerting evidence
  • Mobile application vetting reports for approved apps
  • Secure communications and VPN deployment configuration
Where this commonly fails
  • MTD deployed without integration into incident workflows
  • Application vetting limited to enterprise app store
  • VPN split tunnelling permits direct internet egress
  • MAM policies not enforced on personal cloud sync apps
MD124-TECH-02
Mobile Threat Defense (MTD)

Deploy MTD solutions to detect and mitigate device-level, network-level, and application-level threats on mobile devices.

Artefacts an auditor will ask for
  • Enterprise mobility management configuration baseline
  • Mobile threat defence telemetry and alerting evidence
  • Mobile application vetting reports for approved apps
  • Secure communications and VPN deployment configuration
Where this commonly fails
  • MTD deployed without integration into incident workflows
  • Application vetting limited to enterprise app store
  • VPN split tunnelling permits direct internet egress
  • MAM policies not enforced on personal cloud sync apps
MD124-TECH-03
Mobile Application Vetting

Establish a mobile application vetting process to evaluate app security before deployment. Assess apps for malware, privacy violations, and vulnerabilities.

Artefacts an auditor will ask for
  • Enterprise mobility management configuration baseline
  • Mobile threat defence telemetry and alerting evidence
  • Mobile application vetting reports for approved apps
  • Secure communications and VPN deployment configuration
Where this commonly fails
  • MTD deployed without integration into incident workflows
  • Application vetting limited to enterprise app store
  • VPN split tunnelling permits direct internet egress
  • MAM policies not enforced on personal cloud sync apps
MD124-TECH-04
Mobile Application Management (MAM)

Manage applications on mobile devices including deployment, updates, configuration, and removal. Separate personal and enterprise applications.

Artefacts an auditor will ask for
  • Enterprise mobility management configuration baseline
  • Mobile threat defence telemetry and alerting evidence
  • Mobile application vetting reports for approved apps
  • Secure communications and VPN deployment configuration
Where this commonly fails
  • MTD deployed without integration into incident workflows
  • Application vetting limited to enterprise app store
  • VPN split tunnelling permits direct internet egress
  • MAM policies not enforced on personal cloud sync apps
MD124-TECH-05
VPN and Secure Communication

Configure VPN or per-app VPN for mobile devices accessing enterprise resources. Ensure all enterprise traffic is encrypted.

Artefacts an auditor will ask for
  • Enterprise mobility management configuration baseline
  • Mobile threat defence telemetry and alerting evidence
  • Mobile application vetting reports for approved apps
  • Secure communications and VPN deployment configuration
Where this commonly fails
  • MTD deployed without integration into incident workflows
  • Application vetting limited to enterprise app store
  • VPN split tunnelling permits direct internet egress
  • MAM policies not enforced on personal cloud sync apps

Monitoring and Response

800-124r2-5.1
Mobile Threat Defense Monitoring

Continuously monitor mobile devices for indicators of compromise including malware, jailbreak, root, and abnormal behavior.

Artefacts an auditor will ask for
  • MTD coverage report
  • Detection rule set documentation
  • Alert triage records
  • Integration with SOC workflows
Where this commonly fails
  • MTD installed but not enforced
  • Alerts routed only to end users
  • Coverage gaps for tablet and shared device fleets
800-124r2-5.2
Mobile Operating System Updates

Ensure mobile operating systems and firmware receive timely security updates aligned to vendor release cycles and risk tolerance.

Artefacts an auditor will ask for
  • Update compliance dashboard
  • Forced update configuration evidence
  • End of support roadmap per platform
  • Exception register
Where this commonly fails
  • Devices stuck on outdated OS due to carrier delays
  • End of support devices still active
  • No deadlines on user managed updates
800-124r2-5.3
User Awareness for Mobile Risks

Train mobile device users on threats such as phishing, malicious applications, untrusted networks, and physical loss risks.

Artefacts an auditor will ask for
  • Mobile awareness training content
  • Completion records
  • Phishing simulation results
  • Awareness campaign materials
Where this commonly fails
  • Training generic to all device types
  • No reinforcement after initial onboarding
  • Simulations not measured for improvement
800-124r2-8.2
Continuous Compliance Reporting

Produce continuous compliance reports for the mobile estate covering enrollment, posture, application inventory, and exceptions.

Artefacts an auditor will ask for
  • Compliance dashboard
  • Monthly metrics report
  • Exception trend analysis
  • Action items log from leadership reviews
Where this commonly fails
  • Reports issued but not acted upon
  • Metrics not tied to risk decisions
  • No leadership review cadence

Risk Management

800-124r2-2.1
Mobile Device Threat Model

Maintain a documented threat model for mobile devices that addresses device, network, application, and ecosystem level threats relevant to the enterprise.

Artefacts an auditor will ask for
  • Mobile threat model document
  • Annual review records
  • Risk register entries tied to mobile
  • Threat intelligence sources used
Where this commonly fails
  • Threat model not refreshed for new mobile operating system versions
  • BYOD scenarios omitted
  • No alignment with mobile threat defense tooling

Technical Controls

800-124r2-3.1
Enterprise Mobility Management Deployment

Deploy an enterprise mobility management platform that enforces device configuration, application management, and selective wipe capabilities.

Artefacts an auditor will ask for
  • EMM enrollment statistics
  • Approved configuration profiles
  • Selective wipe procedure
  • EMM administrator access review
Where this commonly fails
  • Enrollment voluntary rather than enforced
  • Stale profiles applied to current devices
  • Wipe capability never tested
800-124r2-3.2
Device Authentication and Enrollment

Validate device identity and posture during enrollment and at access time before granting access to enterprise resources.

Artefacts an auditor will ask for
  • Enrollment workflow documentation
  • Device attestation evidence
  • Conditional access policies
  • Sample of denied access events
Where this commonly fails
  • Enrollment based solely on user credentials
  • No revalidation after major operating system changes
  • Conditional access lacks posture signals
800-124r2-3.3
Device Hardening Baselines

Apply security configuration baselines to mobile devices that disable unneeded features and enforce protective defaults.

Artefacts an auditor will ask for
  • Platform specific hardening baselines
  • Configuration compliance report
  • Exception register with risk acceptance
  • Baseline review history
Where this commonly fails
  • Baselines maintained for only one platform
  • Compliance reporting not acted upon
  • Older operating system versions outside baseline scope
800-124r2-3.4
Mobile Application Vetting

Vet mobile applications prior to deployment using static and dynamic analysis aligned with enterprise risk tolerance.

Artefacts an auditor will ask for
  • Application vetting policy
  • Approved application catalog
  • Vetting reports per application
  • Periodic re-vetting evidence
Where this commonly fails
  • Reliance on public store ratings only
  • No re-vetting after major updates
  • Internal applications skip the process
800-124r2-3.5
Mobile Application Allow and Deny Lists

Maintain enterprise allow and deny lists for mobile applications, enforced through EMM controls and reviewed on a regular cadence.

Artefacts an auditor will ask for
  • Current allow and deny list
  • Enforcement configuration evidence
  • Quarterly review records
  • Exception approval log
Where this commonly fails
  • Allow list grown to the point of meaninglessness
  • Deny list not synchronized across managed devices
  • No process to revoke previously allowed applications
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices framework page.