NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices
Evidence request list. 34 controls, 34 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Data Protection
Protect enterprise data on mobile devices through device level encryption, application containerization, and data loss prevention controls.
- Encryption status reporting
- Container configuration
- DLP policy and incident records
- Backup destination controls
- Personal and enterprise data co-mingled
- DLP policies not enforced for messaging applications
- Backup to personal accounts permitted
Protect mobile data in transit through approved VPN, secure messaging, and TLS enforcement to enterprise resources.
- Per app VPN configuration
- Approved secure messaging applications
- TLS version enforcement evidence
- Traffic inspection records where applicable
- Split tunneling allowed for sensitive applications
- Public Wi-Fi use without VPN
- Legacy TLS still permitted
Define and operate procedures for reporting and responding to lost or stolen mobile devices including remote lock, locate, and wipe.
- Lost device reporting hotline or portal
- Wipe action audit log
- Service level metrics for response time
- User awareness materials
- No service level for response time
- Users unaware of reporting channel
- Wipe actions not logged or reviewed
Deployment Models
Apply specific controls and user agreements where personal devices access enterprise resources, including privacy considerations.
- BYOD policy and acknowledgement
- Privacy notice for managed personal devices
- Container or workspace configuration
- Offboarding workflow for BYOD
- Full device wipe risk on personal devices
- No privacy notice provided to users
- Offboarding misses cached enterprise data
Define configuration and user privacy posture for corporate owned, business only, and corporate owned personally enabled deployment models.
- Deployment model decision record
- Profiles per deployment model
- User notice of monitoring scope
- Asset register tagged by model
- Mixed models within a single profile group
- Monitoring scope not disclosed
- Inventory not tagged by ownership model
Governance
Establish enterprise policies covering acceptable use, ownership models, supported platforms, and security requirements for mobile devices accessing enterprise resources.
- Approved mobile device policy
- Acceptable use policy acknowledgements
- Ownership model decision record
- Policy exception register
- Policy silent on personal device use
- No acknowledgement collection for contractors
- Policy not updated when new operating systems are supported
Identity
Integrate mobile devices with enterprise identity platforms so that authentication, authorization, and conditional access apply consistently.
- Identity provider integration evidence
- Conditional access policies
- Strong authentication enforcement reporting
- Privileged access controls for mobile administrators
- Local accounts on devices that bypass identity provider
- MFA exceptions for mobile users
- Privileged actions performed from non-managed devices
Lifecycle
Manage mobile devices through their lifecycle from procurement and provisioning to maintenance and disposal.
- Procurement standard with security clauses
- Provisioning workflow
- Maintenance and repair process
- Disposal and sanitization records
- Procurement bypasses standard channels
- No standard handover when staff change roles
- Disposal handled outside of asset management
Decommission mobile devices through full data sanitization, account removal, and recycling or destruction aligned to media policy.
- Decommissioning checklist
- Wipe verification records
- Recycling vendor certification
- Asset register update evidence
- Wipe not verified before disposal
- Vendor certifications not collected
- Stale assets remain in inventory
Mobile Device Policies
Develop a mobile device security policy addressing authorized devices, operating systems, security requirements, acceptable use, and consequences for non-compliance.
- Mobile device security policy approved by leadership
- BYOD acceptable use agreement signed by users
- Mobile data protection policy with classification mapping
- Device lifecycle procedure from issuance to disposal
- Policy not refreshed for new device classes (wearables, eSIM)
- BYOD consent forms missing legal review
- Data protection policy silent on offline cached data
- Lifecycle records do not include sanitisation evidence
Establish Bring Your Own Device policies defining requirements for personal devices accessing enterprise resources, including containerization, minimum security configurations.
- Mobile device security policy approved by leadership
- BYOD acceptable use agreement signed by users
- Mobile data protection policy with classification mapping
- Device lifecycle procedure from issuance to disposal
- Policy not refreshed for new device classes (wearables, eSIM)
- BYOD consent forms missing legal review
- Data protection policy silent on offline cached data
- Lifecycle records do not include sanitisation evidence
Define data protection requirements for mobile devices including encryption, data loss prevention, and restrictions on sensitive data storage and transmission.
- Mobile device security policy approved by leadership
- BYOD acceptable use agreement signed by users
- Mobile data protection policy with classification mapping
- Device lifecycle procedure from issuance to disposal
- Policy not refreshed for new device classes (wearables, eSIM)
- BYOD consent forms missing legal review
- Data protection policy silent on offline cached data
- Lifecycle records do not include sanitisation evidence
Establish procedures for the complete lifecycle of mobile devices including procurement, provisioning, operation, incident response, and secure disposal.
- Mobile device security policy approved by leadership
- BYOD acceptable use agreement signed by users
- Mobile data protection policy with classification mapping
- Device lifecycle procedure from issuance to disposal
- Policy not refreshed for new device classes (wearables, eSIM)
- BYOD consent forms missing legal review
- Data protection policy silent on offline cached data
- Lifecycle records do not include sanitisation evidence
Mobile Device Security Controls
Require strong device authentication (biometric + PIN/password). Configure automatic lock after inactivity period. Implement remote lock capabilities.
- Mobile device enrolment and policy configuration evidence
- Encryption attestation for managed mobile devices
- Remote wipe procedure with execution logs
- Patch and update compliance reports from MDM
- BYOD devices not subject to encryption attestation
- Remote wipe limited to corporate workspace containers only
- Patch compliance reporting lacks executive thresholds
- Jailbreak detection alerts not integrated with SOC
Enable full-device encryption on all managed mobile devices. Ensure encryption keys are properly managed and protected.
- Mobile device enrolment and policy configuration evidence
- Encryption attestation for managed mobile devices
- Remote wipe procedure with execution logs
- Patch and update compliance reports from MDM
- BYOD devices not subject to encryption attestation
- Remote wipe limited to corporate workspace containers only
- Patch compliance reporting lacks executive thresholds
- Jailbreak detection alerts not integrated with SOC
Enable remote wipe for managed devices. Configure selective wipe for BYOD to remove only enterprise data. Test wipe capabilities regularly.
- Mobile device enrolment and policy configuration evidence
- Encryption attestation for managed mobile devices
- Remote wipe procedure with execution logs
- Patch and update compliance reports from MDM
- BYOD devices not subject to encryption attestation
- Remote wipe limited to corporate workspace containers only
- Patch compliance reporting lacks executive thresholds
- Jailbreak detection alerts not integrated with SOC
Enforce timely OS and application updates. Define maximum allowable delay for security patches. Consider automatic update enforcement.
- Mobile device enrolment and policy configuration evidence
- Encryption attestation for managed mobile devices
- Remote wipe procedure with execution logs
- Patch and update compliance reports from MDM
- BYOD devices not subject to encryption attestation
- Remote wipe limited to corporate workspace containers only
- Patch compliance reporting lacks executive thresholds
- Jailbreak detection alerts not integrated with SOC
Detect and respond to jailbroken or rooted devices. Block compromised devices from accessing enterprise resources. Alert security teams.
- Mobile device enrolment and policy configuration evidence
- Encryption attestation for managed mobile devices
- Remote wipe procedure with execution logs
- Patch and update compliance reports from MDM
- BYOD devices not subject to encryption attestation
- Remote wipe limited to corporate workspace containers only
- Patch compliance reporting lacks executive thresholds
- Jailbreak detection alerts not integrated with SOC
Configure secure Wi-Fi settings (WPA3/WPA2-Enterprise). Disable auto-connect to unknown networks. Implement cellular network security controls.
- Mobile device enrolment and policy configuration evidence
- Encryption attestation for managed mobile devices
- Remote wipe procedure with execution logs
- Patch and update compliance reports from MDM
- BYOD devices not subject to encryption attestation
- Remote wipe limited to corporate workspace containers only
- Patch compliance reporting lacks executive thresholds
- Jailbreak detection alerts not integrated with SOC
Mobile Device Security Technologies
Deploy EMM/MDM solutions to manage mobile device configuration, enforce security policies, distribute applications, and remotely manage devices.
- Enterprise mobility management configuration baseline
- Mobile threat defence telemetry and alerting evidence
- Mobile application vetting reports for approved apps
- Secure communications and VPN deployment configuration
- MTD deployed without integration into incident workflows
- Application vetting limited to enterprise app store
- VPN split tunnelling permits direct internet egress
- MAM policies not enforced on personal cloud sync apps
Deploy MTD solutions to detect and mitigate device-level, network-level, and application-level threats on mobile devices.
- Enterprise mobility management configuration baseline
- Mobile threat defence telemetry and alerting evidence
- Mobile application vetting reports for approved apps
- Secure communications and VPN deployment configuration
- MTD deployed without integration into incident workflows
- Application vetting limited to enterprise app store
- VPN split tunnelling permits direct internet egress
- MAM policies not enforced on personal cloud sync apps
Establish a mobile application vetting process to evaluate app security before deployment. Assess apps for malware, privacy violations, and vulnerabilities.
- Enterprise mobility management configuration baseline
- Mobile threat defence telemetry and alerting evidence
- Mobile application vetting reports for approved apps
- Secure communications and VPN deployment configuration
- MTD deployed without integration into incident workflows
- Application vetting limited to enterprise app store
- VPN split tunnelling permits direct internet egress
- MAM policies not enforced on personal cloud sync apps
Manage applications on mobile devices including deployment, updates, configuration, and removal. Separate personal and enterprise applications.
- Enterprise mobility management configuration baseline
- Mobile threat defence telemetry and alerting evidence
- Mobile application vetting reports for approved apps
- Secure communications and VPN deployment configuration
- MTD deployed without integration into incident workflows
- Application vetting limited to enterprise app store
- VPN split tunnelling permits direct internet egress
- MAM policies not enforced on personal cloud sync apps
Configure VPN or per-app VPN for mobile devices accessing enterprise resources. Ensure all enterprise traffic is encrypted.
- Enterprise mobility management configuration baseline
- Mobile threat defence telemetry and alerting evidence
- Mobile application vetting reports for approved apps
- Secure communications and VPN deployment configuration
- MTD deployed without integration into incident workflows
- Application vetting limited to enterprise app store
- VPN split tunnelling permits direct internet egress
- MAM policies not enforced on personal cloud sync apps
Monitoring and Response
Continuously monitor mobile devices for indicators of compromise including malware, jailbreak, root, and abnormal behavior.
- MTD coverage report
- Detection rule set documentation
- Alert triage records
- Integration with SOC workflows
- MTD installed but not enforced
- Alerts routed only to end users
- Coverage gaps for tablet and shared device fleets
Ensure mobile operating systems and firmware receive timely security updates aligned to vendor release cycles and risk tolerance.
- Update compliance dashboard
- Forced update configuration evidence
- End of support roadmap per platform
- Exception register
- Devices stuck on outdated OS due to carrier delays
- End of support devices still active
- No deadlines on user managed updates
Train mobile device users on threats such as phishing, malicious applications, untrusted networks, and physical loss risks.
- Mobile awareness training content
- Completion records
- Phishing simulation results
- Awareness campaign materials
- Training generic to all device types
- No reinforcement after initial onboarding
- Simulations not measured for improvement
Produce continuous compliance reports for the mobile estate covering enrollment, posture, application inventory, and exceptions.
- Compliance dashboard
- Monthly metrics report
- Exception trend analysis
- Action items log from leadership reviews
- Reports issued but not acted upon
- Metrics not tied to risk decisions
- No leadership review cadence
Risk Management
Maintain a documented threat model for mobile devices that addresses device, network, application, and ecosystem level threats relevant to the enterprise.
- Mobile threat model document
- Annual review records
- Risk register entries tied to mobile
- Threat intelligence sources used
- Threat model not refreshed for new mobile operating system versions
- BYOD scenarios omitted
- No alignment with mobile threat defense tooling
Technical Controls
Deploy an enterprise mobility management platform that enforces device configuration, application management, and selective wipe capabilities.
- EMM enrollment statistics
- Approved configuration profiles
- Selective wipe procedure
- EMM administrator access review
- Enrollment voluntary rather than enforced
- Stale profiles applied to current devices
- Wipe capability never tested
Validate device identity and posture during enrollment and at access time before granting access to enterprise resources.
- Enrollment workflow documentation
- Device attestation evidence
- Conditional access policies
- Sample of denied access events
- Enrollment based solely on user credentials
- No revalidation after major operating system changes
- Conditional access lacks posture signals
Apply security configuration baselines to mobile devices that disable unneeded features and enforce protective defaults.
- Platform specific hardening baselines
- Configuration compliance report
- Exception register with risk acceptance
- Baseline review history
- Baselines maintained for only one platform
- Compliance reporting not acted upon
- Older operating system versions outside baseline scope
Vet mobile applications prior to deployment using static and dynamic analysis aligned with enterprise risk tolerance.
- Application vetting policy
- Approved application catalog
- Vetting reports per application
- Periodic re-vetting evidence
- Reliance on public store ratings only
- No re-vetting after major updates
- Internal applications skip the process
Maintain enterprise allow and deny lists for mobile applications, enforced through EMM controls and reviewed on a regular cadence.
- Current allow and deny list
- Enforcement configuration evidence
- Quarterly review records
- Exception approval log
- Allow list grown to the point of meaninglessness
- Deny list not synchronized across managed devices
- No process to revoke previously allowed applications
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NIST SP 800-124 Revision 2 - Guidelines for Managing the Security of Mobile Devices framework page.