Skip to main content
Review and revision metadata
Review Date: 2026-07-05
Reviewer: Operations Manager

previous version on gdrive

A.7.13 Equipment Maintenance

Equipment Maintenance Framework

Proper maintenance of endpoint equipment is distributed between centralized configuration management and individual employee accountability. The specific maintenance baselines required to protect information availability, integrity, and confidentiality include:

  • Patch Management & Vulnerability Mitigation: Maintenance involves the mandatory installation of operating system patches, application updates, and driver refreshments. Critical security updates must be applied within 72 hours of release.
  • Security Software Optimization: Endpoint defense tools (such as Windows Defender, Microsoft Defender for Mac, Bitdefender, or ecosystem-native layers) must be actively maintained, continuously running, and updated with the latest threat definitions.
  • Storage Optimization & Encryption Health: Storage media must be checked to ensure that full-disk cryptographic mechanisms (BitLocker, FileVault, or ChromeOS native encryption) remain active and healthy. Overrides or disabling of these maintenance profiles is blocked via Google Endpoint Management.
  • Account and Profile Maintenance: For BYOD equipment, users are required to maintain a strict separation of corporate and personal data by utilizing a containerized anDREa Work Profile. This profile is subject to continuous integrity audits and remote administrative upkeep.

Administration & Cross-References

  • Operational Instructions: The explicit technical steps for enrolling, patching, securing, and lifecycle-reporting for all equipment are detailed comprehensively under A.06.07: Remote Working*.
  • Compliance Overviews: Periodic validation of device health and enrollment compliance is logged and tracked within the Inventory List.