Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

N.4.01 Security and management of user devices

Control Overview

This control mandates that all corporate endpoints—including PCs, laptops, mobile phones, and tablets used by internal employees or external contractors—are structurally hardened and secured against unauthorized access, unauthorized software installations, and tampering with security configurations. To safeguard the corporate network from endpoint-driven threats, the organization must maintain a real-time, accurate asset inventory, enforce cryptographic data protection, strip unneeded local administrative privileges, and ensure prompt patch and vulnerability management.

note

Applicability Note: This control is highly critical and fully applicable to the anDREa platform, acting as the frontline technical barrier for our fully remote workforce.

Compliance & Strategic Approach

Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, linking device-level configuration controls directly to our network access boundaries.

Currently, anDREa enforces baseline endpoint security across all devices bound to the @andrea-cloud.com identity domain. Our framework mandates full-disk encryption (such as BitLocker for Windows or FileVault for macOS), restricted local administrator rights, mandatory anti-malware (e.g., Windows Defender), and automated OS patching. To guarantee data containment, all endpoints interacting with the environment are configured to be remotely wipeable. However, as noted in our self-assessment, our historical reliance on individual user compliance for configuration verification represents an active maturity transition point. We are shifting toward a centrally managed, policy-enforced deployment model to eliminate manual verification variance.


Control Mappings & Evidence

Framework / Document ReferenceElement & IdentifierDescription / Relationship to NIS 2
ISO/IEC 27001A.08.01 - User end point devicesMandates that protection measures are implemented for information accessed, processed, or stored on user endpoint devices.
ISO/IEC 27001A.06.07 - Remote workingGoverns operational and device security settings applied when endpoints operate on untrusted external networks.
Core Endpoint PolicyRemote Working & Device Security GuidelinesThe authoritative text outlining mandatory password lengths, encryption settings, local admin restrictions, and patching baselines. A.06.07 - Remote working, Acceptable Use of Hardware & Internet Policy
Technical EnforcementCentral Workspace Wipe LedgerActive administrative logs in Google Workspace/Office 365 proving the capability to issue and verify remote data wipes for all active accounts.

Audit Summary

  • Compliance Status: Compliant (With Maturity Improvement Actions Underway)
  • Gaps & Improvement Points: The organization technically meets baseline security obligations (encryption is universal, admin rights are restricted, and endpoints are wipeable). However, to reach robust NIS 2 audit compliance at scale, the organization is advised to transition from user-level policy instructions to an explicit, centralized Mobile Device Management (MDM) regime (such as Microsoft Intune or Google Endpoint Management).
  • Next Actions: Formally document and roll out centralized MDM configuration baselines that programmatically enforce encryption, automate patch cycles, and log security compliance metrics centrally, rather than relying on manual user confirmation.