N.4.01 Security and management of user devices
Control Overview
This control mandates that all corporate endpoints—including PCs, laptops, mobile phones, and tablets used by internal employees or external contractors—are structurally hardened and secured against unauthorized access, unauthorized software installations, and tampering with security configurations. To safeguard the corporate network from endpoint-driven threats, the organization must maintain a real-time, accurate asset inventory, enforce cryptographic data protection, strip unneeded local administrative privileges, and ensure prompt patch and vulnerability management.
Applicability Note: This control is highly critical and fully applicable to the anDREa platform, acting as the frontline technical barrier for our fully remote workforce.
Compliance & Strategic Approach
Our approach satisfying this NIS 2 requirement operates within our ISO/IEC 27001-based ISMS, linking device-level configuration controls directly to our network access boundaries.
Currently, anDREa enforces baseline endpoint security across all devices bound to the @andrea-cloud.com identity domain. Our framework mandates full-disk encryption (such as BitLocker for Windows or FileVault for macOS), restricted local administrator rights, mandatory anti-malware (e.g., Windows Defender), and automated OS patching. To guarantee data containment, all endpoints interacting with the environment are configured to be remotely wipeable. However, as noted in our self-assessment, our historical reliance on individual user compliance for configuration verification represents an active maturity transition point. We are shifting toward a centrally managed, policy-enforced deployment model to eliminate manual verification variance.
Control Mappings & Evidence
| Framework / Document Reference | Element & Identifier | Description / Relationship to NIS 2 |
|---|---|---|
| ISO/IEC 27001 | A.08.01 - User end point devices | Mandates that protection measures are implemented for information accessed, processed, or stored on user endpoint devices. |
| ISO/IEC 27001 | A.06.07 - Remote working | Governs operational and device security settings applied when endpoints operate on untrusted external networks. |
| Core Endpoint Policy | Remote Working & Device Security Guidelines | The authoritative text outlining mandatory password lengths, encryption settings, local admin restrictions, and patching baselines. A.06.07 - Remote working, Acceptable Use of Hardware & Internet Policy |
| Technical Enforcement | Central Workspace Wipe Ledger | Active administrative logs in Google Workspace/Office 365 proving the capability to issue and verify remote data wipes for all active accounts. |
Audit Summary
- Compliance Status: Compliant (With Maturity Improvement Actions Underway)
- Gaps & Improvement Points: The organization technically meets baseline security obligations (encryption is universal, admin rights are restricted, and endpoints are wipeable). However, to reach robust NIS 2 audit compliance at scale, the organization is advised to transition from user-level policy instructions to an explicit, centralized Mobile Device Management (MDM) regime (such as Microsoft Intune or Google Endpoint Management).
- Next Actions: Formally document and roll out centralized MDM configuration baselines that programmatically enforce encryption, automate patch cycles, and log security compliance metrics centrally, rather than relying on manual user confirmation.