Glossary

MDM (Mobile Device Management)

MDM — mobile device management, though laptops are the real subject — is the tooling that enforces security policy on endpoints: disk encryption, screen lock, OS patching, and remote wipe when a device walks away. For compliance purposes it’s less about management and more about proof: MDM is how you evidence that every device touching company data meets policy.

Why auditors sample it

Endpoints are where data physically leaves your cloud perimeter — a stolen unencrypted laptop is a reportable breach in HIPAA contexts and an ugly finding anywhere. Auditors ask for the coverage report: how many devices, what percentage encrypted, screen-lock enforced, OS versions current. “We told everyone to turn on FileVault” is a policy; the MDM export is a control.

The startup-sized version

Full-suite MDM (Jamf, Kandji, Intune and peers) for company-owned fleets; lighter agents for BYOD-heavy teams. The compliance floor is consistent: enrollment covering everyone with data access, encryption and lock enforced rather than requested, and offboarding that includes device reclamation or wipe — the endpoint half of the leaver process.

The common gap

Coverage drift: contractors, the founder’s personal laptop, the machine someone “just uses for email.” Auditors reconcile the MDM roster against HR the same way they reconcile accounts — the delta is the finding.

Related Terms

Audit Trail — An audit trail is the tamper-evident record of who did what, when, in your systems — the evidence layer every framework samples and every incident needs.

Access Review — An access review is the periodic check that everyone's system access matches their role — the most-sampled SOC 2 control and the most common exception.

Data Classification — Data classification assigns sensitivity levels to data so controls can scale with risk — three or four tiers, applied where data lives, not in a binder.