MDM (Mobile Device Management)
MDM — mobile device management, though laptops are the real subject — is the tooling that enforces security policy on endpoints: disk encryption, screen lock, OS patching, and remote wipe when a device walks away. For compliance purposes it’s less about management and more about proof: MDM is how you evidence that every device touching company data meets policy.
Why auditors sample it
Endpoints are where data physically leaves your cloud perimeter — a stolen unencrypted laptop is a reportable breach in HIPAA contexts and an ugly finding anywhere. Auditors ask for the coverage report: how many devices, what percentage encrypted, screen-lock enforced, OS versions current. “We told everyone to turn on FileVault” is a policy; the MDM export is a control.
The startup-sized version
Full-suite MDM (Jamf, Kandji, Intune and peers) for company-owned fleets; lighter agents for BYOD-heavy teams. The compliance floor is consistent: enrollment covering everyone with data access, encryption and lock enforced rather than requested, and offboarding that includes device reclamation or wipe — the endpoint half of the leaver process.
The common gap
Coverage drift: contractors, the founder’s personal laptop, the machine someone “just uses for email.” Auditors reconcile the MDM roster against HR the same way they reconcile accounts — the delta is the finding.
Audit Trail — An audit trail is the tamper-evident record of who did what, when, in your systems — the evidence layer every framework samples and every incident needs.
Access Review — An access review is the periodic check that everyone's system access matches their role — the most-sampled SOC 2 control and the most common exception.
Data Classification — Data classification assigns sensitivity levels to data so controls can scale with risk — three or four tiers, applied where data lives, not in a binder.