Network Trace
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

24) Can your organisation perform a remote wipe on all organisation-provisioned endpoint devices?

August 30, 2022
IT Operations
Laptop Drive Encryption
Small Framework

Answer yes if your organisation enforces hard drive encryption on all laptop devices. In the notes, please include details of the encryption algorithm(s) used and how this is enforced.

If an employee misplaces or has an organisation-provisioned endpoint device stolen, it is important that your business can remotely wipe confidential business data to prevent unauthorised access.

There are some limitations to remote wiping, so this control is most effective when combined with full-disk encryption, which is covered in a separate control.

How to implement the control

The best way to manage remote wipe capabilities on endpoint devices is through a comprehensive Mobile Device Management (MDM) or Unified Endpoint Management (UEM) solution, which can often facilitate many of the endpoint device controls covered in this framework. Before looking for a separate remote wipe solution, check whether any of your existing MDM or UEM solutions provide this functionality.

If an MDM or UEM solution is not in place, third-party software can sometimes provide remote wipe capabilities. If you choose this option, carefully assess the credibility and security of any third-party provider before deployment.

Your organisation must have a defined process for performing a remote wipe when an employee reports an endpoint device as lost or stolen, and ensure employees are aware of the process through regular information security awareness training.

If you would like to contribute to this article or provide feedback, please email knowledge@riskledger.com. Contributors will be recognised on our contributors page.

Pattern Trapezoid Mesh

Defend against supply chain attacks with Defend-As-One.

No organisation is an island.