What's changed: Initial version
3.3Verifying policy and standards compliance
Covers the operations that keep endpoints "as agreed"—asset management (hardware/software inventory), program distribution, data backup, regulatory compliance (PCI DSS/HIPAA/GDPR), and BYOD for personal devices—as the foundation for judging "does this device meet the standard?"
Endpoint safety cannot be maintained just by installing good tools on each machine. It stands only on operational rules (policies)—and confirmation that they are actually followed: "know what devices and software the organization has," "distribute software by a set procedure," "back up so you can recover after a failure," and "comply with laws and industry standards." This section covers asset management (a ledger of hardware/software inventory) that first records what and how much exists, unified program distribution, backup for emergencies, the regulations to obey—PCI DSS (card data), HIPAA (health information), GDPR (EU personal data)—and the management challenges of BYOD, using personal devices for work, all through the lens of "does this device meet the standard?"
3.3.1Asset management, program distribution, and backup
- Asset management means grasping the organization's hardware and software as an inventory (ledger). Without knowing "what, where, and which version," you cannot find neglected vulnerable software or unauthorized software (shadow IT). An accurate inventory is a prerequisite for patching and updates.
- Program distribution is the mechanism to deliver software to each device by a unified procedure (a distribution server, MDM, etc.). Rather than individuals installing on their own, centrally distributing vetted software keeps versions uniform and helps prevent malware from slipping in.
- Backup copies data to another location to prepare for recovery from failure, accidental deletion, or ransomware. The 3-2-1 rule (three copies, two media types, one off-site) is a standard guideline. A backup is only meaningful once you confirm not just "is it being taken" but "can it be restored" (a restore test).
3.3.2Regulatory compliance and BYOD
- The key regulations depend on the data handled: PCI DSS is the standard for businesses handling credit-card data; HIPAA protects health information in the US; GDPR protects personal data in the EU (and can apply beyond its borders). The point is the mapping—"which data you handle" determines which regulation applies.
- BYOD (Bring Your Own Device) is the practice of using personal devices for work. It is convenient, but because business data lands on devices the company cannot fully control, risk must be curbed with device management (MDM), encryption, app distribution/restriction, and configuration management. Typical measures are remote wipe on loss and separating the work area from the personal area.
Most-tested: asset management = a hardware/software inventory (a prerequisite for patching/updates); a backup is meaningful only with 3-2-1 and a restore test; regulation is decided by the data handled—PCI DSS = card, HIPAA = health, GDPR = EU personal data; BYOD curbs personal-device risk with MDM, encryption, app distribution/restriction, and configuration management. Nail the mapping of "which standard for which data/device."
Suppose your employer is about to start accepting credit-card payments to sell products online. Thinking "our usual operations are fine" is dangerous. Because you now handle card data, compliance with the industry standard PCI DSS is required, and the starting point is asset management (inventory) that accurately grasps "what devices and software the company even has." Without a ledger, you cannot notice that old, vulnerable software still lingers somewhere. Next, install only vetted software onto the payment-related PCs by a unified procedure (program distribution), preventing arbitrary installs. And as a precaution, take a backup of important data including payment records—and test that it can actually be restored, because "we had it but it was corrupt and could not be restored" is meaningless. Further, if a salesperson wants to take orders on a personal phone, that is a BYOD management challenge. If business data or card-related information lands on a personal device, it cannot be permitted without measures like MDM management, device encryption, and remote wipe on loss. The key idea: choose the required standard and controls according to the data handled (card = PCI DSS, health = HIPAA, EU personal data = GDPR) and how devices are held (company-issued or BYOD). At the introductory level you need not memorize each regulation's fine clauses; correctly holding the mapping of "which standard and which controls for which data/device" is the first step toward compliance.
| Regulation | Mainly protects | Typical scope |
|---|---|---|
| PCI DSS | Credit-card data | Businesses handling card payments |
| HIPAA | Medical/health information | US healthcare-related organizations |
| GDPR | Personal data of EU residents | Organizations handling EU personal data (incl. abroad) |
| BYOD (an operational challenge) | Business data on personal devices | Handled with MDM, encryption, app restriction, config management |
Trap: "A backup taken on schedule needs no check that it can be restored" is wrong—a backup is meaningful only once it can actually be restored, so periodic restore tests are essential. Also wrong: "GDPR only concerns organizations inside the EU and has nothing to do with a Japanese company"—GDPR can apply to organizations outside the EU if they handle EU residents' personal data, so judge by the data handled.
3.3.3Section summary
- Asset management (hardware/software inventory) is a prerequisite for patching/updates; a backup is meaningful only with 3-2-1 and a restore test
- Regulation is decided by the data handled: PCI DSS = card, HIPAA = health, GDPR = EU personal data (can reach beyond its borders)
- BYOD puts business data on personal devices, so curb the risk with MDM, encryption, app distribution/restriction, and configuration management
Sign in to track progress — Log in.
Quick check
(just a quick review)Q1. A company is newly starting online credit-card payments. Which standard is most appropriate to comply with in order to handle card data?
Q2. For a server's important data, the backup job succeeds on schedule every night. Which viewpoint on backup operations is most appropriate?
Q3. A salesperson requests to handle business orders on a personal smartphone. Which control is most appropriate when permitting BYOD?

