PR.IR-01.263
Does your organization perform endpoint health checks before allowing devices to access production resources?
Explanation
Endpoint health checks verify that devices meet minimum security requirements (such as up-to-date antivirus, patched operating systems, and enabled security controls) before they can connect to production environments. This helps prevent compromised or vulnerable devices from accessing sensitive resources and potentially spreading malware or enabling unauthorized access throughout your network. Evidence could include documentation of your Network Access Control (NAC) solution configuration, screenshots of health check policies, or endpoint compliance reports showing devices that passed or failed health checks before attempting to access production resources.
Implementation Example
Check the cyber health of endpoints before allowing them to access and use production resources
ID: PR.IR-01.263
Context
- Function
- PR: PROTECT
- Category
- PR.IR: Technology Infrastructure Resilience
- Sub-Category
- Networks and environments are protected from unauthorized logical access and usage

