Does your organization perform endpoint health checks before allowing devices to access production resources?
Explanation
Endpoint health checks verify that devices meet minimum security requirements (such as up-to-date antivirus, patched operating systems, and enabled security controls) before they can connect to production environments. This helps prevent compromised or vulnerable devices from accessing sensitive resources and potentially spreading malware or enabling unauthorized access throughout your network.
Evidence could include documentation of your Network Access Control (NAC) solution configuration, screenshots of health check policies, or endpoint compliance reports showing devices that passed or failed health checks before attempting to access production resources.
Implementation Example
Check the cyber health of endpoints before allowing them to access and use production resources
ID: PR.IR-01.263
Context
- Function
- PR: PROTECT
- Category
- PR.IR: Technology Infrastructure Resilience
- Sub-Category
- Networks and environments are protected from unauthorized logical access and usage
Related questions
- Has your organization implemented network segmentation that separates different trust boundaries and platform types, with controlled communications between segments?
- Has your organization implemented network segmentation to isolate internal networks from external networks, with controls that restrict inbound traffic to only necessary communications?
- Has your organization implemented a zero trust architecture that restricts network access to each resource based on the principle of least privilege?
- Has your organization implemented physical safeguards to protect equipment from environmental threats such as flooding, fire, wind, excessive heat, and humidity?
- Do you require service providers who operate systems on your behalf to implement protections against environmental threats and maintain adequate operating infrastructure?
- Has your organization implemented redundancy measures to eliminate single points of failure across all critical systems and infrastructure?

