DEVICE-004: Device Encryption Requirements

Platform
Google Workspace
Category
Device & Endpoint Management
Severity
High
Zero Trust pillar
Devices (weight 3)
Golden fixtures
1
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Device encryption should be required on all mobile devices to protect data at rest from physical theft or loss

Recommended value

Encryption required on all managed devices

Remediation

Admin Console > Devices > Mobile & endpoints > Settings > Universal settings > Encryption > Require device encryption

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for DEVICE-004
ScenarioExpected verdict
always-warnWARN

Framework mappings

NIST SP 800-53
SC-28, MP-5
CIS Benchmark
6.4
MITRE ATT&CK
T1005