FillTrust

How to answer

How are employee laptops secured?

The question moved on from antivirus. It is now about encryption, updates, and whether you can take a device away.

A model answerImplied, not stated

All employee laptops are enrolled in [your device management tool], with full-disk encryption, automatic screen lock, and operating system updates enforced. Devices are wiped or the account is removed on offboarding.

Square brackets are yours to fill in. FillTrust grades an answer like this implied, not stated when your documents support it.

Answered from
Your acceptable use or endpoint policy, and the section of your SOC 2 report covering workstations.
Evidence to attach
Sometimes a device inventory or a compliance summary from your device management tool, with names removed.
Where it is asked
CAIQ v4.0 · UEM-05SIG LiteISO 27001 Annex A · A.8.1

For a company whose product runs in the cloud, the laptop is often the weakest link in an otherwise reasonable posture: it holds credentials, sometimes exports of customer data, and it leaves the building every evening.

Four things make a complete answer, and they are the four a reviewer scores: full-disk encryption, automatic screen lock, enforced operating system updates, and the ability to revoke or wipe. Antivirus is worth a mention and is no longer the point. If you can say all four are enforced centrally rather than requested politely, that is the strongest version.

Enforced is the operative word. A policy stating that laptops must be encrypted is not the same as a management tool reporting that they are. Small teams frequently have the policy and not the tool, in which case the honest answer says the policy exists and compliance is checked at onboarding. That is materially weaker, and it is also true, and it will not fall apart when somebody asks how many devices are currently compliant.

Bring-your-own-device is the question underneath the question. If contractors or founders use personal machines to reach production, say so and say what compensates: access through a browser only, no local data, short-lived credentials, hardware-backed multi-factor authentication. A reviewer who is told about it and given the mitigation is in a very different position from one who finds out later.

Revocation ties back to offboarding. If the laptop cannot be wiped remotely, then removing the account and rotating credentials is what actually protects you, and saying which of the two you rely on is a better answer than implying both.

The cheapest improvement. Enrolling devices in the management tool your identity provider already includes usually takes an afternoon and converts this answer, and the two adjacent ones about mobile devices and removable media, from implied to confirmed. It is one of the few controls on any questionnaire where the work is smaller than the paperwork around it.

How this one goes wrong

Specific to this question, not general advice.

  • Answering for company-issued devices while contractors use their own. If a personal machine can reach production, it is in scope for the question.
  • Claiming antivirus as the whole answer. Reviewers moved on from this; what they ask about now is encryption, patching and whether the device can be revoked.
  • Assuming disk encryption is on because the operating system enables it by default. It is worth confirming rather than assuming, because the follow-up asks how you know.

There are another two hundred of these in the file.

FillTrust drafts every one from your own documents and shows the passage behind each answer, including the ones it refuses to answer.

Or write this answer down once and publish it on a Trust Center of your own, which costs nothing.