Gideon resource library

Endpoint Posture Policy Starter Pack

A starter set of posture decisions for encryption, operating-system health, endpoint protection, patching, and inventory.

Disk encryption

  • Require full-disk encryption (FileVault, BitLocker) on all managed devices before they reach a compliant state.
  • Escrow recovery keys centrally; block local-only key storage.
  • Set a grace period for newly enrolled devices (e.g., 24–72 hours) before encryption is enforced as a hard block.
  • Alert on encryption status drift—a device that reports compliant, then reports unencrypted, is a priority signal.

Operating-system health

  • Define a minimum supported OS version per platform, tied to vendor security-update lifecycles rather than a fixed release number.
  • Block devices running an OS version past its vendor end-of-support date.
  • Require disk-level integrity checks (Secure Boot, System Integrity Protection) to remain enabled.
  • Set a maximum allowed time since last successful check-in before a device is treated as stale.

Endpoint protection

  • Require an active, reporting EDR/AV agent as a condition of network or SSO access.
  • Block local disabling of protection agents; alert immediately if tamper protection is bypassed.
  • Define which detections trigger automated isolation versus analyst review.
  • Set a maximum time-to-acknowledge for high-severity endpoint alerts.

Patching

  • Set patch SLAs by severity: critical within days, high within a defined window, routine on a standard cadence.
  • Separate OS patching cadence from third-party application patching cadence.
  • Define a staged rollout (pilot ring, broad ring) to catch regressions before fleet-wide deployment.
  • Track patch compliance as a percentage of fleet within SLA, not just “patch available.”

Inventory and discovery

  • Reconcile MDM-managed inventory against network/IdP-visible devices on a regular cadence to surface unmanaged endpoints.
  • Require every device to be attributable to an owner and a device class (corporate, BYOD, contractor).
  • Flag devices with no MDM check-in beyond a defined threshold for automatic de-provisioning review.
  • Maintain a documented exception list—not a silent one—for any device excluded from a control.

How to use this resource

Use these considerations to align security, IT, and procurement stakeholders, document current-state gaps, and define measurable acceptance criteria before a rollout. Start by setting posture by device class and risk level, then layer in grace periods, notification flows, and automated remediation. Assign an owner and an expiry date to every exception before rollout begins—undocumented exceptions are the most common posture gap Gideon sees in fleet reviews.

Back to topic hub