213 – Allow geographic location
Summary
The mobile device must allow remote geographic location in case of loss.
Description
Allowing geographic location on mobile devices gives the ability to determine the physical location (through geographical coordinates) of the device, without requiring physical access to it. This is a control implemented as an anti-theft and loss prevention measure.
Supported In
Advanced: True
References
- CIS-4_1. Establish and maintain a secure configuration process
- CERTJ-DRD15-J. Consider privacy concerns when using Geolocation API
- NYDFS-500_15. Encryption of nonpublic information
- MITRE-M1029. Remote data storage
- CMMC-AC_L2-3_1_12. Control remote access
- CMMC-AC_L2-3_1_18. Mobile device connection
- CMMC-MP_L2-3_8_7. Removable media
- HITRUST-08_g. Equipment siting and protection
- ISO27002-7_9. Security of assets off-premises
- NIST800171-1_18. Control connection of mobile devices
- SIG-M_1_25. End user device security
- ISO27001-7_9. Security of assets off-premises
Last updated
2024/01/18