1. Prerequisites
- Lost or stolen device incident
- Completion of Lost & Stolen Device Validation
- Access to MDM platform
- Access to EDR platform
- Access to asset inventory
- Access to Identity Provider (IdP)
- Access to device management records
- Device identifier available:
- Hostname
- Serial number
- Asset tag
- Mobile device identifier
- Incident ticket created
2. Step-by-Step Instructions
-
Identify Device Details
- Confirm:
- Device type
- Asset owner
- Operating system
- Device management status
- Document device information.
- Confirm:
-
Validate Device Enrollment Status
- Determine whether the device is enrolled in:
- MDM
- EDR
- Asset management systems
- Document management coverage.
- Determine whether the device is enrolled in:
-
Review Encryption Status
- Verify:
- Full disk encryption status
- Encryption technology in use
- Encryption key escrow status
- Document findings.
- Verify:
-
Review Endpoint Security Controls
- Determine whether the device has:
- EDR protection
- Antivirus protection
- Firewall enabled
- Device control policies
- Application control policies
- Document security controls present.
- Determine whether the device has:
-
Review Authentication Controls
- Determine:
- MFA requirements
- Device trust status
- Conditional access policies
- Privileged account usage
- Document authentication protections.
- Determine:
-
Review Remote Management Capabilities
- Verify availability of:
- Remote lock
- Remote wipe
- Device location tracking
- Remote access revocation
- Determine available containment options.
- Verify availability of:
-
Review Compliance Status
- Determine whether the device complies with:
- Security baselines
- Patch requirements
- Encryption requirements
- Device management requirements
- Document non-compliance findings.
- Determine whether the device complies with:
-
Assess Security Risk
- Evaluate:
- Likelihood of compromise
- Likelihood of data exposure
- Effectiveness of existing controls
- Ability to contain the device remotely
- Assign a risk rating.
- Evaluate:
-
Determine Recommended Actions
- Identify required actions including:
- Account containment
- Session revocation
- Remote lock
- Remote wipe
- Additional investigation
- Document recommendations.
- Identify required actions including:
-
Escalate and Hand Off
- Provide findings to the Incident Commander and Technical Lead.
- Escalate to:
- Device Data Exposure Assessment
- Remote Device Lock & Wipe
- Account containment activities
- Update the incident record with all findings.
3. Post-Action
- Ensure all device security controls are documented.
- Ensure encryption status is recorded.
- Document all identified security gaps.
- Attach assessment findings to the incident record.
- Preserve supporting evidence and screenshots where applicable.
- Ensure recommended containment actions are tracked to completion.
Contributor
Vishal Thakur GitHub: https://github.com/malienist
Contributed to the Arcana Incident Response Documentation Framework.
