Endpoint governance

Policies

Nine baseline controls evaluated across every company-owned endpoint.

Review endpoint inventory
97%checks passing

183 of 189 control checks currently pass across 21 endpoints.

9Baseline controlsEvaluate-only prototype
4Healthy policiesNo endpoint exceptions
2Policies to monitorWarnings detected
3Action requiredFailures detected

9 controls · 21 endpoints in scope

Company endpoint baseline

Developers · Support Staff · Executives

Data protection

Disk Encryption

Monitor

Require full-disk encryption on every managed endpoint.

Requirement
Encryption enabled
Mode
Evaluate only
Scope
All company-owned endpoints
Endpoint coverage95%
20 of 21 endpoints passing
20 passing1 warning0 failed

Network protection

Firewall

Healthy

Require the host firewall and the corporate baseline profile.

Requirement
Firewall enabled
Mode
Evaluate only
Scope
All company-owned endpoints
Endpoint coverage100%
21 of 21 endpoints passing
21 passing0 warning0 failed

Data loss prevention

USB Storage Blocked

Monitor

Prevent removable USB storage from mounting on company devices.

Requirement
Removable storage blocked
Mode
Evaluate only
Scope
All company-owned endpoints
Endpoint coverage95%
20 of 21 endpoints passing
20 passing1 warning0 failed

Secure access

Cloudflare Connected

Healthy

Require an active connection to the Benchmark Cloudflare organization.

Requirement
Cloudflare connected
Mode
Evaluate only
Scope
All company-owned endpoints
Endpoint coverage100%
21 of 21 endpoints passing
21 passing0 warning0 failed

Web protection

Web Filtering Active

Action required

Keep corporate web filtering active for managed traffic.

Requirement
Web filtering active
Mode
Evaluate only
Scope
All company-owned endpoints
Endpoint coverage95%
20 of 21 endpoints passing
20 passing0 warning1 failed

Browser management

Chrome Managed

Healthy

Require enterprise enrollment and managed browser policy.

Requirement
Chrome enterprise managed
Mode
Evaluate only
Scope
All company-owned endpoints
Endpoint coverage100%
21 of 21 endpoints passing
21 passing0 warning0 failed

Patch management

OS Current

Healthy

Keep each endpoint on a supported operating-system release.

Requirement
Supported OS release
Mode
Evaluate only
Scope
All company-owned endpoints
Endpoint coverage100%
21 of 21 endpoints passing
21 passing0 warning0 failed

Endpoint visibility

Agent Healthy

Action required

Require the Petroglyph agent to be active and checking in.

Requirement
Agent active and current
Mode
Evaluate only
Scope
All company-owned endpoints
Endpoint coverage90%
19 of 21 endpoints passing
19 passing1 warning1 failed

Access control

Admin Privileges Restricted

Action required

Keep daily-use accounts at standard-user privilege.

Requirement
Local admin restricted
Mode
Evaluate only
Scope
All company-owned endpoints
Endpoint coverage95%
20 of 21 endpoints passing
20 passing0 warning1 failed

Assignment

Organizational scope

The baseline currently applies uniformly to all three organizational units. Unit-specific policy variations can be layered on later.

Developers13 endpoints9 controls assigned
Support Staff7 endpoints9 controls assigned
Executives1 endpoint9 controls assigned