Endpoint Protection
Endpoint protection refers to the practices and software used to defend end-user devices, such as laptops, desktops, servers, and mobile phones, against malicious or unwanted activity. It typically includes tools such as antivirus and antispyware that run on the device itself. It is a component of an organization's broader security posture rather than a compliance certification or legal requirement in its own right.
Endpoint protection is a category of security controls, generally delivered as software safeguards, that protect end-user machines and other devices capable of running a security client (for example workstations, laptops, servers, mobile devices, and in some formulations IoT systems) against attack. Historically associated with signature-based antivirus and antispyware, an Endpoint Protection Platform (EPP) commonly aggregates such controls at the device level. Endpoint protection is a security discipline concerned with device-level threat prevention and detection; it is distinct from privacy obligations and from network-perimeter controls, and it is not itself a regulation, standard, or certification, though it may be implemented to satisfy control requirements under frameworks or agreements. Scope, terminology, and the boundary between endpoint protection, endpoint detection and response, and broader endpoint security vary across vendors and sources; readers should verify definitions and any control mappings against the relevant authoritative framework or product documentation.
Why it matters
Endpoint devices—laptops, desktops, servers, and mobile phones—are among the most exposed elements of an organization's technology estate because they are operated directly by users, connect from varied networks, and often serve as the initial foothold for an attacker. Protecting these devices at the point where software executes complements network-perimeter controls and helps prevent, detect, and contain malicious or unwanted activity before it spreads. Because endpoints frequently store or process regulated data, weaknesses at the device level can carry consequences that extend well beyond information security into privacy and legal exposure.
It is important to be precise about what endpoint protection is and is not. It is a security discipline and a category of controls, not a regulation, standard, or certification. Deploying an Endpoint Protection Platform does not, by itself, make an organization "compliant" with any particular legal regime. That said, endpoint protection is often implemented to help satisfy specific control requirements under voluntary frameworks or contractual agreements, and organizations should map their endpoint controls against whichever authoritative framework or obligation applies to them rather than assuming universal coverage.
Readers should also note that terminology and scope in this area are unsettled. The boundary between endpoint protection, endpoint detection and response, and broader endpoint security varies across vendors and sources, and historical usage tied the term closely to signature-based antivirus and antispyware while contemporary products extend further. Where a control mapping or definition matters for an audit or assessment, verify it against the relevant authoritative framework or product documentation.
Who it's relevant to
Inside EPP
Common questions
Answers to the questions practitioners most commonly ask about EPP.

