This is a pretty great article. We do a lot of this as standard status quo at my company (https://verygoodsecurity.com) and we're about to deploy a full suite of google pixelbooks as well as primary computers instead of macs.
If there's more interest here, email me and I'll write up a lot of what we do -- but this post is a great start! We are planning on open-sourcing a lot of the tools that we built to achieve SOC2, PCI DSS, HIPAA, etc.