CONFIDENTIAL
Prepared by CyberSafe.Now
Program evidence for Northwind Creative Co.
This section lists required controls whose finding is fail as of this snapshot. The list is empty when no required control is failing.
Failed required controls: 1
This section lists required controls whose finding is fail as of this snapshot. The list is empty when no required control is failing.
This section reports the results of the latest scan of the subscribed public hostname, including open ports and findings.
Target: northwind.example — Pass ·
Open ports: 80, 443
Port 443: Pass · TLS 1.3 · expires in 64 days
This section reports the latest connector findings for identity and SaaS controls on the subscribed platform.
Platform: Google Workspace · last sync
| Control | Finding | Evidence |
|---|---|---|
| Multi-Factor Authentication (MFA) Enforced for All Users | Pass | Users without MFA: 0 |
| Super Admin Count Within Policy | Pass | Super admin count: 2 |
| Drive External Sharing Posture | Fail | Sharing capability: External allowed |
This section records the declared backup method, compliance evidence archive status, and data-backup policy review state.
Compliance evidence archive: Enabled
Backup method (declared): Cloud vendor
Last evidence pack:
Data backup policy past due for review: No
Evidence pack contents: Tenant exports, report snapshots, and connector metadata
Active devices: 8 / 8
Last sync:
This section lists staff reviews and company policy uploads on file, with review-due dates where recorded.
| Policy | Uploaded by | Date | File |
|---|---|---|---|
| Data backup policy | Dana Ortiz | data-backup-policy.docx | |
| Incident response policy | Dana Ortiz | ir-policy.pdf |
Assure Plan expects 11 company policies. 2 are on file.
| Policy | Required | Provided to CyberSafe.Now | On file |
|---|---|---|---|
| Dual control for payment changes | Yes | No | — |
| Acceptable use policy documented | Yes | No | — |
| Data handling and classification policy documented | Yes | No | — |
| Password and access control policy documented | Yes | No | — |
| Information security program policy documented | Yes | No | — |
| Incident response policy documented | Yes | Yes | ir-policy.pdf |
| Remote work security policy documented | Yes | No | — |
| Third-party and vendor risk policy documented | Yes | No | — |
| Data backup policy documented | Yes | Yes | data-backup-policy.docx |
| Backup and business continuity policy documented | Yes | No | — |
| Security awareness training policy documented | Yes | No | — |
This section lists company policies on the current plan that have no adopted upload. Required policies in this list have no file on record.
| Policy | Control | Required |
|---|---|---|
| Dual control for payment changes | Dual Control for Payment Changes | Yes |
| Acceptable use policy documented | Acceptable Use Policy Documented | Yes |
| Data handling and classification policy documented | Data Handling and Classification Policy Documented | Yes |
| Password and access control policy documented | Password and Access Control Policy Documented | Yes |
| Information security program policy documented | Information Security Program Policy Documented | Yes |
| Remote work security policy documented | Remote Work Security Policy Documented | Yes |
| Third-party and vendor risk policy documented | Third-Party and Vendor Risk Policy Documented | Yes |
| Backup and business continuity policy documented | Backup and Business Continuity Policy Documented | Yes |
| Security awareness training policy documented | Security Awareness Training Policy Documented | Yes |
This section reproduces the extracted text of an adopted company policy. CyberSafe.Now retains this extract; original PDF or Word bytes are not stored.
Northwind Creative Co. data backup policy.
Production tenant exports are copied monthly to encrypted object storage.
Dana Ortiz reviews restore tests each quarter and records the result.
Backup media leaving the office require dual custody.
This section reproduces the extracted text of an adopted company policy. CyberSafe.Now retains this extract; original PDF or Word bytes are not stored.
Northwind Creative Co. incident response policy.
Staff report suspected incidents to Priya Shah within one hour.
Do not wipe devices before insurer approval.
The owner notifies CyberInsure Claims at 1-800-555-0142.