CONFIDENTIAL
Prepared by CyberSafe.Now
Tenant appendix for Northwind Creative Co. — the full matrix a customer can provide on request, including share of the prior year each control was in compliance.
This section lists the required and recommended controls on the current plan, grouped by category. Status, finding, and evidence are recorded as of generation.
| Control | Req'd | Status | Finding | 1-yr in compliance | Evidence |
|---|---|---|---|---|---|
| SPF, DKIM, and DMARC Configured | Yes | Done | Pass | 100% | — |
| Control | Req'd | Status | Finding | 1-yr in compliance | Evidence |
|---|---|---|---|---|---|
| Full-Disk Encryption on Endpoints | Yes | Done | Pass | 100% | — |
| Operating System (OS) Patch Posture Within Policy | Yes | Done | Pass | 100% | — |
| Screen Lock Policy on Endpoints | Yes | Done | Pass | 100% | — |
| All Endpoints Enrolled in Device Management | Yes | Done | Pass | 100% | — |
| No Risky Local Admin States on Endpoints | No | Done | Pass | 100% | — |
| Secure Wi-Fi on Endpoints | No | Done | Pass | 100% | — |
| No Risky Services Listening on Endpoints | No | Done | Pass | 100% | — |
| No Known-Vulnerable Software on Endpoints | No | Done | Pass | 100% | — |
| Control | Req'd | Status | Finding | 1-yr in compliance | Evidence |
|---|---|---|---|---|---|
| Data Backup Policy Documented | Yes | Done | Pass | 100% | — |
| Incident Response Playbook Documented | Yes | Done | Pass | 100% | — |
| Remote Work Security Acknowledged | Yes | Done | Pass | 100% | — |
| Dual Control for Payment Changes | Yes | Done | Pass | 100% | — |
| Acceptable Use Policy Documented | Yes | Done | Pass | 100% | — |
| Data Handling and Classification Policy Documented | Yes | Done | Pass | 100% | — |
| Password and Access Control Policy Documented | Yes | Done | Pass | 100% | — |
| Information Security Program Policy Documented | Yes | Done | Pass | 100% | — |
| Incident Response Policy Documented | Yes | Done | Pass | 100% | — |
| Remote Work Security Policy Documented | Yes | Done | Pass | 100% | — |
| Third-Party and Vendor Risk Policy Documented | Yes | Done | Pass | 100% | — |
| Backup and Business Continuity Policy Documented | Yes | Done | Pass | 100% | — |
| Security Awareness Training Policy Documented | Yes | Done | Pass | 100% | — |
| Renewal Evidence Pack Available | Yes | Done | Pass | 100% | — |
| Control | Req'd | Status | Finding | 1-yr in compliance | Evidence |
|---|---|---|---|---|---|
| Legacy File Transfer Protocol (FTP) Decommissioned or Replaced | No | Open | Unknown | 0% | — |
| Control | Req'd | Status | Finding | 1-yr in compliance | Evidence |
|---|---|---|---|---|---|
| Multi-Factor Authentication (MFA) Enforced for All Users | Yes | Done | Pass | 100% | Users without MFA: 0 |
| Super Admin Count Within Policy | Yes | Done | Pass | 100% | Super admin count: 2 |
| Audit Logging Enabled for Tenant | Yes | Done | Pass | 100% | Audit log accessible: true |
| Google Workspace Open Authorization (OAuth)/App Consent Review | Yes | Done | Pass | 100% | — |
| Drive External Sharing Posture | Yes | Open | Fail | 38% | Sharing capability: External allowed |
| Security Alert Routing Configured | Yes | Done | Pass | 100% | — |
| Shared Drives in Use for Team Data | Yes | Done | Pass | 100% | — |
| Legacy App Access Restricted (Open Authorization (OAuth) Enforced) | Yes | Done | Pass | 100% | — |
| No Shared User Logins Detected | Yes | Done | Pass | 100% | — |
| Dormant Accounts Reviewed or Disabled | Yes | Done | Pass | 100% | — |
| Joiner/Leaver Process Documented and Followed | Yes | Done | Pass | 100% | — |
| Advanced Spam and Phishing Protection Configured | Yes | Done | Pass | 100% | — |
| Control | Req'd | Status | Finding | 1-yr in compliance | Evidence |
|---|---|---|---|---|---|
| Endpoint Detection and Response (EDR) Integration Connected | No | Done | Pass | 100% | — |
| Control | Req'd | Status | Finding | 1-yr in compliance | Evidence |
|---|---|---|---|---|---|
| Transport Layer Security (TLS) Hygiene for Public Hostname | Yes | Done | Pass | 100% | — |
| No Exposed Admin Services on Public Hostname | Yes | Done | Pass | 100% | — |
| Web Application Firewall (WAF) or Content Delivery Network (CDN) in Front of Public Application | No | Done | Pass | 100% | — |
| Public Web Surface Documented | No | Done | Pass | 100% | — |
| Remote Desktop Protocol (RDP) Not Exposed on Internet or Endpoint Listeners | No | Done | Pass | 100% | — |
| HTTP Strict Transport Security (HSTS) Enabled on Public Hypertext Transfer Protocol Secure (HTTPS) Site | No | Done | Pass | 100% | — |
| No Known-Vulnerable Public Software Versions | No | Done | Pass | 100% | — |
This section reports completed, open, and failed counts for required controls and for recommended controls.
Required controls : 32 /33 completed, 1 open, 1 failed.
Recommended controls : 10 /11 completed, 1 open, 0 failed.