CyberSafe.Now

CONFIDENTIAL

Control status for Northwind Creative Co.

Prepared by CyberSafe.Now

Tenant appendix for Northwind Creative Co. — the full matrix a customer can provide on request, including share of the prior year each control was in compliance.

Generated

Control status

This section lists the required and recommended controls on the current plan, grouped by category. Status, finding, and evidence are recorded as of generation.

Email domain checks

Control Req'd Status Finding 1-yr in compliance Evidence
SPF, DKIM, and DMARC Configured Yes Done Pass 100% —

Endpoint

Control Req'd Status Finding 1-yr in compliance Evidence
Full-Disk Encryption on Endpoints Yes Done Pass 100% —
Operating System (OS) Patch Posture Within Policy Yes Done Pass 100% —
Screen Lock Policy on Endpoints Yes Done Pass 100% —
All Endpoints Enrolled in Device Management Yes Done Pass 100% —
No Risky Local Admin States on Endpoints No Done Pass 100% —
Secure Wi-Fi on Endpoints No Done Pass 100% —
No Risky Services Listening on Endpoints No Done Pass 100% —
No Known-Vulnerable Software on Endpoints No Done Pass 100% —

Evidence reporting

Control Req'd Status Finding 1-yr in compliance Evidence
Data Backup Policy Documented Yes Done Pass 100% —
Incident Response Playbook Documented Yes Done Pass 100% —
Remote Work Security Acknowledged Yes Done Pass 100% —
Dual Control for Payment Changes Yes Done Pass 100% —
Acceptable Use Policy Documented Yes Done Pass 100% —
Data Handling and Classification Policy Documented Yes Done Pass 100% —
Password and Access Control Policy Documented Yes Done Pass 100% —
Information Security Program Policy Documented Yes Done Pass 100% —
Incident Response Policy Documented Yes Done Pass 100% —
Remote Work Security Policy Documented Yes Done Pass 100% —
Third-Party and Vendor Risk Policy Documented Yes Done Pass 100% —
Backup and Business Continuity Policy Documented Yes Done Pass 100% —
Security Awareness Training Policy Documented Yes Done Pass 100% —
Renewal Evidence Pack Available Yes Done Pass 100% —

File transfer

Control Req'd Status Finding 1-yr in compliance Evidence
Legacy File Transfer Protocol (FTP) Decommissioned or Replaced No Open Unknown 0% —

Identity SaaS

Control Req'd Status Finding 1-yr in compliance Evidence
Multi-Factor Authentication (MFA) Enforced for All Users Yes Done Pass 100% Users without MFA: 0
Super Admin Count Within Policy Yes Done Pass 100% Super admin count: 2
Audit Logging Enabled for Tenant Yes Done Pass 100% Audit log accessible: true
Google Workspace Open Authorization (OAuth)/App Consent Review Yes Done Pass 100% —
Drive External Sharing Posture Yes Open Fail 38% Sharing capability: External allowed
Security Alert Routing Configured Yes Done Pass 100% —
Shared Drives in Use for Team Data Yes Done Pass 100% —
Legacy App Access Restricted (Open Authorization (OAuth) Enforced) Yes Done Pass 100% —
No Shared User Logins Detected Yes Done Pass 100% —
Dormant Accounts Reviewed or Disabled Yes Done Pass 100% —
Joiner/Leaver Process Documented and Followed Yes Done Pass 100% —
Advanced Spam and Phishing Protection Configured Yes Done Pass 100% —

Integration layer

Control Req'd Status Finding 1-yr in compliance Evidence
Endpoint Detection and Response (EDR) Integration Connected No Done Pass 100% —

Internet exposure

Control Req'd Status Finding 1-yr in compliance Evidence
Transport Layer Security (TLS) Hygiene for Public Hostname Yes Done Pass 100% —
No Exposed Admin Services on Public Hostname Yes Done Pass 100% —
Web Application Firewall (WAF) or Content Delivery Network (CDN) in Front of Public Application No Done Pass 100% —
Public Web Surface Documented No Done Pass 100% —
Remote Desktop Protocol (RDP) Not Exposed on Internet or Endpoint Listeners No Done Pass 100% —
HTTP Strict Transport Security (HSTS) Enabled on Public Hypertext Transfer Protocol Secure (HTTPS) Site No Done Pass 100% —
No Known-Vulnerable Public Software Versions No Done Pass 100% —

Control summary

This section reports completed, open, and failed counts for required controls and for recommended controls.

Required controls : 32 /33 completed, 1 open, 1 failed.

Recommended controls : 10 /11 completed, 1 open, 0 failed.