Compliance
Questionnaire Toolkit

Check the full questionnaire with auto-suggested responses from current evidence, then save manual confirmations and notes.

Question Set

Danzel (3.3)

Scope

CurrentOnly

Scheme

Basic

Client

Ceres Support Group

Saved Run

New draft

Questions

79

Manual answer is available for every question. Answered: 0 / 79 (remaining: 79).

Reference Manual Answer / Notes Checked Status Suggestion Evidence Auto Suggestion
A1.1
Please provide your organisation legal name and registered details.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A1.2
Please provide the primary business address for this assessment.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A1.3
Please confirm whether your organisation has cyber insurance and provide provider/policy details if applicable.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A1.4
Please identify the principal business activities and services covered by this assessment.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A1.5
Please provide the main security/compliance contact responsible for this submission.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A2.1
Please confirm whether all in-scope user devices are captured in your device inventory.
Present in: Danzel 3.3
Unknown
Manual response required. Inventory and scoping evidence can be corroborated from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Expected supporting records may come from M365, NinjaOne, HaloPSA.
Provide a complete inventory/scoping answer and validate against M365, NinjaOne, HaloPSA.
A2.2
Please confirm whether any home-working devices are included in the scope of this assessment.
Present in: Danzel 3.3
Unknown
Manual response required. Inventory and scoping evidence can be corroborated from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Expected supporting records may come from M365, NinjaOne, HaloPSA.
Provide a complete inventory/scoping answer and validate against M365, NinjaOne, HaloPSA.
A2.3
Please confirm whether any personally owned (BYOD) devices are included in scope.
Present in: Danzel 3.3
Unknown
Manual response required. Inventory and scoping evidence can be corroborated from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Expected supporting records may come from M365, NinjaOne, HaloPSA.
Provide a complete inventory/scoping answer and validate against M365, NinjaOne, HaloPSA.
A2.4
Please list the cloud services that are in scope for this assessment.
Present in: Danzel 3.3
Unknown
Manual response required. Inventory and scoping evidence can be corroborated from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Expected supporting records may come from M365, NinjaOne, HaloPSA.
Provide a complete inventory/scoping answer and validate against M365, NinjaOne, HaloPSA.
A2.5
Please list any internet-facing services, gateways, or externally accessible systems in scope.
Present in: Danzel 3.3
Unknown
Manual response required. Inventory and scoping evidence can be corroborated from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Expected supporting records may come from M365, NinjaOne, HaloPSA.
Provide a complete inventory/scoping answer and validate against M365, NinjaOne, HaloPSA.
A2.6
Please list the quantities and operating systems for your laptops, desktops and virtual desktops within the scope of this assessment.
Present in: Danzel 3.3
NonCompliant
Out-of-support operating systems detected via endoflife.date for A2.6: 22 Lenovo ThinkCentre M80s Gen 3 desktops running Windows 11 Professional 23H2 (cycle 11-23h2-w is out of support; supported version should be 10.0.22631 on a supported cycle).
22 Lenovo ThinkCentre M80s Gen 3 desktops running Windows 11 Professional 23H2; 24 Azure Virtual Desktop session host (Standard D8s v5) virtual desktops running Windows 11 Enterprise multi-session 23H2
Show evidence items (2)
Device Inventory: NonCompliant
Entity: Lenovo ThinkCentre M80s Gen 3
22 Lenovo ThinkCentre M80s Gen 3 Desktop running Windows 11 Professional 23H2
Observed: 08/06/2026 19:09
Device Inventory: NonCompliant
Entity: Azure Virtual Desktop session host (Standard D8s v5)
24 Azure Virtual Desktop session host (Standard D8s v5) VirtualDesktop running Windows 11 Enterprise multi-session 23H2
Observed: 08/06/2026 19:09
Likely No based on current evidence. Out-of-support operating systems detected via endoflife.date for A2.6: 22 Lenovo ThinkCentre M80s Gen 3 desktops running Windows 11 Professional 23H2 (cycle 11-23h2-w is out of support; supported version should be 10.0.22631 on a supported cycle).
A2.6.1
Please list the quantity of thin clients within the scope of this assessment. Please include make and operating systems.
Present in: Danzel 3.3
Compliant
No in-scope devices are recorded for this category.
No in-scope devices recorded for this category.
Likely Yes based on current evidence. No in-scope devices are recorded for this category.
A2.7
Please list the quantity of servers, virtual servers, virtual server hosts (hypervisors) and Virtual Desktop Infrastructure (VDI) servers. You must include the operating system.
Present in: Danzel 3.3
NonCompliant
Out-of-support operating systems detected via endoflife.date for A2.7: 2 Supermicro SuperServer SYS-2029U-E1CR4T Proxmox VE host devices running Proxmox VE 8.2 (latest available version in supported cycle 8.x is 8.4).
6 Azure VM (Standard D4s v5) servers running Ubuntu Server 24.04 LTS; 2 Supermicro SuperServer SYS-2029U-E1CR4T Proxmox VE host hypervisors running Proxmox VE 8.2
Show evidence items (2)
Device Inventory: NonCompliant
Entity: Azure VM (Standard D4s v5)
6 Azure VM (Standard D4s v5) Server running Ubuntu Server 24.04 LTS
Observed: 08/06/2026 19:09
Device Inventory: NonCompliant
Entity: Supermicro SuperServer SYS-2029U-E1CR4T Proxmox VE host
2 Supermicro SuperServer SYS-2029U-E1CR4T Proxmox VE host Hypervisor running Proxmox VE 8.2
Observed: 08/06/2026 19:09
Likely No based on current evidence. Out-of-support operating systems detected via endoflife.date for A2.7: 2 Supermicro SuperServer SYS-2029U-E1CR4T Proxmox VE host devices running Proxmox VE 8.2 (latest available version in supported cycle 8.x is 8.4).
A2.8
Please list the quantities of tablets and mobile devices within the scope of this assessment.
Present in: Danzel 3.3
NonCompliant
Out-of-support operating systems detected via endoflife.date for A2.8: 12 Apple iPhone SE (2nd generation) devices running iOS 17.5 (installed iOS cycle 17 is out of support; supported version should be 26.6).
12 Apple iPhone SE (2nd generation) mobile devices running iOS 17.5
Show evidence items (1)
Device Inventory: NonCompliant
Entity: Apple iPhone SE (2nd generation)
12 Apple iPhone SE (2nd generation) MobileDevice running iOS 17.5
Observed: 08/06/2026 19:09
Likely No based on current evidence. Out-of-support operating systems detected via endoflife.date for A2.8: 12 Apple iPhone SE (2nd generation) devices running iOS 17.5 (installed iOS cycle 17 is out of support; supported version should be 26.6).
A3.1
Please confirm the security update process for in-scope systems and who owns it.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A3.2
Please confirm the vulnerability management process for in-scope systems and services.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A3.3
Please confirm the incident response/escalation process for security events in scope.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A4.1
Do you have firewalls at the boundaries between your organisation's internal networks, laptops, desktops, servers, and the internet?
Present in: Danzel 3.3
NonCompliant
Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Partial
Entity: Device Group: Ceres Service Desks
Reason: Firewall is enabled fleet-wide, but profile lock policy is not yet enforced on 4 legacy terminals.
Demo (The Expanse): Legacy service-desk terminals still permit local profile edits pending migration completion.
Observed: 08/06/2026 18:52
Ref: demo://expanse/ninjaone/firewall-baseline-ceres
Likely No based on current evidence. Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A4.1.1
Do you have software firewalls enabled on all of your computers, laptops and servers?
Present in: Danzel 3.3
NonCompliant
Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Partial
Entity: Device Group: Ceres Service Desks
Reason: Firewall is enabled fleet-wide, but profile lock policy is not yet enforced on 4 legacy terminals.
Demo (The Expanse): Legacy service-desk terminals still permit local profile edits pending migration completion.
Observed: 08/06/2026 18:52
Ref: demo://expanse/ninjaone/firewall-baseline-ceres
Likely No based on current evidence. Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A4.1.2
If you answered no to question A4.1.1, is this because software firewalls are not installed by default as part of the operating system you are using?
Present in: Danzel 3.3
NonCompliant
Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Partial
Entity: Device Group: Ceres Service Desks
Reason: Firewall is enabled fleet-wide, but profile lock policy is not yet enforced on 4 legacy terminals.
Demo (The Expanse): Legacy service-desk terminals still permit local profile edits pending migration completion.
Observed: 08/06/2026 18:52
Ref: demo://expanse/ninjaone/firewall-baseline-ceres
Likely No based on current evidence. Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A4.2
When you first receive an internet router or hardware firewall device, it may have had a default password on it. Have you changed all the default passwords on your boundary firewall devices?
Present in: Danzel 3.3
NonCompliant
Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Partial
Entity: Device Group: Ceres Service Desks
Reason: Firewall is enabled fleet-wide, but profile lock policy is not yet enforced on 4 legacy terminals.
Demo (The Expanse): Legacy service-desk terminals still permit local profile edits pending migration completion.
Observed: 08/06/2026 18:52
Ref: demo://expanse/ninjaone/firewall-baseline-ceres
Likely No based on current evidence. Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A4.2.1
Please describe the process for changing your firewall password.
Present in: Danzel 3.3
NonCompliant
Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Partial
Entity: Device Group: Ceres Service Desks
Reason: Firewall is enabled fleet-wide, but profile lock policy is not yet enforced on 4 legacy terminals.
Demo (The Expanse): Legacy service-desk terminals still permit local profile edits pending migration completion.
Observed: 08/06/2026 18:52
Ref: demo://expanse/ninjaone/firewall-baseline-ceres
Likely No based on current evidence. Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A4.3
How is your firewall password configured?
Present in: Danzel 3.3
NonCompliant
Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Partial
Entity: Device Group: Ceres Service Desks
Reason: Firewall is enabled fleet-wide, but profile lock policy is not yet enforced on 4 legacy terminals.
Demo (The Expanse): Legacy service-desk terminals still permit local profile edits pending migration completion.
Observed: 08/06/2026 18:52
Ref: demo://expanse/ninjaone/firewall-baseline-ceres
Likely No based on current evidence. Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A4.4
Do you change your firewall password when you know or suspect it has been compromised?
Present in: Danzel 3.3
NonCompliant
Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Partial
Entity: Device Group: Ceres Service Desks
Reason: Firewall is enabled fleet-wide, but profile lock policy is not yet enforced on 4 legacy terminals.
Demo (The Expanse): Legacy service-desk terminals still permit local profile edits pending migration completion.
Observed: 08/06/2026 18:52
Ref: demo://expanse/ninjaone/firewall-baseline-ceres
Likely No based on current evidence. Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A4.5
Do you have a process to manage your firewall?
Present in: Danzel 3.3
NonCompliant
Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Partial
Entity: Device Group: Ceres Service Desks
Reason: Firewall is enabled fleet-wide, but profile lock policy is not yet enforced on 4 legacy terminals.
Demo (The Expanse): Legacy service-desk terminals still permit local profile edits pending migration completion.
Observed: 08/06/2026 18:52
Ref: demo://expanse/ninjaone/firewall-baseline-ceres
Likely No based on current evidence. Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A4.6
Have you reviewed your firewall rules in the last 12 months?
Present in: Danzel 3.3
NonCompliant
Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Partial
Entity: Device Group: Ceres Service Desks
Reason: Firewall is enabled fleet-wide, but profile lock policy is not yet enforced on 4 legacy terminals.
Demo (The Expanse): Legacy service-desk terminals still permit local profile edits pending migration completion.
Observed: 08/06/2026 18:52
Ref: demo://expanse/ninjaone/firewall-baseline-ceres
Likely No based on current evidence. Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A4.7
Are host firewalls enabled and configured to block unauthorized inbound network connections on supported endpoints?
Present in: Danzel 3.3
NonCompliant
Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Partial
Entity: Device Group: Ceres Service Desks
Reason: Firewall is enabled fleet-wide, but profile lock policy is not yet enforced on 4 legacy terminals.
Demo (The Expanse): Legacy service-desk terminals still permit local profile edits pending migration completion.
Observed: 08/06/2026 18:52
Ref: demo://expanse/ninjaone/firewall-baseline-ceres
Likely No based on current evidence. Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A4.8
Please describe how you approve and document your allowed inbound connections.
Present in: Danzel 3.3
NonCompliant
Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Partial
Entity: Device Group: Ceres Service Desks
Reason: Firewall is enabled fleet-wide, but profile lock policy is not yet enforced on 4 legacy terminals.
Demo (The Expanse): Legacy service-desk terminals still permit local profile edits pending migration completion.
Observed: 08/06/2026 18:52
Ref: demo://expanse/ninjaone/firewall-baseline-ceres
Likely No based on current evidence. Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A4.9
Are your boundary firewalls configured to allow access to their configuration settings over the internet?
Present in: Danzel 3.3
NonCompliant
Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Partial
Entity: Device Group: Ceres Service Desks
Reason: Firewall is enabled fleet-wide, but profile lock policy is not yet enforced on 4 legacy terminals.
Demo (The Expanse): Legacy service-desk terminals still permit local profile edits pending migration completion.
Observed: 08/06/2026 18:52
Ref: demo://expanse/ninjaone/firewall-baseline-ceres
Likely No based on current evidence. Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A4.10
If you answered yes in question A4.9, is there a documented business requirement for this access?
Present in: Danzel 3.3
NonCompliant
Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Partial
Entity: Device Group: Ceres Service Desks
Reason: Firewall is enabled fleet-wide, but profile lock policy is not yet enforced on 4 legacy terminals.
Demo (The Expanse): Legacy service-desk terminals still permit local profile edits pending migration completion.
Observed: 08/06/2026 18:52
Ref: demo://expanse/ninjaone/firewall-baseline-ceres
Likely No based on current evidence. Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A4.11
If you answered yes in question A4.9, is the access to your firewall settings protected by either multi-factor authentication or by only allowing trusted IP addresses combined with managed authentication to access the settings?
Present in: Danzel 3.3
NonCompliant
Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Partial
Entity: Device Group: Ceres Service Desks
Reason: Firewall is enabled fleet-wide, but profile lock policy is not yet enforced on 4 legacy terminals.
Demo (The Expanse): Legacy service-desk terminals still permit local profile edits pending migration completion.
Observed: 08/06/2026 18:52
Ref: demo://expanse/ninjaone/firewall-baseline-ceres
Likely No based on current evidence. Evidence from NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A5.1
Is unnecessary or unauthorized software identified and remediated in line with policy?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A5.2
Are systems and identities configured to an approved secure baseline with unnecessary features disabled?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A5.3
Have you changed the default password for all user and administrator accounts on all your desktop computers, laptops, thin clients, servers, tablets and mobile phones?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A5.4
Do you run or host external services that provide access to data (that should not be made public) to users across the internet?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A5.5
If yes to question A5.4, which authentication option do you use?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A5.6
Describe the process in place for changing passwords on your external services when you believe they have been compromised.
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A5.7
When not using multi-factor authentication, which option are you using to protect your external service from brute force attacks?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A5.8
Have you disabled any feature which allows automatic file execution of downloaded or imported files without user authorisation?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A5.9
When a device requires a user to be present, do you set a locking mechanism on your devices to access the software and services installed?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A5.10
Which method do you use to unlock the devices?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A6.1
Are all operating systems on your devices supported by a vendor that produces regular security updates and vulnerability fixes?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A6.2
Is all the software on your devices supported by a supplier that produces regular vulnerability fixes for any security problems?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A6.2.1
Please list your internet browser(s).
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A6.2.2
Please list your malware protection software.
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A6.2.3
Please list your email applications installed on end user devices and servers.
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A6.2.4
Please list all office applications that are used to create organisational data.
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A6.3
Are any of the in-scope software or cloud services unlicensed or unsupported?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A6.3.1/A6.6/A6.7
Is unsupported or end-of-life software identified and remediated with accountable ownership?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A6.4/A6.5
Are security updates applied within policy timelines for operating systems and applications?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A6.4.1
Are all updates applied for operating systems by enabling auto updates?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A6.4.2
Where auto updates are not being used, how do you ensure all high-risk or critical security updates and vulnerability fixes of all operating systems and firmware on firewalls and routers are applied within 14 days of release?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A6.5
Are all high-risk or critical security updates and vulnerability fixes for applications (including any associated files and extensions) installed within 14 days of release?
Present in: Danzel 3.3
Unknown
Manual response required. Corroborating records may be available from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Supporting records may be available from M365, NinjaOne, HaloPSA.
Provide a manual answer and attach notes. Corroborate with M365, NinjaOne, HaloPSA where possible.
A6.5.1
Are all updates applied on your applications by enabling auto updates?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A6.5.2
Where auto updates are not being used, how do you ensure all high-risk or critical security updates of all applications are applied within 14 days of release?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A6.6
Have you removed any software installed on your devices that is no longer supported and no longer receives regular updates or vulnerability fixes for security problems?
Present in: Danzel 3.3
Unknown
Manual response required. Corroborating records may be available from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Supporting records may be available from M365, NinjaOne, HaloPSA.
Provide a manual answer and attach notes. Corroborate with M365, NinjaOne, HaloPSA where possible.
A6.7
Where you have a business need to use unsupported software, have you moved the devices and software out of scope of this assessment?
Present in: Danzel 3.3
Unknown
Manual response required. Corroborating records may be available from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Supporting records may be available from M365, NinjaOne, HaloPSA.
Provide a manual answer and attach notes. Corroborate with M365, NinjaOne, HaloPSA where possible.
A7.1
Are your users only provided with user accounts after a process has been followed to approve their creation? Describe the process.
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A7.2
Are all your user and administrative accounts accessed by entering unique credentials?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A7.3
How do you ensure you have deleted, or disabled, any accounts for staff who are no longer with your organisation?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A7.4
Do you ensure that staff only have the access privileges that they need to do their current job? How do you do this?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A7.5
Do you have a formal process for giving someone access to systems at an administrator level and can you describe this process?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A7.6
Are administrative accounts separate from standard user accounts and used only for administrative tasks?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A7.7
How does your organisation prevent administrator accounts from being used to carry out everyday tasks like browsing the web or accessing email?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A7.8
Do you formally track which users have administrator accounts in your organisation?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A7.9
Do you review who should have administrative access on a regular basis?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A7.10
Where you have systems that require passwords (or where passwords are a backup for a passwordless system), how are they protected from brute-force attacks?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A7.11
Which technical controls are used to manage the quality of your passwords within your organisation?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A7.12
Please explain how you encourage people to use unique and strong passwords.
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A7.13
Do you have a process for when you believe the passwords or accounts have been compromised?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A7.14
Is multi-factor authentication enforced for privileged users and cloud service access?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A7.15
If you have answered no to question A7.14, please provide a list of your cloud services that do not provide any option for MFA.
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A7.16
Has MFA been applied to all administrators of your cloud services, excluding any listed in A7.15 that do not provide it?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A7.17
Has MFA been applied to all users of your cloud services, excluding any listed in A7.15 that do not provide it?
Present in: Danzel 3.3
NonCompliant
Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
No direct evidence items are currently mapped to this question.
Likely No based on current evidence. Evidence from the connected data sources shows this control is not yet implemented; remediation has been logged as an open action with the client.
A8.1
Is anti-malware protection enabled on supported devices with current signatures and active monitoring?
Present in: Danzel 3.3
NonCompliant
Evidence from M365-Demo, NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
2 evidence item(s): M365-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: NonCompliant
Entity: Devices: Ceres Cargo Terminals (7)
Reason: Signatures are outside policy freshness threshold.
Demo (The Expanse): 7 cargo-manifest terminals on Ceres report stale malware signatures.
Observed: 08/06/2026 18:58
Ref: demo://expanse/ninjaone/av-signature-staleness
M365-Demo: Compliant
Entity: Tenant: Ceres Support
Reason: Endpoint anti-malware protection healthy with no stale signatures.
Demo (The Expanse): Ceres support desk uses dedicated break-glass admin identities.
Observed: 08/06/2026 18:04
Ref: demo://expanse/m365/ceres-breakglass
Likely No based on current evidence. Evidence from M365-Demo, NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A8.2/A8.3
Are malware detections investigated and resolved through a documented incident workflow?
Present in: Danzel 3.3
NonCompliant
Evidence from HaloPSA-Demo, NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
2 evidence item(s): HaloPSA-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Partial
Entity: Endpoint Detection Queue: Cargo Terminals
Reason: Two detections are triaged but awaiting final closure notes.
Demo (The Expanse): Endpoint malware detections have containment evidence, with 2 investigations still pending final closure sign-off.
Observed: 08/06/2026 18:47
Ref: demo://expanse/ninjaone/malware-investigation-workflow
HaloPSA-Demo: Partial
Entity: Incident Queue: Docking Kiosks
Reason: Three incidents remain open without closure evidence attachments.
Demo (The Expanse): 3 malware-response tickets on docking kiosks still awaiting closure evidence.
Observed: 08/06/2026 18:29
Ref: demo://expanse/halopsa/malware-response-queue
Likely No based on current evidence. Evidence from HaloPSA-Demo, NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A8.3
If Option A has been selected: where you have anti-malware software installed, is it set to scan web pages you visit and warn you about accessing malicious websites?
Present in: Danzel 3.3
Unknown
Manual response required. Corroborating records may be available from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Supporting records may be available from M365, NinjaOne, HaloPSA.
Provide a manual answer and attach notes. Corroborate with M365, NinjaOne, HaloPSA where possible.
A8.4
If Option B has been selected: where you use an app-store or application signing, are users restricted from installing unsigned applications?
Present in: Danzel 3.3
NonCompliant
Evidence from M365-Demo, NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
2 evidence item(s): M365-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: NonCompliant
Entity: Devices: Ceres Cargo Terminals (7)
Reason: Signatures are outside policy freshness threshold.
Demo (The Expanse): 7 cargo-manifest terminals on Ceres report stale malware signatures.
Observed: 08/06/2026 18:58
Ref: demo://expanse/ninjaone/av-signature-staleness
M365-Demo: Compliant
Entity: Tenant: Ceres Support
Reason: Endpoint anti-malware protection healthy with no stale signatures.
Demo (The Expanse): Ceres support desk uses dedicated break-glass admin identities.
Observed: 08/06/2026 18:04
Ref: demo://expanse/m365/ceres-breakglass
Likely No based on current evidence. Evidence from M365-Demo, NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
A8.5
If Option B has been selected: where you use an app-store or application signing, do you ensure users only install applications approved by your organisation and maintain that approved list?
Present in: Danzel 3.3
NonCompliant
Evidence from M365-Demo, NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
2 evidence item(s): M365-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: NonCompliant
Entity: Devices: Ceres Cargo Terminals (7)
Reason: Signatures are outside policy freshness threshold.
Demo (The Expanse): 7 cargo-manifest terminals on Ceres report stale malware signatures.
Observed: 08/06/2026 18:58
Ref: demo://expanse/ninjaone/av-signature-staleness
M365-Demo: Compliant
Entity: Tenant: Ceres Support
Reason: Endpoint anti-malware protection healthy with no stale signatures.
Demo (The Expanse): Ceres support desk uses dedicated break-glass admin identities.
Observed: 08/06/2026 18:04
Ref: demo://expanse/m365/ceres-breakglass
Likely No based on current evidence. Evidence from M365-Demo, NinjaOne-Demo shows this control is not yet implemented; remediation has been logged as an open action with the client.
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.