Compliance
Questionnaire Toolkit

Check the full questionnaire with auto-suggested responses from current evidence, then save manual confirmations and notes.

Question Set

Danzel (3.3)

Scope

CurrentOnly

Scheme

Basic

Client

Rocinante Logistics

Saved Run

New draft

Questions

79

Manual answer is available for every question. Answered: 0 / 79 (remaining: 79).

Reference Manual Answer / Notes Checked Status Suggestion Evidence Auto Suggestion
A1.1
Please provide your organisation legal name and registered details.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A1.2
Please provide the primary business address for this assessment.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A1.3
Please confirm whether your organisation has cyber insurance and provide provider/policy details if applicable.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A1.4
Please identify the principal business activities and services covered by this assessment.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A1.5
Please provide the main security/compliance contact responsible for this submission.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A2.1
Please confirm whether all in-scope user devices are captured in your device inventory.
Present in: Danzel 3.3
Unknown
Manual response required. Inventory and scoping evidence can be corroborated from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Expected supporting records may come from M365, NinjaOne, HaloPSA.
Provide a complete inventory/scoping answer and validate against M365, NinjaOne, HaloPSA.
A2.2
Please confirm whether any home-working devices are included in the scope of this assessment.
Present in: Danzel 3.3
Unknown
Manual response required. Inventory and scoping evidence can be corroborated from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Expected supporting records may come from M365, NinjaOne, HaloPSA.
Provide a complete inventory/scoping answer and validate against M365, NinjaOne, HaloPSA.
A2.3
Please confirm whether any personally owned (BYOD) devices are included in scope.
Present in: Danzel 3.3
Unknown
Manual response required. Inventory and scoping evidence can be corroborated from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Expected supporting records may come from M365, NinjaOne, HaloPSA.
Provide a complete inventory/scoping answer and validate against M365, NinjaOne, HaloPSA.
A2.4
Please list the cloud services that are in scope for this assessment.
Present in: Danzel 3.3
Unknown
Manual response required. Inventory and scoping evidence can be corroborated from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Expected supporting records may come from M365, NinjaOne, HaloPSA.
Provide a complete inventory/scoping answer and validate against M365, NinjaOne, HaloPSA.
A2.5
Please list any internet-facing services, gateways, or externally accessible systems in scope.
Present in: Danzel 3.3
Unknown
Manual response required. Inventory and scoping evidence can be corroborated from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Expected supporting records may come from M365, NinjaOne, HaloPSA.
Provide a complete inventory/scoping answer and validate against M365, NinjaOne, HaloPSA.
A2.6
Please list the quantities and operating systems for your laptops, desktops and virtual desktops within the scope of this assessment.
Present in: Danzel 3.3
NonCompliant
Out-of-support operating systems detected via endoflife.date for A2.6: 16 Lenovo ThinkPad T14 Gen 4 laptops running Windows 11 Professional 23H2 (cycle 11-23h2-w is out of support; supported version should be 10.0.22631 on a supported cycle); 8 Lenovo ThinkCentre M70q Gen 3 desktops running Windows 10 Professional 22H2 (Windows 10 is out of support; supported version should be Windows 11 24H2 or later).
16 Lenovo ThinkPad T14 Gen 4 laptops running Windows 11 Professional 23H2; 8 Lenovo ThinkCentre M70q Gen 3 desktops running Windows 10 Professional 22H2
Show evidence items (2)
Device Inventory: NonCompliant
Entity: Lenovo ThinkPad T14 Gen 4
16 Lenovo ThinkPad T14 Gen 4 Laptop running Windows 11 Professional 23H2
Observed: 08/06/2026 19:22
Device Inventory: NonCompliant
Entity: Lenovo ThinkCentre M70q Gen 3
8 Lenovo ThinkCentre M70q Gen 3 Desktop running Windows 10 Professional 22H2
Observed: 08/06/2026 19:22
Likely No based on current evidence. Out-of-support operating systems detected via endoflife.date for A2.6: 16 Lenovo ThinkPad T14 Gen 4 laptops running Windows 11 Professional 23H2 (cycle 11-23h2-w is out of support; supported version should be 10.0.22631 on a supported cycle); 8 Lenovo ThinkCentre M70q Gen 3 desktops running Windows 10 Professional 22H2 (Windows 10 is out of support; supported version should be Windows 11 24H2 or later).
A2.6.1
Please list the quantity of thin clients within the scope of this assessment. Please include make and operating systems.
Present in: Danzel 3.3
Partial
Some operating systems in A2.6.1 could not be lifecycle-validated from endoflife.date cycles: 11 IGEL UD3-620 devices running IGEL OS 12.
11 IGEL UD3-620 thin clients running IGEL OS 12
Show evidence items (1)
Device Inventory: Partial
Entity: IGEL UD3-620
11 IGEL UD3-620 ThinClient running IGEL OS 12
Observed: 08/06/2026 19:22
Partially evidenced. Review before confirming. Some operating systems in A2.6.1 could not be lifecycle-validated from endoflife.date cycles: 11 IGEL UD3-620 devices running IGEL OS 12.
A2.7
Please list the quantity of servers, virtual servers, virtual server hosts (hypervisors) and Virtual Desktop Infrastructure (VDI) servers. You must include the operating system.
Present in: Danzel 3.3
Compliant
All operating system versions in A2.7 are currently supported based on endoflife.date lifecycle data. Update insights: 4 HPE ProLiant DL360 Gen10 devices running Windows Server 2022 (installed cycle 2022 is supported, but later supported cycle 2025 is available (latest 10.0.26100)); 9 Dell PowerEdge R640 virtual machine devices running Windows Server 2019 (installed cycle 2019 is supported, but later supported cycle 2025 is available (latest 10.0.26100)).
4 HPE ProLiant DL360 Gen10 servers running Windows Server 2022; 9 Dell PowerEdge R640 virtual machine virtual servers running Windows Server 2019
Show evidence items (2)
Device Inventory: Compliant
Entity: HPE ProLiant DL360 Gen10
4 HPE ProLiant DL360 Gen10 Server running Windows Server 2022
Observed: 08/06/2026 19:22
Device Inventory: Compliant
Entity: Dell PowerEdge R640 virtual machine
9 Dell PowerEdge R640 virtual machine VirtualServer running Windows Server 2019
Observed: 08/06/2026 19:22
Likely Yes based on current evidence. All operating system versions in A2.7 are currently supported based on endoflife.date lifecycle data. Update insights: 4 HPE ProLiant DL360 Gen10 devices running Windows Server 2022 (installed cycle 2022 is supported, but later supported cycle 2025 is available (latest 10.0.26100)); 9 Dell PowerEdge R640 virtual machine devices running Windows Server 2019 (installed cycle 2019 is supported, but later supported cycle 2025 is available (latest 10.0.26100)).
A2.8
Please list the quantities of tablets and mobile devices within the scope of this assessment.
Present in: Danzel 3.3
Compliant
All operating system versions in A2.8 are currently supported based on endoflife.date lifecycle data.
5 Samsung Galaxy Tab A9+ tablets running Android 14; 14 Google Pixel 8 Pro mobile devices running Android 15
Show evidence items (2)
Device Inventory: Compliant
Entity: Samsung Galaxy Tab A9+
5 Samsung Galaxy Tab A9+ Tablet running Android 14
Observed: 08/06/2026 19:22
Device Inventory: Compliant
Entity: Google Pixel 8 Pro
14 Google Pixel 8 Pro MobileDevice running Android 15
Observed: 08/06/2026 19:22
Likely Yes based on current evidence. All operating system versions in A2.8 are currently supported based on endoflife.date lifecycle data.
A3.1
Please confirm the security update process for in-scope systems and who owns it.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A3.2
Please confirm the vulnerability management process for in-scope systems and services.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A3.3
Please confirm the incident response/escalation process for security events in scope.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A4.1
Do you have firewalls at the boundaries between your organisation's internal networks, laptops, desktops, servers, and the internet?
Present in: Danzel 3.3
Partial
Evidence from HaloPSA-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
2 evidence item(s): HaloPSA-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Partial
Entity: Device Group: Rocinante Fleet Endpoints
Reason: Most devices enforce host firewall policy, but 2 field laptops still have public profile exceptions pending review.
Demo (The Expanse): Fleet endpoint audit found 2 laptops with temporary inbound exceptions awaiting approved closure.
Observed: 08/06/2026 19:01
Ref: demo://expanse/ninjaone/firewall-baseline-rocinante
HaloPSA-Demo: Compliant
Entity: Change Queue: Firewall Management Access
Reason: Remote firewall administration is ticketed, approved, and linked to a documented operational requirement.
Demo (The Expanse): Firewall management access for Rocinante mission support is approved via recurring CAB record and monthly review.
Observed: 08/06/2026 18:52
Ref: demo://expanse/halopsa/firewall-admin-access-rocinante
Partially evidenced. Review before confirming. Evidence from HaloPSA-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A4.1.1
Do you have software firewalls enabled on all of your computers, laptops and servers?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from HaloPSA-Demo, NinjaOne-Demo for this control; manual verification is recommended.
2 evidence item(s): HaloPSA-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Partial
Entity: Device Group: Rocinante Fleet Endpoints
Reason: Most devices enforce host firewall policy, but 2 field laptops still have public profile exceptions pending review.
Demo (The Expanse): Fleet endpoint audit found 2 laptops with temporary inbound exceptions awaiting approved closure.
Observed: 08/06/2026 19:01
Ref: demo://expanse/ninjaone/firewall-baseline-rocinante
HaloPSA-Demo: Compliant
Entity: Change Queue: Firewall Management Access
Reason: Remote firewall administration is ticketed, approved, and linked to a documented operational requirement.
Demo (The Expanse): Firewall management access for Rocinante mission support is approved via recurring CAB record and monthly review.
Observed: 08/06/2026 18:52
Ref: demo://expanse/halopsa/firewall-admin-access-rocinante
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from HaloPSA-Demo, NinjaOne-Demo for this control; manual verification is recommended.
A4.1.2
If you answered no to question A4.1.1, is this because software firewalls are not installed by default as part of the operating system you are using?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from HaloPSA-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
2 evidence item(s): HaloPSA-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Partial
Entity: Device Group: Rocinante Fleet Endpoints
Reason: Most devices enforce host firewall policy, but 2 field laptops still have public profile exceptions pending review.
Demo (The Expanse): Fleet endpoint audit found 2 laptops with temporary inbound exceptions awaiting approved closure.
Observed: 08/06/2026 19:01
Ref: demo://expanse/ninjaone/firewall-baseline-rocinante
HaloPSA-Demo: Compliant
Entity: Change Queue: Firewall Management Access
Reason: Remote firewall administration is ticketed, approved, and linked to a documented operational requirement.
Demo (The Expanse): Firewall management access for Rocinante mission support is approved via recurring CAB record and monthly review.
Observed: 08/06/2026 18:52
Ref: demo://expanse/halopsa/firewall-admin-access-rocinante
Likely Yes based on current evidence. Verified configuration evidence from HaloPSA-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A4.2
When you first receive an internet router or hardware firewall device, it may have had a default password on it. Have you changed all the default passwords on your boundary firewall devices?
Present in: Danzel 3.3
Partial
Evidence from HaloPSA-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
2 evidence item(s): HaloPSA-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Partial
Entity: Device Group: Rocinante Fleet Endpoints
Reason: Most devices enforce host firewall policy, but 2 field laptops still have public profile exceptions pending review.
Demo (The Expanse): Fleet endpoint audit found 2 laptops with temporary inbound exceptions awaiting approved closure.
Observed: 08/06/2026 19:01
Ref: demo://expanse/ninjaone/firewall-baseline-rocinante
HaloPSA-Demo: Compliant
Entity: Change Queue: Firewall Management Access
Reason: Remote firewall administration is ticketed, approved, and linked to a documented operational requirement.
Demo (The Expanse): Firewall management access for Rocinante mission support is approved via recurring CAB record and monthly review.
Observed: 08/06/2026 18:52
Ref: demo://expanse/halopsa/firewall-admin-access-rocinante
Partially evidenced. Review before confirming. Evidence from HaloPSA-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A4.2.1
Please describe the process for changing your firewall password.
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from HaloPSA-Demo, NinjaOne-Demo for this control; manual verification is recommended.
2 evidence item(s): HaloPSA-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Partial
Entity: Device Group: Rocinante Fleet Endpoints
Reason: Most devices enforce host firewall policy, but 2 field laptops still have public profile exceptions pending review.
Demo (The Expanse): Fleet endpoint audit found 2 laptops with temporary inbound exceptions awaiting approved closure.
Observed: 08/06/2026 19:01
Ref: demo://expanse/ninjaone/firewall-baseline-rocinante
HaloPSA-Demo: Compliant
Entity: Change Queue: Firewall Management Access
Reason: Remote firewall administration is ticketed, approved, and linked to a documented operational requirement.
Demo (The Expanse): Firewall management access for Rocinante mission support is approved via recurring CAB record and monthly review.
Observed: 08/06/2026 18:52
Ref: demo://expanse/halopsa/firewall-admin-access-rocinante
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from HaloPSA-Demo, NinjaOne-Demo for this control; manual verification is recommended.
A4.3
How is your firewall password configured?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from HaloPSA-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
2 evidence item(s): HaloPSA-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Partial
Entity: Device Group: Rocinante Fleet Endpoints
Reason: Most devices enforce host firewall policy, but 2 field laptops still have public profile exceptions pending review.
Demo (The Expanse): Fleet endpoint audit found 2 laptops with temporary inbound exceptions awaiting approved closure.
Observed: 08/06/2026 19:01
Ref: demo://expanse/ninjaone/firewall-baseline-rocinante
HaloPSA-Demo: Compliant
Entity: Change Queue: Firewall Management Access
Reason: Remote firewall administration is ticketed, approved, and linked to a documented operational requirement.
Demo (The Expanse): Firewall management access for Rocinante mission support is approved via recurring CAB record and monthly review.
Observed: 08/06/2026 18:52
Ref: demo://expanse/halopsa/firewall-admin-access-rocinante
Likely Yes based on current evidence. Verified configuration evidence from HaloPSA-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A4.4
Do you change your firewall password when you know or suspect it has been compromised?
Present in: Danzel 3.3
Partial
Evidence from HaloPSA-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
2 evidence item(s): HaloPSA-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Partial
Entity: Device Group: Rocinante Fleet Endpoints
Reason: Most devices enforce host firewall policy, but 2 field laptops still have public profile exceptions pending review.
Demo (The Expanse): Fleet endpoint audit found 2 laptops with temporary inbound exceptions awaiting approved closure.
Observed: 08/06/2026 19:01
Ref: demo://expanse/ninjaone/firewall-baseline-rocinante
HaloPSA-Demo: Compliant
Entity: Change Queue: Firewall Management Access
Reason: Remote firewall administration is ticketed, approved, and linked to a documented operational requirement.
Demo (The Expanse): Firewall management access for Rocinante mission support is approved via recurring CAB record and monthly review.
Observed: 08/06/2026 18:52
Ref: demo://expanse/halopsa/firewall-admin-access-rocinante
Partially evidenced. Review before confirming. Evidence from HaloPSA-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A4.5
Do you have a process to manage your firewall?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from HaloPSA-Demo, NinjaOne-Demo for this control; manual verification is recommended.
2 evidence item(s): HaloPSA-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Partial
Entity: Device Group: Rocinante Fleet Endpoints
Reason: Most devices enforce host firewall policy, but 2 field laptops still have public profile exceptions pending review.
Demo (The Expanse): Fleet endpoint audit found 2 laptops with temporary inbound exceptions awaiting approved closure.
Observed: 08/06/2026 19:01
Ref: demo://expanse/ninjaone/firewall-baseline-rocinante
HaloPSA-Demo: Compliant
Entity: Change Queue: Firewall Management Access
Reason: Remote firewall administration is ticketed, approved, and linked to a documented operational requirement.
Demo (The Expanse): Firewall management access for Rocinante mission support is approved via recurring CAB record and monthly review.
Observed: 08/06/2026 18:52
Ref: demo://expanse/halopsa/firewall-admin-access-rocinante
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from HaloPSA-Demo, NinjaOne-Demo for this control; manual verification is recommended.
A4.6
Have you reviewed your firewall rules in the last 12 months?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from HaloPSA-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
2 evidence item(s): HaloPSA-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Partial
Entity: Device Group: Rocinante Fleet Endpoints
Reason: Most devices enforce host firewall policy, but 2 field laptops still have public profile exceptions pending review.
Demo (The Expanse): Fleet endpoint audit found 2 laptops with temporary inbound exceptions awaiting approved closure.
Observed: 08/06/2026 19:01
Ref: demo://expanse/ninjaone/firewall-baseline-rocinante
HaloPSA-Demo: Compliant
Entity: Change Queue: Firewall Management Access
Reason: Remote firewall administration is ticketed, approved, and linked to a documented operational requirement.
Demo (The Expanse): Firewall management access for Rocinante mission support is approved via recurring CAB record and monthly review.
Observed: 08/06/2026 18:52
Ref: demo://expanse/halopsa/firewall-admin-access-rocinante
Likely Yes based on current evidence. Verified configuration evidence from HaloPSA-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A4.7
Are host firewalls enabled and configured to block unauthorized inbound network connections on supported endpoints?
Present in: Danzel 3.3
Partial
Evidence from HaloPSA-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
2 evidence item(s): HaloPSA-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Partial
Entity: Device Group: Rocinante Fleet Endpoints
Reason: Most devices enforce host firewall policy, but 2 field laptops still have public profile exceptions pending review.
Demo (The Expanse): Fleet endpoint audit found 2 laptops with temporary inbound exceptions awaiting approved closure.
Observed: 08/06/2026 19:01
Ref: demo://expanse/ninjaone/firewall-baseline-rocinante
HaloPSA-Demo: Compliant
Entity: Change Queue: Firewall Management Access
Reason: Remote firewall administration is ticketed, approved, and linked to a documented operational requirement.
Demo (The Expanse): Firewall management access for Rocinante mission support is approved via recurring CAB record and monthly review.
Observed: 08/06/2026 18:52
Ref: demo://expanse/halopsa/firewall-admin-access-rocinante
Partially evidenced. Review before confirming. Evidence from HaloPSA-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A4.8
Please describe how you approve and document your allowed inbound connections.
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from HaloPSA-Demo, NinjaOne-Demo for this control; manual verification is recommended.
2 evidence item(s): HaloPSA-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Partial
Entity: Device Group: Rocinante Fleet Endpoints
Reason: Most devices enforce host firewall policy, but 2 field laptops still have public profile exceptions pending review.
Demo (The Expanse): Fleet endpoint audit found 2 laptops with temporary inbound exceptions awaiting approved closure.
Observed: 08/06/2026 19:01
Ref: demo://expanse/ninjaone/firewall-baseline-rocinante
HaloPSA-Demo: Compliant
Entity: Change Queue: Firewall Management Access
Reason: Remote firewall administration is ticketed, approved, and linked to a documented operational requirement.
Demo (The Expanse): Firewall management access for Rocinante mission support is approved via recurring CAB record and monthly review.
Observed: 08/06/2026 18:52
Ref: demo://expanse/halopsa/firewall-admin-access-rocinante
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from HaloPSA-Demo, NinjaOne-Demo for this control; manual verification is recommended.
A4.9
Are your boundary firewalls configured to allow access to their configuration settings over the internet?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from HaloPSA-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
2 evidence item(s): HaloPSA-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Partial
Entity: Device Group: Rocinante Fleet Endpoints
Reason: Most devices enforce host firewall policy, but 2 field laptops still have public profile exceptions pending review.
Demo (The Expanse): Fleet endpoint audit found 2 laptops with temporary inbound exceptions awaiting approved closure.
Observed: 08/06/2026 19:01
Ref: demo://expanse/ninjaone/firewall-baseline-rocinante
HaloPSA-Demo: Compliant
Entity: Change Queue: Firewall Management Access
Reason: Remote firewall administration is ticketed, approved, and linked to a documented operational requirement.
Demo (The Expanse): Firewall management access for Rocinante mission support is approved via recurring CAB record and monthly review.
Observed: 08/06/2026 18:52
Ref: demo://expanse/halopsa/firewall-admin-access-rocinante
Likely Yes based on current evidence. Verified configuration evidence from HaloPSA-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A4.10
If you answered yes in question A4.9, is there a documented business requirement for this access?
Present in: Danzel 3.3
Partial
Evidence from HaloPSA-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
2 evidence item(s): HaloPSA-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Partial
Entity: Device Group: Rocinante Fleet Endpoints
Reason: Most devices enforce host firewall policy, but 2 field laptops still have public profile exceptions pending review.
Demo (The Expanse): Fleet endpoint audit found 2 laptops with temporary inbound exceptions awaiting approved closure.
Observed: 08/06/2026 19:01
Ref: demo://expanse/ninjaone/firewall-baseline-rocinante
HaloPSA-Demo: Compliant
Entity: Change Queue: Firewall Management Access
Reason: Remote firewall administration is ticketed, approved, and linked to a documented operational requirement.
Demo (The Expanse): Firewall management access for Rocinante mission support is approved via recurring CAB record and monthly review.
Observed: 08/06/2026 18:52
Ref: demo://expanse/halopsa/firewall-admin-access-rocinante
Partially evidenced. Review before confirming. Evidence from HaloPSA-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A4.11
If you answered yes in question A4.9, is the access to your firewall settings protected by either multi-factor authentication or by only allowing trusted IP addresses combined with managed authentication to access the settings?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from HaloPSA-Demo, NinjaOne-Demo for this control; manual verification is recommended.
2 evidence item(s): HaloPSA-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Partial
Entity: Device Group: Rocinante Fleet Endpoints
Reason: Most devices enforce host firewall policy, but 2 field laptops still have public profile exceptions pending review.
Demo (The Expanse): Fleet endpoint audit found 2 laptops with temporary inbound exceptions awaiting approved closure.
Observed: 08/06/2026 19:01
Ref: demo://expanse/ninjaone/firewall-baseline-rocinante
HaloPSA-Demo: Compliant
Entity: Change Queue: Firewall Management Access
Reason: Remote firewall administration is ticketed, approved, and linked to a documented operational requirement.
Demo (The Expanse): Firewall management access for Rocinante mission support is approved via recurring CAB record and monthly review.
Observed: 08/06/2026 18:52
Ref: demo://expanse/halopsa/firewall-admin-access-rocinante
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from HaloPSA-Demo, NinjaOne-Demo for this control; manual verification is recommended.
A5.1
Is unnecessary or unauthorized software identified and remediated in line with policy?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
3 evidence item(s): HaloPSA-Demo (1), M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (3)
HaloPSA-Demo: Partial
Entity: Change Queue: Software Remediation
Reason: Two software removal changes are approved but awaiting maintenance window completion.
Demo (The Expanse): Remediation workflow includes 2 pending software removal actions scheduled in the next approved maintenance window.
Observed: 08/06/2026 18:49
Ref: demo://expanse/halopsa/software-remediation-queue
M365-Intune-Demo: Partial
Entity: Intune Discovered Apps: Fleet Operations
Reason: Three devices still report unapproved remote-admin tooling outside approved baseline.
Demo (The Expanse): Intune discovered apps flagged 3 unmanaged remote-admin installations pending remediation approval.
Observed: 08/06/2026 18:38
Ref: demo://expanse/m365/intune-discovered-apps
NinjaOne-Demo: Partial
Entity: Software Inventory: Fleet Tablets
Reason: Three unauthorized remote support tools remain pending removal.
Demo (The Expanse): NinjaOne software inventory flags 3 non-standard remote support tools still present on fleet tablets.
Observed: 08/06/2026 18:36
Ref: demo://expanse/ninjaone/unauthorized-software-inventory
Likely Yes based on current evidence. Verified configuration evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A5.2
Are systems and identities configured to an approved secure baseline with unnecessary features disabled?
Present in: Danzel 3.3
Partial
Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
No direct evidence items are currently mapped to this question.
Partially evidenced. Review before confirming. Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A5.3
Have you changed the default password for all user and administrator accounts on all your desktop computers, laptops, thin clients, servers, tablets and mobile phones?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
No direct evidence items are currently mapped to this question.
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
A5.4
Do you run or host external services that provide access to data (that should not be made public) to users across the internet?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
No direct evidence items are currently mapped to this question.
Likely Yes based on current evidence. Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A5.5
If yes to question A5.4, which authentication option do you use?
Present in: Danzel 3.3
Partial
Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
No direct evidence items are currently mapped to this question.
Partially evidenced. Review before confirming. Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A5.6
Describe the process in place for changing passwords on your external services when you believe they have been compromised.
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
No direct evidence items are currently mapped to this question.
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
A5.7
When not using multi-factor authentication, which option are you using to protect your external service from brute force attacks?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
No direct evidence items are currently mapped to this question.
Likely Yes based on current evidence. Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A5.8
Have you disabled any feature which allows automatic file execution of downloaded or imported files without user authorisation?
Present in: Danzel 3.3
Partial
Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
No direct evidence items are currently mapped to this question.
Partially evidenced. Review before confirming. Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A5.9
When a device requires a user to be present, do you set a locking mechanism on your devices to access the software and services installed?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
No direct evidence items are currently mapped to this question.
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
A5.10
Which method do you use to unlock the devices?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
3 evidence item(s): HaloPSA-Demo (1), M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (3)
HaloPSA-Demo: Partial
Entity: Change Queue: Software Remediation
Reason: Two software removal changes are approved but awaiting maintenance window completion.
Demo (The Expanse): Remediation workflow includes 2 pending software removal actions scheduled in the next approved maintenance window.
Observed: 08/06/2026 18:49
Ref: demo://expanse/halopsa/software-remediation-queue
M365-Intune-Demo: Partial
Entity: Intune Discovered Apps: Fleet Operations
Reason: Three devices still report unapproved remote-admin tooling outside approved baseline.
Demo (The Expanse): Intune discovered apps flagged 3 unmanaged remote-admin installations pending remediation approval.
Observed: 08/06/2026 18:38
Ref: demo://expanse/m365/intune-discovered-apps
NinjaOne-Demo: Partial
Entity: Software Inventory: Fleet Tablets
Reason: Three unauthorized remote support tools remain pending removal.
Demo (The Expanse): NinjaOne software inventory flags 3 non-standard remote support tools still present on fleet tablets.
Observed: 08/06/2026 18:36
Ref: demo://expanse/ninjaone/unauthorized-software-inventory
Likely Yes based on current evidence. Verified configuration evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A6.1
Are all operating systems on your devices supported by a vendor that produces regular security updates and vulnerability fixes?
Present in: Danzel 3.3
Partial
Evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
3 evidence item(s): HaloPSA-Demo (1), M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (3)
HaloPSA-Demo: Partial
Entity: Patch Queue: Belt Relay Endpoints
Reason: Four tracked items exceeded the agreed remediation window.
Demo (The Expanse): 4 patch SLA breaches recorded across Belt relay endpoints in the last cycle.
Observed: 08/06/2026 19:04
Ref: demo://expanse/halopsa/patch-sla
M365-Intune-Demo: Partial
Entity: Intune Update Compliance: Fleet Tablets
Reason: Five tablets are outside update deployment deadline and pending restart completion.
Demo (The Expanse): Intune update compliance shows 5 fleet tablets missing latest quality update SLA target.
Observed: 08/06/2026 18:43
Ref: demo://expanse/m365/intune-update-compliance
NinjaOne-Demo: Partial
Entity: Devices: Belt Fleet Tablets (5)
Reason: Unmanaged tablets are outside the required patch SLA window.
Demo (The Expanse): 5 Belt fleet tablets are unmanaged and outside baseline policy.
Observed: 08/06/2026 18:34
Ref: demo://expanse/ninjaone/unmanaged-tablets
Partially evidenced. Review before confirming. Evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A6.2
Is all the software on your devices supported by a supplier that produces regular vulnerability fixes for any security problems?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo for this control; manual verification is recommended.
3 evidence item(s): HaloPSA-Demo (1), M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (3)
HaloPSA-Demo: Partial
Entity: Patch Queue: Belt Relay Endpoints
Reason: Four tracked items exceeded the agreed remediation window.
Demo (The Expanse): 4 patch SLA breaches recorded across Belt relay endpoints in the last cycle.
Observed: 08/06/2026 19:04
Ref: demo://expanse/halopsa/patch-sla
M365-Intune-Demo: Partial
Entity: Intune Update Compliance: Fleet Tablets
Reason: Five tablets are outside update deployment deadline and pending restart completion.
Demo (The Expanse): Intune update compliance shows 5 fleet tablets missing latest quality update SLA target.
Observed: 08/06/2026 18:43
Ref: demo://expanse/m365/intune-update-compliance
NinjaOne-Demo: Partial
Entity: Devices: Belt Fleet Tablets (5)
Reason: Unmanaged tablets are outside the required patch SLA window.
Demo (The Expanse): 5 Belt fleet tablets are unmanaged and outside baseline policy.
Observed: 08/06/2026 18:34
Ref: demo://expanse/ninjaone/unmanaged-tablets
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo for this control; manual verification is recommended.
A6.2.1
Please list your internet browser(s).
Present in: Danzel 3.3
Compliant
Verified configuration evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
3 evidence item(s): HaloPSA-Demo (1), M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (3)
HaloPSA-Demo: Partial
Entity: Patch Queue: Belt Relay Endpoints
Reason: Four tracked items exceeded the agreed remediation window.
Demo (The Expanse): 4 patch SLA breaches recorded across Belt relay endpoints in the last cycle.
Observed: 08/06/2026 19:04
Ref: demo://expanse/halopsa/patch-sla
M365-Intune-Demo: Partial
Entity: Intune Update Compliance: Fleet Tablets
Reason: Five tablets are outside update deployment deadline and pending restart completion.
Demo (The Expanse): Intune update compliance shows 5 fleet tablets missing latest quality update SLA target.
Observed: 08/06/2026 18:43
Ref: demo://expanse/m365/intune-update-compliance
NinjaOne-Demo: Partial
Entity: Devices: Belt Fleet Tablets (5)
Reason: Unmanaged tablets are outside the required patch SLA window.
Demo (The Expanse): 5 Belt fleet tablets are unmanaged and outside baseline policy.
Observed: 08/06/2026 18:34
Ref: demo://expanse/ninjaone/unmanaged-tablets
Likely Yes based on current evidence. Verified configuration evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A6.2.2
Please list your malware protection software.
Present in: Danzel 3.3
Partial
Evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
3 evidence item(s): HaloPSA-Demo (1), M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (3)
HaloPSA-Demo: Partial
Entity: Patch Queue: Belt Relay Endpoints
Reason: Four tracked items exceeded the agreed remediation window.
Demo (The Expanse): 4 patch SLA breaches recorded across Belt relay endpoints in the last cycle.
Observed: 08/06/2026 19:04
Ref: demo://expanse/halopsa/patch-sla
M365-Intune-Demo: Partial
Entity: Intune Update Compliance: Fleet Tablets
Reason: Five tablets are outside update deployment deadline and pending restart completion.
Demo (The Expanse): Intune update compliance shows 5 fleet tablets missing latest quality update SLA target.
Observed: 08/06/2026 18:43
Ref: demo://expanse/m365/intune-update-compliance
NinjaOne-Demo: Partial
Entity: Devices: Belt Fleet Tablets (5)
Reason: Unmanaged tablets are outside the required patch SLA window.
Demo (The Expanse): 5 Belt fleet tablets are unmanaged and outside baseline policy.
Observed: 08/06/2026 18:34
Ref: demo://expanse/ninjaone/unmanaged-tablets
Partially evidenced. Review before confirming. Evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A6.2.3
Please list your email applications installed on end user devices and servers.
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo for this control; manual verification is recommended.
3 evidence item(s): HaloPSA-Demo (1), M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (3)
HaloPSA-Demo: Partial
Entity: Patch Queue: Belt Relay Endpoints
Reason: Four tracked items exceeded the agreed remediation window.
Demo (The Expanse): 4 patch SLA breaches recorded across Belt relay endpoints in the last cycle.
Observed: 08/06/2026 19:04
Ref: demo://expanse/halopsa/patch-sla
M365-Intune-Demo: Partial
Entity: Intune Update Compliance: Fleet Tablets
Reason: Five tablets are outside update deployment deadline and pending restart completion.
Demo (The Expanse): Intune update compliance shows 5 fleet tablets missing latest quality update SLA target.
Observed: 08/06/2026 18:43
Ref: demo://expanse/m365/intune-update-compliance
NinjaOne-Demo: Partial
Entity: Devices: Belt Fleet Tablets (5)
Reason: Unmanaged tablets are outside the required patch SLA window.
Demo (The Expanse): 5 Belt fleet tablets are unmanaged and outside baseline policy.
Observed: 08/06/2026 18:34
Ref: demo://expanse/ninjaone/unmanaged-tablets
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo for this control; manual verification is recommended.
A6.2.4
Please list all office applications that are used to create organisational data.
Present in: Danzel 3.3
Compliant
Verified configuration evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
3 evidence item(s): HaloPSA-Demo (1), M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (3)
HaloPSA-Demo: Partial
Entity: Patch Queue: Belt Relay Endpoints
Reason: Four tracked items exceeded the agreed remediation window.
Demo (The Expanse): 4 patch SLA breaches recorded across Belt relay endpoints in the last cycle.
Observed: 08/06/2026 19:04
Ref: demo://expanse/halopsa/patch-sla
M365-Intune-Demo: Partial
Entity: Intune Update Compliance: Fleet Tablets
Reason: Five tablets are outside update deployment deadline and pending restart completion.
Demo (The Expanse): Intune update compliance shows 5 fleet tablets missing latest quality update SLA target.
Observed: 08/06/2026 18:43
Ref: demo://expanse/m365/intune-update-compliance
NinjaOne-Demo: Partial
Entity: Devices: Belt Fleet Tablets (5)
Reason: Unmanaged tablets are outside the required patch SLA window.
Demo (The Expanse): 5 Belt fleet tablets are unmanaged and outside baseline policy.
Observed: 08/06/2026 18:34
Ref: demo://expanse/ninjaone/unmanaged-tablets
Likely Yes based on current evidence. Verified configuration evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A6.3
Are any of the in-scope software or cloud services unlicensed or unsupported?
Present in: Danzel 3.3
Partial
Evidence from NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Compliant
Entity: Device Group: Rocinante Mission Hosts
Reason: No unsupported software detected in current inventory baseline.
Demo (The Expanse): Rocinante mission hosts completed latest endpoint quarantine drill.
Observed: 08/06/2026 18:12
Ref: demo://expanse/ninjaone/quarantine-drill
Partially evidenced. Review before confirming. Evidence from NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A6.3.1/A6.6/A6.7
Is unsupported or end-of-life software identified and remediated with accountable ownership?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from NinjaOne-Demo for this control; manual verification is recommended.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Compliant
Entity: Device Group: Rocinante Mission Hosts
Reason: No unsupported software detected in current inventory baseline.
Demo (The Expanse): Rocinante mission hosts completed latest endpoint quarantine drill.
Observed: 08/06/2026 18:12
Ref: demo://expanse/ninjaone/quarantine-drill
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from NinjaOne-Demo for this control; manual verification is recommended.
A6.4/A6.5
Are security updates applied within policy timelines for operating systems and applications?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
3 evidence item(s): HaloPSA-Demo (1), M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (3)
HaloPSA-Demo: Partial
Entity: Patch Queue: Belt Relay Endpoints
Reason: Four tracked items exceeded the agreed remediation window.
Demo (The Expanse): 4 patch SLA breaches recorded across Belt relay endpoints in the last cycle.
Observed: 08/06/2026 19:04
Ref: demo://expanse/halopsa/patch-sla
M365-Intune-Demo: Partial
Entity: Intune Update Compliance: Fleet Tablets
Reason: Five tablets are outside update deployment deadline and pending restart completion.
Demo (The Expanse): Intune update compliance shows 5 fleet tablets missing latest quality update SLA target.
Observed: 08/06/2026 18:43
Ref: demo://expanse/m365/intune-update-compliance
NinjaOne-Demo: Partial
Entity: Devices: Belt Fleet Tablets (5)
Reason: Unmanaged tablets are outside the required patch SLA window.
Demo (The Expanse): 5 Belt fleet tablets are unmanaged and outside baseline policy.
Observed: 08/06/2026 18:34
Ref: demo://expanse/ninjaone/unmanaged-tablets
Likely Yes based on current evidence. Verified configuration evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A6.4.1
Are all updates applied for operating systems by enabling auto updates?
Present in: Danzel 3.3
Partial
Evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
3 evidence item(s): HaloPSA-Demo (1), M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (3)
HaloPSA-Demo: Partial
Entity: Patch Queue: Belt Relay Endpoints
Reason: Four tracked items exceeded the agreed remediation window.
Demo (The Expanse): 4 patch SLA breaches recorded across Belt relay endpoints in the last cycle.
Observed: 08/06/2026 19:04
Ref: demo://expanse/halopsa/patch-sla
M365-Intune-Demo: Partial
Entity: Intune Update Compliance: Fleet Tablets
Reason: Five tablets are outside update deployment deadline and pending restart completion.
Demo (The Expanse): Intune update compliance shows 5 fleet tablets missing latest quality update SLA target.
Observed: 08/06/2026 18:43
Ref: demo://expanse/m365/intune-update-compliance
NinjaOne-Demo: Partial
Entity: Devices: Belt Fleet Tablets (5)
Reason: Unmanaged tablets are outside the required patch SLA window.
Demo (The Expanse): 5 Belt fleet tablets are unmanaged and outside baseline policy.
Observed: 08/06/2026 18:34
Ref: demo://expanse/ninjaone/unmanaged-tablets
Partially evidenced. Review before confirming. Evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A6.4.2
Where auto updates are not being used, how do you ensure all high-risk or critical security updates and vulnerability fixes of all operating systems and firmware on firewalls and routers are applied within 14 days of release?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo for this control; manual verification is recommended.
3 evidence item(s): HaloPSA-Demo (1), M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (3)
HaloPSA-Demo: Partial
Entity: Patch Queue: Belt Relay Endpoints
Reason: Four tracked items exceeded the agreed remediation window.
Demo (The Expanse): 4 patch SLA breaches recorded across Belt relay endpoints in the last cycle.
Observed: 08/06/2026 19:04
Ref: demo://expanse/halopsa/patch-sla
M365-Intune-Demo: Partial
Entity: Intune Update Compliance: Fleet Tablets
Reason: Five tablets are outside update deployment deadline and pending restart completion.
Demo (The Expanse): Intune update compliance shows 5 fleet tablets missing latest quality update SLA target.
Observed: 08/06/2026 18:43
Ref: demo://expanse/m365/intune-update-compliance
NinjaOne-Demo: Partial
Entity: Devices: Belt Fleet Tablets (5)
Reason: Unmanaged tablets are outside the required patch SLA window.
Demo (The Expanse): 5 Belt fleet tablets are unmanaged and outside baseline policy.
Observed: 08/06/2026 18:34
Ref: demo://expanse/ninjaone/unmanaged-tablets
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo for this control; manual verification is recommended.
A6.5
Are all high-risk or critical security updates and vulnerability fixes for applications (including any associated files and extensions) installed within 14 days of release?
Present in: Danzel 3.3
Unknown
Manual response required. Corroborating records may be available from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Supporting records may be available from M365, NinjaOne, HaloPSA.
Provide a manual answer and attach notes. Corroborate with M365, NinjaOne, HaloPSA where possible.
A6.5.1
Are all updates applied on your applications by enabling auto updates?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
3 evidence item(s): HaloPSA-Demo (1), M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (3)
HaloPSA-Demo: Partial
Entity: Patch Queue: Belt Relay Endpoints
Reason: Four tracked items exceeded the agreed remediation window.
Demo (The Expanse): 4 patch SLA breaches recorded across Belt relay endpoints in the last cycle.
Observed: 08/06/2026 19:04
Ref: demo://expanse/halopsa/patch-sla
M365-Intune-Demo: Partial
Entity: Intune Update Compliance: Fleet Tablets
Reason: Five tablets are outside update deployment deadline and pending restart completion.
Demo (The Expanse): Intune update compliance shows 5 fleet tablets missing latest quality update SLA target.
Observed: 08/06/2026 18:43
Ref: demo://expanse/m365/intune-update-compliance
NinjaOne-Demo: Partial
Entity: Devices: Belt Fleet Tablets (5)
Reason: Unmanaged tablets are outside the required patch SLA window.
Demo (The Expanse): 5 Belt fleet tablets are unmanaged and outside baseline policy.
Observed: 08/06/2026 18:34
Ref: demo://expanse/ninjaone/unmanaged-tablets
Likely Yes based on current evidence. Verified configuration evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A6.5.2
Where auto updates are not being used, how do you ensure all high-risk or critical security updates of all applications are applied within 14 days of release?
Present in: Danzel 3.3
Partial
Evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
3 evidence item(s): HaloPSA-Demo (1), M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (3)
HaloPSA-Demo: Partial
Entity: Patch Queue: Belt Relay Endpoints
Reason: Four tracked items exceeded the agreed remediation window.
Demo (The Expanse): 4 patch SLA breaches recorded across Belt relay endpoints in the last cycle.
Observed: 08/06/2026 19:04
Ref: demo://expanse/halopsa/patch-sla
M365-Intune-Demo: Partial
Entity: Intune Update Compliance: Fleet Tablets
Reason: Five tablets are outside update deployment deadline and pending restart completion.
Demo (The Expanse): Intune update compliance shows 5 fleet tablets missing latest quality update SLA target.
Observed: 08/06/2026 18:43
Ref: demo://expanse/m365/intune-update-compliance
NinjaOne-Demo: Partial
Entity: Devices: Belt Fleet Tablets (5)
Reason: Unmanaged tablets are outside the required patch SLA window.
Demo (The Expanse): 5 Belt fleet tablets are unmanaged and outside baseline policy.
Observed: 08/06/2026 18:34
Ref: demo://expanse/ninjaone/unmanaged-tablets
Partially evidenced. Review before confirming. Evidence from HaloPSA-Demo, M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A6.6
Have you removed any software installed on your devices that is no longer supported and no longer receives regular updates or vulnerability fixes for security problems?
Present in: Danzel 3.3
Unknown
Manual response required. Corroborating records may be available from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Supporting records may be available from M365, NinjaOne, HaloPSA.
Provide a manual answer and attach notes. Corroborate with M365, NinjaOne, HaloPSA where possible.
A6.7
Where you have a business need to use unsupported software, have you moved the devices and software out of scope of this assessment?
Present in: Danzel 3.3
Unknown
Manual response required. Corroborating records may be available from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Supporting records may be available from M365, NinjaOne, HaloPSA.
Provide a manual answer and attach notes. Corroborate with M365, NinjaOne, HaloPSA where possible.
A7.1
Are your users only provided with user accounts after a process has been followed to approve their creation? Describe the process.
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from M365-Demo for this control; manual verification is recommended.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Partial
Entity: Tenant: Rocinante Operations
Reason: Two shared admin/user identities remain in active use.
Demo (The Expanse): Rocinante operations still has 2 dual-use privileged identities pending split.
Observed: 08/06/2026 18:47
Ref: demo://expanse/m365/roci-privileged-separation
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from M365-Demo for this control; manual verification is recommended.
A7.2
Are all your user and administrative accounts accessed by entering unique credentials?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from M365-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Partial
Entity: Tenant: Rocinante Operations
Reason: Two shared admin/user identities remain in active use.
Demo (The Expanse): Rocinante operations still has 2 dual-use privileged identities pending split.
Observed: 08/06/2026 18:47
Ref: demo://expanse/m365/roci-privileged-separation
Likely Yes based on current evidence. Verified configuration evidence from M365-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A7.3
How do you ensure you have deleted, or disabled, any accounts for staff who are no longer with your organisation?
Present in: Danzel 3.3
Partial
Evidence from M365-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Partial
Entity: Tenant: Rocinante Operations
Reason: Two shared admin/user identities remain in active use.
Demo (The Expanse): Rocinante operations still has 2 dual-use privileged identities pending split.
Observed: 08/06/2026 18:47
Ref: demo://expanse/m365/roci-privileged-separation
Partially evidenced. Review before confirming. Evidence from M365-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A7.4
Do you ensure that staff only have the access privileges that they need to do their current job? How do you do this?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from M365-Demo for this control; manual verification is recommended.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Partial
Entity: Tenant: Rocinante Operations
Reason: Two shared admin/user identities remain in active use.
Demo (The Expanse): Rocinante operations still has 2 dual-use privileged identities pending split.
Observed: 08/06/2026 18:47
Ref: demo://expanse/m365/roci-privileged-separation
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from M365-Demo for this control; manual verification is recommended.
A7.5
Do you have a formal process for giving someone access to systems at an administrator level and can you describe this process?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from M365-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Partial
Entity: Tenant: Rocinante Operations
Reason: Two shared admin/user identities remain in active use.
Demo (The Expanse): Rocinante operations still has 2 dual-use privileged identities pending split.
Observed: 08/06/2026 18:47
Ref: demo://expanse/m365/roci-privileged-separation
Likely Yes based on current evidence. Verified configuration evidence from M365-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A7.6
Are administrative accounts separate from standard user accounts and used only for administrative tasks?
Present in: Danzel 3.3
Partial
Evidence from M365-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Partial
Entity: Tenant: Rocinante Operations
Reason: Two shared admin/user identities remain in active use.
Demo (The Expanse): Rocinante operations still has 2 dual-use privileged identities pending split.
Observed: 08/06/2026 18:47
Ref: demo://expanse/m365/roci-privileged-separation
Partially evidenced. Review before confirming. Evidence from M365-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A7.7
How does your organisation prevent administrator accounts from being used to carry out everyday tasks like browsing the web or accessing email?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from M365-Demo for this control; manual verification is recommended.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Partial
Entity: Tenant: Rocinante Operations
Reason: Two shared admin/user identities remain in active use.
Demo (The Expanse): Rocinante operations still has 2 dual-use privileged identities pending split.
Observed: 08/06/2026 18:47
Ref: demo://expanse/m365/roci-privileged-separation
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from M365-Demo for this control; manual verification is recommended.
A7.8
Do you formally track which users have administrator accounts in your organisation?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from M365-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Partial
Entity: Tenant: Rocinante Operations
Reason: Two shared admin/user identities remain in active use.
Demo (The Expanse): Rocinante operations still has 2 dual-use privileged identities pending split.
Observed: 08/06/2026 18:47
Ref: demo://expanse/m365/roci-privileged-separation
Likely Yes based on current evidence. Verified configuration evidence from M365-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A7.9
Do you review who should have administrative access on a regular basis?
Present in: Danzel 3.3
Partial
Evidence from M365-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Partial
Entity: Tenant: Rocinante Operations
Reason: Two shared admin/user identities remain in active use.
Demo (The Expanse): Rocinante operations still has 2 dual-use privileged identities pending split.
Observed: 08/06/2026 18:47
Ref: demo://expanse/m365/roci-privileged-separation
Partially evidenced. Review before confirming. Evidence from M365-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A7.10
Where you have systems that require passwords (or where passwords are a backup for a passwordless system), how are they protected from brute-force attacks?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from M365-Demo for this control; manual verification is recommended.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Partial
Entity: Tenant: Rocinante Operations
Reason: Two shared admin/user identities remain in active use.
Demo (The Expanse): Rocinante operations still has 2 dual-use privileged identities pending split.
Observed: 08/06/2026 18:47
Ref: demo://expanse/m365/roci-privileged-separation
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from M365-Demo for this control; manual verification is recommended.
A7.11
Which technical controls are used to manage the quality of your passwords within your organisation?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from M365-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Partial
Entity: Tenant: Rocinante Operations
Reason: Two shared admin/user identities remain in active use.
Demo (The Expanse): Rocinante operations still has 2 dual-use privileged identities pending split.
Observed: 08/06/2026 18:47
Ref: demo://expanse/m365/roci-privileged-separation
Likely Yes based on current evidence. Verified configuration evidence from M365-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A7.12
Please explain how you encourage people to use unique and strong passwords.
Present in: Danzel 3.3
Partial
Evidence from M365-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Partial
Entity: Tenant: Rocinante Operations
Reason: Two shared admin/user identities remain in active use.
Demo (The Expanse): Rocinante operations still has 2 dual-use privileged identities pending split.
Observed: 08/06/2026 18:47
Ref: demo://expanse/m365/roci-privileged-separation
Partially evidenced. Review before confirming. Evidence from M365-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A7.13
Do you have a process for when you believe the passwords or accounts have been compromised?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from M365-Demo for this control; manual verification is recommended.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Partial
Entity: Tenant: Rocinante Operations
Reason: Two shared admin/user identities remain in active use.
Demo (The Expanse): Rocinante operations still has 2 dual-use privileged identities pending split.
Observed: 08/06/2026 18:47
Ref: demo://expanse/m365/roci-privileged-separation
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from M365-Demo for this control; manual verification is recommended.
A7.14
Is multi-factor authentication enforced for privileged users and cloud service access?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
No direct evidence items are currently mapped to this question.
Likely Yes based on current evidence. Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A7.15
If you have answered no to question A7.14, please provide a list of your cloud services that do not provide any option for MFA.
Present in: Danzel 3.3
Partial
Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
No direct evidence items are currently mapped to this question.
Partially evidenced. Review before confirming. Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A7.16
Has MFA been applied to all administrators of your cloud services, excluding any listed in A7.15 that do not provide it?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
No direct evidence items are currently mapped to this question.
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
A7.17
Has MFA been applied to all users of your cloud services, excluding any listed in A7.15 that do not provide it?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
No direct evidence items are currently mapped to this question.
Likely Yes based on current evidence. Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A8.1
Is anti-malware protection enabled on supported devices with current signatures and active monitoring?
Present in: Danzel 3.3
Partial
Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
No direct evidence items are currently mapped to this question.
Partially evidenced. Review before confirming. Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A8.2/A8.3
Are malware detections investigated and resolved through a documented incident workflow?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
No direct evidence items are currently mapped to this question.
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
A8.3
If Option A has been selected: where you have anti-malware software installed, is it set to scan web pages you visit and warn you about accessing malicious websites?
Present in: Danzel 3.3
Unknown
Manual response required. Corroborating records may be available from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Supporting records may be available from M365, NinjaOne, HaloPSA.
Provide a manual answer and attach notes. Corroborate with M365, NinjaOne, HaloPSA where possible.
A8.4
If Option B has been selected: where you use an app-store or application signing, are users restricted from installing unsigned applications?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
No direct evidence items are currently mapped to this question.
Likely Yes based on current evidence. Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A8.5
If Option B has been selected: where you use an app-store or application signing, do you ensure users only install applications approved by your organisation and maintain that approved list?
Present in: Danzel 3.3
Partial
Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
No direct evidence items are currently mapped to this question.
Partially evidenced. Review before confirming. Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.