Compliance
Questionnaire Toolkit

Check the full questionnaire with auto-suggested responses from current evidence, then save manual confirmations and notes.

Question Set

Danzel (3.3)

Scope

CurrentOnly

Scheme

Basic

Client

Tycho Manufacturing

Saved Run

New draft

Questions

79

Manual answer is available for every question. Answered: 0 / 79 (remaining: 79).

Reference Manual Answer / Notes Checked Status Suggestion Evidence Auto Suggestion
A1.1
Please provide your organisation legal name and registered details.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A1.2
Please provide the primary business address for this assessment.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A1.3
Please confirm whether your organisation has cyber insurance and provide provider/policy details if applicable.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A1.4
Please identify the principal business activities and services covered by this assessment.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A1.5
Please provide the main security/compliance contact responsible for this submission.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A2.1
Please confirm whether all in-scope user devices are captured in your device inventory.
Present in: Danzel 3.3
Unknown
Manual response required. Inventory and scoping evidence can be corroborated from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Expected supporting records may come from M365, NinjaOne, HaloPSA.
Provide a complete inventory/scoping answer and validate against M365, NinjaOne, HaloPSA.
A2.2
Please confirm whether any home-working devices are included in the scope of this assessment.
Present in: Danzel 3.3
Unknown
Manual response required. Inventory and scoping evidence can be corroborated from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Expected supporting records may come from M365, NinjaOne, HaloPSA.
Provide a complete inventory/scoping answer and validate against M365, NinjaOne, HaloPSA.
A2.3
Please confirm whether any personally owned (BYOD) devices are included in scope.
Present in: Danzel 3.3
Unknown
Manual response required. Inventory and scoping evidence can be corroborated from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Expected supporting records may come from M365, NinjaOne, HaloPSA.
Provide a complete inventory/scoping answer and validate against M365, NinjaOne, HaloPSA.
A2.4
Please list the cloud services that are in scope for this assessment.
Present in: Danzel 3.3
Unknown
Manual response required. Inventory and scoping evidence can be corroborated from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Expected supporting records may come from M365, NinjaOne, HaloPSA.
Provide a complete inventory/scoping answer and validate against M365, NinjaOne, HaloPSA.
A2.5
Please list any internet-facing services, gateways, or externally accessible systems in scope.
Present in: Danzel 3.3
Unknown
Manual response required. Inventory and scoping evidence can be corroborated from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Expected supporting records may come from M365, NinjaOne, HaloPSA.
Provide a complete inventory/scoping answer and validate against M365, NinjaOne, HaloPSA.
A2.6
Please list the quantities and operating systems for your laptops, desktops and virtual desktops within the scope of this assessment.
Present in: Danzel 3.3
NonCompliant
Out-of-support operating systems detected via endoflife.date for A2.6: 25 Microsoft Surface Laptop 5 laptops running Windows 11 Professional 23H2 (cycle 11-23h2-w is out of support; supported version should be 10.0.22631 on a supported cycle); 12 Lenovo ThinkCentre M90q Gen 3 desktops running Windows 10 Professional 22H2 (Windows 10 is out of support; supported version should be Windows 11 24H2 or later).
10 Apple MacBook Pro 14-inch (M2 Pro) laptops running macOS Ventura 13; 25 Microsoft Surface Laptop 5 laptops running Windows 11 Professional 23H2; 12 Lenovo ThinkCentre M90q Gen 3 desktops running Windows 10 Professional 22H2; 18 Azure Virtual Desktop session host (Standard D4s v5) virtual desktops running Windows 11 Enterprise 23H2
Show evidence items (4)
Device Inventory: NonCompliant
Entity: Apple MacBook Pro 14-inch (M2 Pro)
10 Apple MacBook Pro 14-inch (M2 Pro) Laptop running macOS Ventura 13
Observed: 08/06/2026 19:20
Device Inventory: NonCompliant
Entity: Microsoft Surface Laptop 5
25 Microsoft Surface Laptop 5 Laptop running Windows 11 Professional 23H2
Observed: 08/06/2026 19:20
Device Inventory: NonCompliant
Entity: Lenovo ThinkCentre M90q Gen 3
12 Lenovo ThinkCentre M90q Gen 3 Desktop running Windows 10 Professional 22H2
Observed: 08/06/2026 19:20
Device Inventory: NonCompliant
Entity: Azure Virtual Desktop session host (Standard D4s v5)
18 Azure Virtual Desktop session host (Standard D4s v5) VirtualDesktop running Windows 11 Enterprise 23H2
Observed: 08/06/2026 19:20
Likely No based on current evidence. Out-of-support operating systems detected via endoflife.date for A2.6: 25 Microsoft Surface Laptop 5 laptops running Windows 11 Professional 23H2 (cycle 11-23h2-w is out of support; supported version should be 10.0.22631 on a supported cycle); 12 Lenovo ThinkCentre M90q Gen 3 desktops running Windows 10 Professional 22H2 (Windows 10 is out of support; supported version should be Windows 11 24H2 or later).
A2.6.1
Please list the quantity of thin clients within the scope of this assessment. Please include make and operating systems.
Present in: Danzel 3.3
Partial
Some operating systems in A2.6.1 could not be lifecycle-validated from endoflife.date cycles: 6 Lenovo ThinkCentre M75q Gen 2 Tiny devices running ThinOS 9.1.
6 Lenovo ThinkCentre M75q Gen 2 Tiny thin clients running ThinOS 9.1
Show evidence items (1)
Device Inventory: Partial
Entity: Lenovo ThinkCentre M75q Gen 2 Tiny
6 Lenovo ThinkCentre M75q Gen 2 Tiny ThinClient running ThinOS 9.1
Observed: 08/06/2026 19:20
Partially evidenced. Review before confirming. Some operating systems in A2.6.1 could not be lifecycle-validated from endoflife.date cycles: 6 Lenovo ThinkCentre M75q Gen 2 Tiny devices running ThinOS 9.1.
A2.7
Please list the quantity of servers, virtual servers, virtual server hosts (hypervisors) and Virtual Desktop Infrastructure (VDI) servers. You must include the operating system.
Present in: Danzel 3.3
Partial
Some operating systems in A2.7 could not be lifecycle-validated from endoflife.date cycles: 3 Dell PowerEdge R740 ESXi host devices running VMware ESXi 8.0 Update 2.
8 Lenovo ThinkSystem SR650 V2 servers running Windows Server 2022; 14 Dell PowerEdge R740 virtual machine virtual servers running Windows Server 2019; 3 Dell PowerEdge R740 ESXi host hypervisors running VMware ESXi 8.0 Update 2; 2 Azure Virtual Desktop host (Dell PowerEdge R650) VDI servers running Windows Server 2022
Show evidence items (4)
Device Inventory: Partial
Entity: Lenovo ThinkSystem SR650 V2
8 Lenovo ThinkSystem SR650 V2 Server running Windows Server 2022
Observed: 08/06/2026 19:20
Device Inventory: Partial
Entity: Dell PowerEdge R740 virtual machine
14 Dell PowerEdge R740 virtual machine VirtualServer running Windows Server 2019
Observed: 08/06/2026 19:20
Device Inventory: Partial
Entity: Dell PowerEdge R740 ESXi host
3 Dell PowerEdge R740 ESXi host Hypervisor running VMware ESXi 8.0 Update 2
Observed: 08/06/2026 19:20
Device Inventory: Partial
Entity: Azure Virtual Desktop host (Dell PowerEdge R650)
2 Azure Virtual Desktop host (Dell PowerEdge R650) VdiServer running Windows Server 2022
Observed: 08/06/2026 19:20
Partially evidenced. Review before confirming. Some operating systems in A2.7 could not be lifecycle-validated from endoflife.date cycles: 3 Dell PowerEdge R740 ESXi host devices running VMware ESXi 8.0 Update 2.
A2.8
Please list the quantities of tablets and mobile devices within the scope of this assessment.
Present in: Danzel 3.3
NonCompliant
Out-of-support operating systems detected via endoflife.date for A2.8: 28 Apple iPhone 14 devices running iOS 17.5 (installed iOS cycle 17 is out of support; supported version should be 26.6).
9 Samsung Galaxy Tab Active4 Pro tablets running Android 14; 28 Apple iPhone 14 mobile devices running iOS 17.5
Show evidence items (2)
Device Inventory: NonCompliant
Entity: Samsung Galaxy Tab Active4 Pro
9 Samsung Galaxy Tab Active4 Pro Tablet running Android 14
Observed: 08/06/2026 19:20
Device Inventory: NonCompliant
Entity: Apple iPhone 14
28 Apple iPhone 14 MobileDevice running iOS 17.5
Observed: 08/06/2026 19:20
Likely No based on current evidence. Out-of-support operating systems detected via endoflife.date for A2.8: 28 Apple iPhone 14 devices running iOS 17.5 (installed iOS cycle 17 is out of support; supported version should be 26.6).
A3.1
Please confirm the security update process for in-scope systems and who owns it.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A3.2
Please confirm the vulnerability management process for in-scope systems and services.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A3.3
Please confirm the incident response/escalation process for security events in scope.
Present in: Danzel 3.3
Unknown
Manual response required. Supporting records can be corroborated from HaloPSA, M365, NinjaOne where available.
No direct mapped evidence yet. Supporting records may be available from HaloPSA, M365, NinjaOne.
Provide a manual answer and attach notes. Corroborate with HaloPSA, M365, NinjaOne where possible.
A4.1
Do you have firewalls at the boundaries between your organisation's internal networks, laptops, desktops, servers, and the internet?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
2 evidence item(s): M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Compliant
Entity: Device Group: Tycho Engineering Endpoints
Reason: All sampled endpoints report host firewall enabled and locked by policy.
Demo (The Expanse): 100% of Tycho engineering endpoints report host firewall enabled across domain/private/public profiles.
Observed: 08/06/2026 19:06
Ref: demo://expanse/ninjaone/firewall-baseline-tycho
M365-Intune-Demo: Compliant
Entity: Intune Device Compliance: Tycho Engineering
Reason: All targeted Windows devices report firewall enabled across domain, private, and public profiles.
Demo (The Expanse): Intune compliance reports confirm host firewall policy is enforced tenant-wide for Tycho engineering devices.
Observed: 08/06/2026 19:01
Ref: demo://expanse/m365/intune-firewall-compliance
Likely Yes based on current evidence. Verified configuration evidence from M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A4.1.1
Do you have software firewalls enabled on all of your computers, laptops and servers?
Present in: Danzel 3.3
Partial
Evidence from M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
2 evidence item(s): M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Compliant
Entity: Device Group: Tycho Engineering Endpoints
Reason: All sampled endpoints report host firewall enabled and locked by policy.
Demo (The Expanse): 100% of Tycho engineering endpoints report host firewall enabled across domain/private/public profiles.
Observed: 08/06/2026 19:06
Ref: demo://expanse/ninjaone/firewall-baseline-tycho
M365-Intune-Demo: Compliant
Entity: Intune Device Compliance: Tycho Engineering
Reason: All targeted Windows devices report firewall enabled across domain, private, and public profiles.
Demo (The Expanse): Intune compliance reports confirm host firewall policy is enforced tenant-wide for Tycho engineering devices.
Observed: 08/06/2026 19:01
Ref: demo://expanse/m365/intune-firewall-compliance
Partially evidenced. Review before confirming. Evidence from M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A4.1.2
If you answered no to question A4.1.1, is this because software firewalls are not installed by default as part of the operating system you are using?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from M365-Intune-Demo, NinjaOne-Demo for this control; manual verification is recommended.
2 evidence item(s): M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Compliant
Entity: Device Group: Tycho Engineering Endpoints
Reason: All sampled endpoints report host firewall enabled and locked by policy.
Demo (The Expanse): 100% of Tycho engineering endpoints report host firewall enabled across domain/private/public profiles.
Observed: 08/06/2026 19:06
Ref: demo://expanse/ninjaone/firewall-baseline-tycho
M365-Intune-Demo: Compliant
Entity: Intune Device Compliance: Tycho Engineering
Reason: All targeted Windows devices report firewall enabled across domain, private, and public profiles.
Demo (The Expanse): Intune compliance reports confirm host firewall policy is enforced tenant-wide for Tycho engineering devices.
Observed: 08/06/2026 19:01
Ref: demo://expanse/m365/intune-firewall-compliance
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from M365-Intune-Demo, NinjaOne-Demo for this control; manual verification is recommended.
A4.2
When you first receive an internet router or hardware firewall device, it may have had a default password on it. Have you changed all the default passwords on your boundary firewall devices?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
2 evidence item(s): M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Compliant
Entity: Device Group: Tycho Engineering Endpoints
Reason: All sampled endpoints report host firewall enabled and locked by policy.
Demo (The Expanse): 100% of Tycho engineering endpoints report host firewall enabled across domain/private/public profiles.
Observed: 08/06/2026 19:06
Ref: demo://expanse/ninjaone/firewall-baseline-tycho
M365-Intune-Demo: Compliant
Entity: Intune Device Compliance: Tycho Engineering
Reason: All targeted Windows devices report firewall enabled across domain, private, and public profiles.
Demo (The Expanse): Intune compliance reports confirm host firewall policy is enforced tenant-wide for Tycho engineering devices.
Observed: 08/06/2026 19:01
Ref: demo://expanse/m365/intune-firewall-compliance
Likely Yes based on current evidence. Verified configuration evidence from M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A4.2.1
Please describe the process for changing your firewall password.
Present in: Danzel 3.3
Partial
Evidence from M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
2 evidence item(s): M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Compliant
Entity: Device Group: Tycho Engineering Endpoints
Reason: All sampled endpoints report host firewall enabled and locked by policy.
Demo (The Expanse): 100% of Tycho engineering endpoints report host firewall enabled across domain/private/public profiles.
Observed: 08/06/2026 19:06
Ref: demo://expanse/ninjaone/firewall-baseline-tycho
M365-Intune-Demo: Compliant
Entity: Intune Device Compliance: Tycho Engineering
Reason: All targeted Windows devices report firewall enabled across domain, private, and public profiles.
Demo (The Expanse): Intune compliance reports confirm host firewall policy is enforced tenant-wide for Tycho engineering devices.
Observed: 08/06/2026 19:01
Ref: demo://expanse/m365/intune-firewall-compliance
Partially evidenced. Review before confirming. Evidence from M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A4.3
How is your firewall password configured?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from M365-Intune-Demo, NinjaOne-Demo for this control; manual verification is recommended.
2 evidence item(s): M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Compliant
Entity: Device Group: Tycho Engineering Endpoints
Reason: All sampled endpoints report host firewall enabled and locked by policy.
Demo (The Expanse): 100% of Tycho engineering endpoints report host firewall enabled across domain/private/public profiles.
Observed: 08/06/2026 19:06
Ref: demo://expanse/ninjaone/firewall-baseline-tycho
M365-Intune-Demo: Compliant
Entity: Intune Device Compliance: Tycho Engineering
Reason: All targeted Windows devices report firewall enabled across domain, private, and public profiles.
Demo (The Expanse): Intune compliance reports confirm host firewall policy is enforced tenant-wide for Tycho engineering devices.
Observed: 08/06/2026 19:01
Ref: demo://expanse/m365/intune-firewall-compliance
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from M365-Intune-Demo, NinjaOne-Demo for this control; manual verification is recommended.
A4.4
Do you change your firewall password when you know or suspect it has been compromised?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
2 evidence item(s): M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Compliant
Entity: Device Group: Tycho Engineering Endpoints
Reason: All sampled endpoints report host firewall enabled and locked by policy.
Demo (The Expanse): 100% of Tycho engineering endpoints report host firewall enabled across domain/private/public profiles.
Observed: 08/06/2026 19:06
Ref: demo://expanse/ninjaone/firewall-baseline-tycho
M365-Intune-Demo: Compliant
Entity: Intune Device Compliance: Tycho Engineering
Reason: All targeted Windows devices report firewall enabled across domain, private, and public profiles.
Demo (The Expanse): Intune compliance reports confirm host firewall policy is enforced tenant-wide for Tycho engineering devices.
Observed: 08/06/2026 19:01
Ref: demo://expanse/m365/intune-firewall-compliance
Likely Yes based on current evidence. Verified configuration evidence from M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A4.5
Do you have a process to manage your firewall?
Present in: Danzel 3.3
Partial
Evidence from M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
2 evidence item(s): M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Compliant
Entity: Device Group: Tycho Engineering Endpoints
Reason: All sampled endpoints report host firewall enabled and locked by policy.
Demo (The Expanse): 100% of Tycho engineering endpoints report host firewall enabled across domain/private/public profiles.
Observed: 08/06/2026 19:06
Ref: demo://expanse/ninjaone/firewall-baseline-tycho
M365-Intune-Demo: Compliant
Entity: Intune Device Compliance: Tycho Engineering
Reason: All targeted Windows devices report firewall enabled across domain, private, and public profiles.
Demo (The Expanse): Intune compliance reports confirm host firewall policy is enforced tenant-wide for Tycho engineering devices.
Observed: 08/06/2026 19:01
Ref: demo://expanse/m365/intune-firewall-compliance
Partially evidenced. Review before confirming. Evidence from M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A4.6
Have you reviewed your firewall rules in the last 12 months?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from M365-Intune-Demo, NinjaOne-Demo for this control; manual verification is recommended.
2 evidence item(s): M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Compliant
Entity: Device Group: Tycho Engineering Endpoints
Reason: All sampled endpoints report host firewall enabled and locked by policy.
Demo (The Expanse): 100% of Tycho engineering endpoints report host firewall enabled across domain/private/public profiles.
Observed: 08/06/2026 19:06
Ref: demo://expanse/ninjaone/firewall-baseline-tycho
M365-Intune-Demo: Compliant
Entity: Intune Device Compliance: Tycho Engineering
Reason: All targeted Windows devices report firewall enabled across domain, private, and public profiles.
Demo (The Expanse): Intune compliance reports confirm host firewall policy is enforced tenant-wide for Tycho engineering devices.
Observed: 08/06/2026 19:01
Ref: demo://expanse/m365/intune-firewall-compliance
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from M365-Intune-Demo, NinjaOne-Demo for this control; manual verification is recommended.
A4.7
Are host firewalls enabled and configured to block unauthorized inbound network connections on supported endpoints?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
2 evidence item(s): M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Compliant
Entity: Device Group: Tycho Engineering Endpoints
Reason: All sampled endpoints report host firewall enabled and locked by policy.
Demo (The Expanse): 100% of Tycho engineering endpoints report host firewall enabled across domain/private/public profiles.
Observed: 08/06/2026 19:06
Ref: demo://expanse/ninjaone/firewall-baseline-tycho
M365-Intune-Demo: Compliant
Entity: Intune Device Compliance: Tycho Engineering
Reason: All targeted Windows devices report firewall enabled across domain, private, and public profiles.
Demo (The Expanse): Intune compliance reports confirm host firewall policy is enforced tenant-wide for Tycho engineering devices.
Observed: 08/06/2026 19:01
Ref: demo://expanse/m365/intune-firewall-compliance
Likely Yes based on current evidence. Verified configuration evidence from M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A4.8
Please describe how you approve and document your allowed inbound connections.
Present in: Danzel 3.3
Partial
Evidence from M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
2 evidence item(s): M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Compliant
Entity: Device Group: Tycho Engineering Endpoints
Reason: All sampled endpoints report host firewall enabled and locked by policy.
Demo (The Expanse): 100% of Tycho engineering endpoints report host firewall enabled across domain/private/public profiles.
Observed: 08/06/2026 19:06
Ref: demo://expanse/ninjaone/firewall-baseline-tycho
M365-Intune-Demo: Compliant
Entity: Intune Device Compliance: Tycho Engineering
Reason: All targeted Windows devices report firewall enabled across domain, private, and public profiles.
Demo (The Expanse): Intune compliance reports confirm host firewall policy is enforced tenant-wide for Tycho engineering devices.
Observed: 08/06/2026 19:01
Ref: demo://expanse/m365/intune-firewall-compliance
Partially evidenced. Review before confirming. Evidence from M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A4.9
Are your boundary firewalls configured to allow access to their configuration settings over the internet?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from M365-Intune-Demo, NinjaOne-Demo for this control; manual verification is recommended.
2 evidence item(s): M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Compliant
Entity: Device Group: Tycho Engineering Endpoints
Reason: All sampled endpoints report host firewall enabled and locked by policy.
Demo (The Expanse): 100% of Tycho engineering endpoints report host firewall enabled across domain/private/public profiles.
Observed: 08/06/2026 19:06
Ref: demo://expanse/ninjaone/firewall-baseline-tycho
M365-Intune-Demo: Compliant
Entity: Intune Device Compliance: Tycho Engineering
Reason: All targeted Windows devices report firewall enabled across domain, private, and public profiles.
Demo (The Expanse): Intune compliance reports confirm host firewall policy is enforced tenant-wide for Tycho engineering devices.
Observed: 08/06/2026 19:01
Ref: demo://expanse/m365/intune-firewall-compliance
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from M365-Intune-Demo, NinjaOne-Demo for this control; manual verification is recommended.
A4.10
If you answered yes in question A4.9, is there a documented business requirement for this access?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
2 evidence item(s): M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Compliant
Entity: Device Group: Tycho Engineering Endpoints
Reason: All sampled endpoints report host firewall enabled and locked by policy.
Demo (The Expanse): 100% of Tycho engineering endpoints report host firewall enabled across domain/private/public profiles.
Observed: 08/06/2026 19:06
Ref: demo://expanse/ninjaone/firewall-baseline-tycho
M365-Intune-Demo: Compliant
Entity: Intune Device Compliance: Tycho Engineering
Reason: All targeted Windows devices report firewall enabled across domain, private, and public profiles.
Demo (The Expanse): Intune compliance reports confirm host firewall policy is enforced tenant-wide for Tycho engineering devices.
Observed: 08/06/2026 19:01
Ref: demo://expanse/m365/intune-firewall-compliance
Likely Yes based on current evidence. Verified configuration evidence from M365-Intune-Demo, NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A4.11
If you answered yes in question A4.9, is the access to your firewall settings protected by either multi-factor authentication or by only allowing trusted IP addresses combined with managed authentication to access the settings?
Present in: Danzel 3.3
Partial
Evidence from M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
2 evidence item(s): M365-Intune-Demo (1), NinjaOne-Demo (1).
Show evidence items (2)
NinjaOne-Demo: Compliant
Entity: Device Group: Tycho Engineering Endpoints
Reason: All sampled endpoints report host firewall enabled and locked by policy.
Demo (The Expanse): 100% of Tycho engineering endpoints report host firewall enabled across domain/private/public profiles.
Observed: 08/06/2026 19:06
Ref: demo://expanse/ninjaone/firewall-baseline-tycho
M365-Intune-Demo: Compliant
Entity: Intune Device Compliance: Tycho Engineering
Reason: All targeted Windows devices report firewall enabled across domain, private, and public profiles.
Demo (The Expanse): Intune compliance reports confirm host firewall policy is enforced tenant-wide for Tycho engineering devices.
Observed: 08/06/2026 19:01
Ref: demo://expanse/m365/intune-firewall-compliance
Partially evidenced. Review before confirming. Evidence from M365-Intune-Demo, NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A5.1
Is unnecessary or unauthorized software identified and remediated in line with policy?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
No direct evidence items are currently mapped to this question.
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
A5.2
Are systems and identities configured to an approved secure baseline with unnecessary features disabled?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Compliant
Entity: Device Policies: Tycho Workstations
Reason: No baseline drift detected against hardened workstation policy set.
Demo (The Expanse): Tycho workstation hardening baseline remains aligned with approved secure configuration profile.
Observed: 08/06/2026 19:04
Ref: demo://expanse/ninjaone/secure-configuration-baseline
Likely Yes based on current evidence. Verified configuration evidence from NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A5.3
Have you changed the default password for all user and administrator accounts on all your desktop computers, laptops, thin clients, servers, tablets and mobile phones?
Present in: Danzel 3.3
Partial
Evidence from NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Compliant
Entity: Device Policies: Tycho Workstations
Reason: No baseline drift detected against hardened workstation policy set.
Demo (The Expanse): Tycho workstation hardening baseline remains aligned with approved secure configuration profile.
Observed: 08/06/2026 19:04
Ref: demo://expanse/ninjaone/secure-configuration-baseline
Partially evidenced. Review before confirming. Evidence from NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A5.4
Do you run or host external services that provide access to data (that should not be made public) to users across the internet?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from NinjaOne-Demo for this control; manual verification is recommended.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Compliant
Entity: Device Policies: Tycho Workstations
Reason: No baseline drift detected against hardened workstation policy set.
Demo (The Expanse): Tycho workstation hardening baseline remains aligned with approved secure configuration profile.
Observed: 08/06/2026 19:04
Ref: demo://expanse/ninjaone/secure-configuration-baseline
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from NinjaOne-Demo for this control; manual verification is recommended.
A5.5
If yes to question A5.4, which authentication option do you use?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Compliant
Entity: Device Policies: Tycho Workstations
Reason: No baseline drift detected against hardened workstation policy set.
Demo (The Expanse): Tycho workstation hardening baseline remains aligned with approved secure configuration profile.
Observed: 08/06/2026 19:04
Ref: demo://expanse/ninjaone/secure-configuration-baseline
Likely Yes based on current evidence. Verified configuration evidence from NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A5.6
Describe the process in place for changing passwords on your external services when you believe they have been compromised.
Present in: Danzel 3.3
Partial
Evidence from NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Compliant
Entity: Device Policies: Tycho Workstations
Reason: No baseline drift detected against hardened workstation policy set.
Demo (The Expanse): Tycho workstation hardening baseline remains aligned with approved secure configuration profile.
Observed: 08/06/2026 19:04
Ref: demo://expanse/ninjaone/secure-configuration-baseline
Partially evidenced. Review before confirming. Evidence from NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A5.7
When not using multi-factor authentication, which option are you using to protect your external service from brute force attacks?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from NinjaOne-Demo for this control; manual verification is recommended.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Compliant
Entity: Device Policies: Tycho Workstations
Reason: No baseline drift detected against hardened workstation policy set.
Demo (The Expanse): Tycho workstation hardening baseline remains aligned with approved secure configuration profile.
Observed: 08/06/2026 19:04
Ref: demo://expanse/ninjaone/secure-configuration-baseline
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from NinjaOne-Demo for this control; manual verification is recommended.
A5.8
Have you disabled any feature which allows automatic file execution of downloaded or imported files without user authorisation?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Compliant
Entity: Device Policies: Tycho Workstations
Reason: No baseline drift detected against hardened workstation policy set.
Demo (The Expanse): Tycho workstation hardening baseline remains aligned with approved secure configuration profile.
Observed: 08/06/2026 19:04
Ref: demo://expanse/ninjaone/secure-configuration-baseline
Likely Yes based on current evidence. Verified configuration evidence from NinjaOne-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A5.9
When a device requires a user to be present, do you set a locking mechanism on your devices to access the software and services installed?
Present in: Danzel 3.3
Partial
Evidence from NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
1 evidence item(s): NinjaOne-Demo (1).
Show evidence items (1)
NinjaOne-Demo: Compliant
Entity: Device Policies: Tycho Workstations
Reason: No baseline drift detected against hardened workstation policy set.
Demo (The Expanse): Tycho workstation hardening baseline remains aligned with approved secure configuration profile.
Observed: 08/06/2026 19:04
Ref: demo://expanse/ninjaone/secure-configuration-baseline
Partially evidenced. Review before confirming. Evidence from NinjaOne-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A5.10
Which method do you use to unlock the devices?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
No direct evidence items are currently mapped to this question.
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
A6.1
Are all operating systems on your devices supported by a vendor that produces regular security updates and vulnerability fixes?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
No direct evidence items are currently mapped to this question.
Likely Yes based on current evidence. Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A6.2
Is all the software on your devices supported by a supplier that produces regular vulnerability fixes for any security problems?
Present in: Danzel 3.3
Partial
Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
No direct evidence items are currently mapped to this question.
Partially evidenced. Review before confirming. Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A6.2.1
Please list your internet browser(s).
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
No direct evidence items are currently mapped to this question.
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
A6.2.2
Please list your malware protection software.
Present in: Danzel 3.3
Compliant
Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
No direct evidence items are currently mapped to this question.
Likely Yes based on current evidence. Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A6.2.3
Please list your email applications installed on end user devices and servers.
Present in: Danzel 3.3
Partial
Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
No direct evidence items are currently mapped to this question.
Partially evidenced. Review before confirming. Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A6.2.4
Please list all office applications that are used to create organisational data.
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
No direct evidence items are currently mapped to this question.
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
A6.3
Are any of the in-scope software or cloud services unlicensed or unsupported?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from HaloPSA-Demo, M365-Intune-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
2 evidence item(s): HaloPSA-Demo (1), M365-Intune-Demo (1).
Show evidence items (2)
M365-Intune-Demo: Compliant
Entity: Intune Endpoint Analytics: Software Lifecycle
Reason: No end-of-life software titles remain on in-scope endpoint inventory.
Demo (The Expanse): Intune software inventory and remediation tasks show all EOL packages removed from Tycho managed endpoints.
Observed: 08/06/2026 17:59
Ref: demo://expanse/m365/intune-eol-software
HaloPSA-Demo: Compliant
Entity: Change Window: Luna Command
Reason: All remediation tickets were closed with approval and owner sign-off.
Demo (The Expanse): Luna command image rollouts completed within emergency patch window.
Observed: 08/06/2026 17:48
Ref: demo://expanse/halopsa/luna-emergency-rollout
Likely Yes based on current evidence. Verified configuration evidence from HaloPSA-Demo, M365-Intune-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A6.3.1/A6.6/A6.7
Is unsupported or end-of-life software identified and remediated with accountable ownership?
Present in: Danzel 3.3
Partial
Evidence from HaloPSA-Demo, M365-Intune-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
2 evidence item(s): HaloPSA-Demo (1), M365-Intune-Demo (1).
Show evidence items (2)
M365-Intune-Demo: Compliant
Entity: Intune Endpoint Analytics: Software Lifecycle
Reason: No end-of-life software titles remain on in-scope endpoint inventory.
Demo (The Expanse): Intune software inventory and remediation tasks show all EOL packages removed from Tycho managed endpoints.
Observed: 08/06/2026 17:59
Ref: demo://expanse/m365/intune-eol-software
HaloPSA-Demo: Compliant
Entity: Change Window: Luna Command
Reason: All remediation tickets were closed with approval and owner sign-off.
Demo (The Expanse): Luna command image rollouts completed within emergency patch window.
Observed: 08/06/2026 17:48
Ref: demo://expanse/halopsa/luna-emergency-rollout
Partially evidenced. Review before confirming. Evidence from HaloPSA-Demo, M365-Intune-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A6.4/A6.5
Are security updates applied within policy timelines for operating systems and applications?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
No direct evidence items are currently mapped to this question.
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
A6.4.1
Are all updates applied for operating systems by enabling auto updates?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
No direct evidence items are currently mapped to this question.
Likely Yes based on current evidence. Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A6.4.2
Where auto updates are not being used, how do you ensure all high-risk or critical security updates and vulnerability fixes of all operating systems and firmware on firewalls and routers are applied within 14 days of release?
Present in: Danzel 3.3
Partial
Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
No direct evidence items are currently mapped to this question.
Partially evidenced. Review before confirming. Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A6.5
Are all high-risk or critical security updates and vulnerability fixes for applications (including any associated files and extensions) installed within 14 days of release?
Present in: Danzel 3.3
Unknown
Manual response required. Corroborating records may be available from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Supporting records may be available from M365, NinjaOne, HaloPSA.
Provide a manual answer and attach notes. Corroborate with M365, NinjaOne, HaloPSA where possible.
A6.5.1
Are all updates applied on your applications by enabling auto updates?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
No direct evidence items are currently mapped to this question.
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
A6.5.2
Where auto updates are not being used, how do you ensure all high-risk or critical security updates of all applications are applied within 14 days of release?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
No direct evidence items are currently mapped to this question.
Likely Yes based on current evidence. Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A6.6
Have you removed any software installed on your devices that is no longer supported and no longer receives regular updates or vulnerability fixes for security problems?
Present in: Danzel 3.3
Unknown
Manual response required. Corroborating records may be available from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Supporting records may be available from M365, NinjaOne, HaloPSA.
Provide a manual answer and attach notes. Corroborate with M365, NinjaOne, HaloPSA where possible.
A6.7
Where you have a business need to use unsupported software, have you moved the devices and software out of scope of this assessment?
Present in: Danzel 3.3
Unknown
Manual response required. Corroborating records may be available from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Supporting records may be available from M365, NinjaOne, HaloPSA.
Provide a manual answer and attach notes. Corroborate with M365, NinjaOne, HaloPSA where possible.
A7.1
Are your users only provided with user accounts after a process has been followed to approve their creation? Describe the process.
Present in: Danzel 3.3
Partial
Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
No direct evidence items are currently mapped to this question.
Partially evidenced. Review before confirming. Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A7.2
Are all your user and administrative accounts accessed by entering unique credentials?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
No direct evidence items are currently mapped to this question.
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
A7.3
How do you ensure you have deleted, or disabled, any accounts for staff who are no longer with your organisation?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
No direct evidence items are currently mapped to this question.
Likely Yes based on current evidence. Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A7.4
Do you ensure that staff only have the access privileges that they need to do their current job? How do you do this?
Present in: Danzel 3.3
Partial
Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
No direct evidence items are currently mapped to this question.
Partially evidenced. Review before confirming. Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A7.5
Do you have a formal process for giving someone access to systems at an administrator level and can you describe this process?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
No direct evidence items are currently mapped to this question.
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
A7.6
Are administrative accounts separate from standard user accounts and used only for administrative tasks?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
No direct evidence items are currently mapped to this question.
Likely Yes based on current evidence. Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A7.7
How does your organisation prevent administrator accounts from being used to carry out everyday tasks like browsing the web or accessing email?
Present in: Danzel 3.3
Partial
Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
No direct evidence items are currently mapped to this question.
Partially evidenced. Review before confirming. Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A7.8
Do you formally track which users have administrator accounts in your organisation?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
No direct evidence items are currently mapped to this question.
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
A7.9
Do you review who should have administrative access on a regular basis?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
No direct evidence items are currently mapped to this question.
Likely Yes based on current evidence. Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A7.10
Where you have systems that require passwords (or where passwords are a backup for a passwordless system), how are they protected from brute-force attacks?
Present in: Danzel 3.3
Partial
Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
No direct evidence items are currently mapped to this question.
Partially evidenced. Review before confirming. Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A7.11
Which technical controls are used to manage the quality of your passwords within your organisation?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
No direct evidence items are currently mapped to this question.
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
A7.12
Please explain how you encourage people to use unique and strong passwords.
Present in: Danzel 3.3
Compliant
Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
No direct evidence items are currently mapped to this question.
Likely Yes based on current evidence. Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A7.13
Do you have a process for when you believe the passwords or accounts have been compromised?
Present in: Danzel 3.3
Partial
Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
No direct evidence items are currently mapped to this question.
Partially evidenced. Review before confirming. Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A7.14
Is multi-factor authentication enforced for privileged users and cloud service access?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from M365-Demo for this control; manual verification is recommended.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Compliant
Entity: Tenant: Tycho Station
Reason: All privileged role sign-ins required MFA in the last reporting period.
Demo (The Expanse): Tycho Station admin enclave enforces MFA on all privileged identities.
Observed: 08/06/2026 18:52
Ref: demo://expanse/m365/tycho-admin-mfa
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from M365-Demo for this control; manual verification is recommended.
A7.15
If you have answered no to question A7.14, please provide a list of your cloud services that do not provide any option for MFA.
Present in: Danzel 3.3
Compliant
Verified configuration evidence from M365-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Compliant
Entity: Tenant: Tycho Station
Reason: All privileged role sign-ins required MFA in the last reporting period.
Demo (The Expanse): Tycho Station admin enclave enforces MFA on all privileged identities.
Observed: 08/06/2026 18:52
Ref: demo://expanse/m365/tycho-admin-mfa
Likely Yes based on current evidence. Verified configuration evidence from M365-Demo confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A7.16
Has MFA been applied to all administrators of your cloud services, excluding any listed in A7.15 that do not provide it?
Present in: Danzel 3.3
Partial
Evidence from M365-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Compliant
Entity: Tenant: Tycho Station
Reason: All privileged role sign-ins required MFA in the last reporting period.
Demo (The Expanse): Tycho Station admin enclave enforces MFA on all privileged identities.
Observed: 08/06/2026 18:52
Ref: demo://expanse/m365/tycho-admin-mfa
Partially evidenced. Review before confirming. Evidence from M365-Demo shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A7.17
Has MFA been applied to all users of your cloud services, excluding any listed in A7.15 that do not provide it?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from M365-Demo for this control; manual verification is recommended.
1 evidence item(s): M365-Demo (1).
Show evidence items (1)
M365-Demo: Compliant
Entity: Tenant: Tycho Station
Reason: All privileged role sign-ins required MFA in the last reporting period.
Demo (The Expanse): Tycho Station admin enclave enforces MFA on all privileged identities.
Observed: 08/06/2026 18:52
Ref: demo://expanse/m365/tycho-admin-mfa
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from M365-Demo for this control; manual verification is recommended.
A8.1
Is anti-malware protection enabled on supported devices with current signatures and active monitoring?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
No direct evidence items are currently mapped to this question.
Likely Yes based on current evidence. Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
A8.2/A8.3
Are malware detections investigated and resolved through a documented incident workflow?
Present in: Danzel 3.3
Partial
Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
No direct evidence items are currently mapped to this question.
Partially evidenced. Review before confirming. Evidence from the connected data sources shows this control is partially in place: some configuration is correct, but gaps remain before the requirement is fully met.
A8.3
If Option A has been selected: where you have anti-malware software installed, is it set to scan web pages you visit and warn you about accessing malicious websites?
Present in: Danzel 3.3
Unknown
Manual response required. Corroborating records may be available from M365, NinjaOne, HaloPSA.
No direct mapped evidence yet. Supporting records may be available from M365, NinjaOne, HaloPSA.
Provide a manual answer and attach notes. Corroborate with M365, NinjaOne, HaloPSA where possible.
A8.4
If Option B has been selected: where you use an app-store or application signing, are users restricted from installing unsigned applications?
Present in: Danzel 3.3
Unknown
No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
No direct evidence items are currently mapped to this question.
Insufficient evidence for an automatic answer. No conclusive evidence has been returned from the connected data sources for this control; manual verification is recommended.
A8.5
If Option B has been selected: where you use an app-store or application signing, do you ensure users only install applications approved by your organisation and maintain that approved list?
Present in: Danzel 3.3
Compliant
Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
No direct evidence items are currently mapped to this question.
Likely Yes based on current evidence. Verified configuration evidence from the connected data sources confirms this control is fully implemented, with no outstanding non-conformities from the latest assessment cycle.
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.