Harbour ITMenu

Powered by Office Sentry 2.2.0

You're in the demo. Three fictional clients with made-up people. Look around freely: nothing can be changed, and it all resets every night.Get Office Sentry
Clients/Northwind Traders

IASME Cyber Assurance

Northwind Traders · northwindtraders.onmicrosoft.com

The controls IASME Cyber Assurance asks about, theme by theme: what Microsoft 365 shows judged from the data, and the rest as text to complete. Hold Cyber Essentials first; its pack covers the technical controls.

Not ready

Northwind Traders has 6 controls to fix before applying for Cyber Assurance.

Judged from Microsoft 365 data collected ; 29 controls need evidence Microsoft 365 can't show.

No data from 12 July 2026: the oldest data held is from 6 September 2026.

Fix before you apply

6 controls
  1. Users can consent to any app. Any user can grant any app access to their mail and files.

    Fix: Set user consent to "Allow user consent for apps from verified publishers, for selected permissions" or turn it off and use the admin consent workflow. See the rows →

  2. 4 of 36 computers not encrypted. For example DESK-WRIGHT18 (leo.wright@northwindtraders.example): Windows disk isn't encrypted.

    Fix: Turn on BitLocker. See the rows →

  3. Anyone, including guests, can invite guests. Guests can invite other guests.

    Fix: Restrict guest invitations to admins and the Guest Inviter role, or at least to members, under External collaboration settings. See the rows →

  4. 4 accounts inactive for 90+ days or never used. For example hannah.robinson@northwindtraders.example: Licensed member, last signed in 7 Apr 2026.

    Fix: Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used. See the rows →

  5. Enforced by Require MFA for all users, with 1 exclusion to review. For example breakglass@northwindtraders.example: Excluded from "Require MFA for all users".

    Fix: Create a Conditional Access policy requiring MFA for all users and all cloud apps, or turn on Security Defaults if the tenant has no Entra ID P1. See the rows →

  6. 1 guest with admin roles. For example g#EXT#@northwindtraders.example: Guest holding Exchange Administrator.

    Fix: Remove admin roles from guest accounts. See the rows →

Organisation and governance

Your evidence

A named director is accountable for information security and data protection, it's on the board's agenda, and someone is given the time and skills to run it.

Your evidence
A named person accountable for security

A board member, director or partner has overall responsibility for information security and data protection, and it is a standing item at management meetings.

[Name], [role], has overall responsibility for information security and data protection and reports to [the board or partners], where security is a standing agenda item. Day-to-day IT security is managed by [IT provider].

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Security policies written, approved and reviewed

Information security policies cover the scope, set clear responsibilities, are shared with everyone they apply to, and have been reviewed and approved in the last 12 months.

Information security policies covering [acceptable use, access control, passwords, data protection and incident response] are approved by [role], reviewed every [12 months] and acknowledged by staff.

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A current risk assessment with owners and actions

A risk assessment covering the scope, reviewed in the last 12 months, names an owner and a treatment for each risk and has an action plan approved at board level.

An information security risk assessment covering [scope] names an owner for each risk, the agreed treatment and an action plan. It was last reviewed on [date] by [name and role] and approved by [director or partner].

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Cloud services and the supply chain

Fail

The cloud services that hold the organisation's data are known, where they keep it is known, and suppliers are held to security requirements.

Pass
Cloud services in use listed

The cloud services used to store and share information are listed.

  • Microsoft 365 (Microsoft 365 Business Basic, Microsoft 365 Business Premium). Cloud services connected to Microsoft 365 sign-in: Mail Sync Pro, Survey Tool, Zoom.

Microsoft 365 (Microsoft 365 Business Basic, Microsoft 365 Business Premium). Cloud services connected to Microsoft 365 sign-in: Mail Sync Pro, Survey Tool, Zoom.

What Microsoft 365 can't show: Microsoft 365 lists the apps connected to its sign-in; add services people sign in to separately.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Pass
Where cloud data is stored

The organisation knows where its cloud providers store its data.

  • Email, files and Teams data are held in Microsoft 365, in Microsoft's datacentres.

Email, files and Teams data are held in Microsoft 365, in Microsoft's datacentres.

What Microsoft 365 can't show: Judged from the tenant's country in Microsoft 365. Add every other cloud service.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
Third-party apps controlled

Users can't connect third-party apps to company data on their own, and apps with broad access are known.

Gaps
  • Users can consent to any app.
  • Any user can grant any app access to their mail and files
  • 1 app with access to mail, files or the directory.
  • Mail Sync Pro: Mail.Read (application permission; unverified publisher)
  • Any user can register an app.
  • Users can register apps that nobody reviews

Fix: Set user consent to "Allow user consent for apps from verified publishers, for selected permissions" or turn it off and use the admin consent workflow. Consent phishing relies on this setting. See the rows →

Third-party application access to Microsoft 365 data is not controlled. Users can consent to any app. 1 app with access to mail, files or the directory.

What Microsoft 365 can't show: Judged from Entra ID consent settings and app permissions.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Security requirements for suppliers

Suppliers and contractors who handle the organisation's information must meet defined security requirements, checked before they start and reviewed.

Suppliers and contractors that handle the organisation's data are checked before they're used, must meet [Cyber Essentials or equivalent security requirements], and are reviewed [every 12 months]. They're listed in [supplier register].

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Information assets

Fail

Equipment and information are listed with owners, sensitive and personal data is identified and encrypted, and data is wiped before equipment goes.

Your evidence
An asset register with named owners

Physical and information assets, including every laptop, tablet and phone, are recorded with a named owner, a category and their location.

  • But: 1 of 39 device records unused for 90+ days.
  • But: 1 of 37 joined computers not in Intune.
Computers managed by Intune
36
Of which encrypted
32
Windows computers out of support
5
Reaching end of support within 90 days
20
Not compliant
6

An asset register in [tool or spreadsheet] lists [hardware, software, cloud services and the information held], each with a named owner, a category and where it is. Devices are added when they're set up and removed when they're disposed of, and the register was last reviewed on [date].

What Microsoft 365 can't show: Microsoft 365 lists the devices Intune and Entra ID know; the register covers everything else.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
Data encrypted in the cloud, in transit and on laptops

Data is encrypted on its way to and while stored in cloud services, and on mobile devices that hold it.

  • But: 1 of 1 mail domain doesn't fully enforce MTA-STS.
Gaps
  • 4 of 36 computers not encrypted.
  • DESK-WRIGHT18 (leo.wright@northwindtraders.example): Windows disk isn't encrypted
  • LAPTOP-HUGHES (robert.hughes@northwindtraders.example): Windows disk isn't encrypted
  • LAPTOP-SCOTT29 (olivia.scott@northwindtraders.example): Windows disk isn't encrypted
  • LAPTOP-SMITH07 (olivia.smith@northwindtraders.example): Windows disk isn't encrypted

Fix: Turn on BitLocker (Windows) and FileVault (macOS) with an Intune disk encryption policy, with recovery keys escrowed to Entra ID, so a lost or stolen laptop doesn't expose the client's data. See the rows →

Data in Microsoft 365 is encrypted at rest by Microsoft (BitLocker and per-file service encryption) and in transit using TLS. Not every company computer is encrypted: 4 of 36 computers not encrypted.

What Microsoft 365 can't show: Judged from Intune for company computers; Microsoft encrypts Microsoft 365 data itself.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Removable media tracked and encrypted

USB drives and other removable media are controlled, recorded and encrypted.

Removable media is [blocked by Intune policy or allowed only on encrypted, company-issued drives], and drives that hold the organisation's data are recorded in the asset register.

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Data reviewed and deleted when no longer needed

The data held is reviewed regularly and deleted when it's no longer relevant.

A retention schedule sets how long each kind of data is kept. Data past its retention period is deleted [by Microsoft 365 retention policies or at a review every (period)], and the data held is reviewed [every 12 months] to check it's still needed.

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Data wiped before equipment is disposed of

When assets are no longer needed, data is securely wiped or the storage destroyed.

Before devices and storage are reused or disposed of, data is securely wiped [with an Intune wipe or a certified erasure tool] or the storage is destroyed by [certified disposal company], and the certificate is kept.

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Legal compliance and data protection

Your evidence

UK GDPR is met: the ICO fee is paid, someone manages data protection, personal data is recorded with its lawful basis, the privacy notice is current, rights requests are handled and processors are under contract.

Your evidence
ICO data protection fee paid

The organisation is registered with the ICO, or has recorded why it's exempt.

The organisation is registered with the Information Commissioner's Office, registration number [ZA number], renewed on [date].

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Data protection managed by a named person

A Data Protection Officer is appointed where one is required; otherwise the decision is recorded and a named person manages data protection.

[The organisation has appointed (name) as its Data Protection Officer, contactable at (email address).] or [The organisation assessed on (date) that it doesn't need a Data Protection Officer; (name, role) is responsible for data protection.]

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Personal data recorded with its lawful basis

For each kind of personal and special category data held, the purpose and lawful basis are recorded.

A record of processing activities lists each kind of personal data held, its purpose and lawful basis, who it's shared with, where it's stored and how long it's kept. [Role] maintains it, and it was last reviewed on [date].

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A current privacy notice

A privacy notice says what data is collected and why, how it's used and people's rights, and is reviewed.

A privacy notice at [web address] explains what personal data is collected, why and on what lawful basis, who it's shared with, how long it's kept, people's rights and how to complain. It was last reviewed on [date].

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
People's rights requests handled

There is a process for requests to see, correct or delete personal data, and for withdrawing consent.

Requests to see, correct or delete personal data, and complaints about how it's used, go to [contact] and are logged in [system]. They're answered within one month, and [role] checks each response before it's sent.

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Data processing agreements with suppliers

Every supplier that processes personal data has a contract with the data protection terms UK GDPR requires, including for data held outside the UK.

Every supplier that processes personal data for the organisation has a written contract with the terms UK GDPR Article 28 requires: acting only on instructions, confidentiality, security, approval of sub-processors, help with people's rights, and deleting or returning the data at the end. They're recorded in [register].

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

People

Fail

Staff are vetted, given only the access their job needs, briefed and trained, and their access goes when they leave or change role.

Your evidence
Staff checked before they get access

Everyone with access to the organisation's data is checked as suitable first.

New staff go through [right-to-work, reference and DBS] checks before they get access, and sign [confidentiality agreements].

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
Access limited to what each job needs

People only have access to the systems and data their role needs.

  • Guests have limited access to directory objects (the default).
Gaps
  • Anyone, including guests, can invite guests.
  • Guests can invite other guests

Fix: Restrict guest invitations to admins and the Guest Inviter role, or at least to members, under External collaboration settings. See the rows →

Access to files and systems is given through role-based groups, approved by [role], and changed when people move roles. [Access is reviewed every 12 months.]

What Microsoft 365 can't show: Microsoft 365 shows what guests can see and who can invite them; describe how staff access is set.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Security and data protection training

Staff and contractors are briefed on their responsibilities when they start and trained regularly.

All staff complete security awareness training [when they join and every year], through [training provider or platform]. Simulated phishing exercises run [monthly or quarterly] and the results are reviewed by [role].

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
Access removed when people leave

When people leave or change role, their access is removed or changed promptly.

  • No stale guest invitations.
Gaps
  • 4 accounts inactive for 90+ days or never used.
  • hannah.robinson@northwindtraders.example: Licensed member, last signed in 7 Apr 2026
  • sophie.smith@northwindtraders.example: Licensed member, last signed in 21 Jan 2026
  • thomas.clarke@northwindtraders.example: Licensed member, last signed in 2 Jun 2026
  • g#EXT#@northwindtraders.example: Guest, never signed in, created ?
  • 1 disabled account still licensed.
  • robert.hughes@northwindtraders.example: Disabled, holding 1 licence

Fix: Disable accounts that haven't signed in for 90 days, or were created over 30 days ago and never used (after checking with the client), then remove their licences. Inactive accounts are a common foothold for attackers. See the rows →

Some inactive accounts in Microsoft Entra ID have not been disabled. 4 accounts inactive for 90+ days or never used. 1 disabled account still licensed.

What Microsoft 365 can't show: Judged from sign-in activity in Microsoft Entra ID. Describe the leavers process in the answer.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Physical and environmental protection

Your evidence

Premises are secured, only authorised people get in, and networks are restricted to authorised devices.

Your evidence
Premises secured

Business premises in scope are physically protected, with access limited to authorised people.

Offices are protected by [locked doors, access control and alarms]. [Servers and network equipment are kept in a locked room or cabinet.]

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Preventing intrusion

Fail

Accounts are protected by MFA, sessions and devices lock, vulnerabilities are found by scanning and fixed, and malicious sites are blocked.

Fail
MFA on every cloud account

Multi-factor authentication protects every account that can reach the organisation's cloud services.

  • But: 14 users without MFA.
  • But: 3 people can only use a text or call as a second factor.
Users with an MFA method registered
62.2% of 37
Accounts covered by an enforced MFA policy
36 of 36
Gaps
  • Enforced by Require MFA for all users, with 1 exclusion to review.
  • breakglass@northwindtraders.example: Excluded from "Require MFA for all users"
  • 1 admin not covered by MFA.
  • breakglass@northwindtraders.example: Global Administrator: excluded from Require MFA for all users
  • Legacy authentication is allowed.
  • No enabled policy blocks legacy authentication for all users

Fix: Create a Conditional Access policy requiring MFA for all users and all cloud apps, or turn on Security Defaults if the tenant has no Entra ID P1. Keep exclusions to break-glass accounts. See the rows →

Multi-factor authentication (MFA) is enforced for Microsoft 365 email (including Outlook on the web and mobile) and cloud applications, through Microsoft Entra ID. Enforced by Conditional Access ("Require MFA for all users") for everyone except 1 named exclusion: breakglass@northwindtraders.example (break-glass).

What Microsoft 365 can't show: Judged for Microsoft 365 sign-ins. Add every other cloud service.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Fail
Few, separate, named administrators

Administrator access is limited to the people who need it, through separate accounts.

  • 2 Global Administrators.
  • Cloud-only tenant: no accounts are synced from on-premises AD.
  • But: 2 admins without a phishing-resistant method.
Accounts holding privileged roles
4
Admins with no MFA policy
1
Admins with no MFA method registered
2
Gaps
  • 1 guest with admin roles.
  • g#EXT#@northwindtraders.example: Guest holding Exchange Administrator
  • 1 app with privileged roles.
  • Some app: App holding Exchange Administrator

Fix: Remove admin roles from guest accounts. If an external partner needs access, use GDAP or a member account in this tenant protected by MFA. See the rows →

Administrator role assignments in Microsoft 365 are tracked, with gaps. 4 accounts hold privileged admin roles, 2 of them Global Administrator (ann.patel@northwindtraders.example, breakglass@northwindtraders.example). 2 Global Administrators. 1 guest with admin roles. 1 app with privileged roles.

What Microsoft 365 can't show: Microsoft 365 shows who holds admin roles today; add administrators of other systems.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Devices and sessions don't stay signed in

Accounts and devices lock or sign out after a period of inactivity.

Computers lock after [5 to 15] minutes of inactivity and need a password, PIN or Windows Hello to unlock. Phones and tablets need a PIN of at least 6 digits or biometrics [enforced by Intune].

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Vulnerability scans at least every six months

All systems are scanned for vulnerabilities at least every six months and after major changes, with penetration tests where the risk assessment calls for them, and the findings are fixed.

External vulnerability scans run [monthly] using [tool or provider]. [A penetration test was last carried out on (date) by (provider).]

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Malicious websites blocked

Access to malicious internet sites and domains is blocked at the boundary or on the device.

Malicious websites are blocked by [Microsoft Defender SmartScreen and network protection, a filtering DNS service such as Quad9, or the firewall's web filter].

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Backup and restore

Your evidence

Information is backed up at least weekly, kept apart and protected, with a copy somewhere else, and restores are tested.

Your evidence
Regular, separate, tested backups

All information is backed up regularly, backups are protected and kept in a different location, and restores are tested.

Microsoft 365 data (Exchange Online mail, OneDrive, SharePoint and Teams) is backed up [daily] by [backup product or provider] to storage separate from Microsoft 365. Backups are kept for [retention period], are [immutable or offline], and use credentials separate from the Microsoft 365 administrator accounts. Restores were last tested on [date].

What Microsoft 365 can't show: Microsoft 365 doesn't back itself up for this purpose; describe the backup of Microsoft 365 too.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Monitoring

Not collected

Access attempts are watched, logs are kept safe for a set time, and warnings are reviewed.

Pass
Logs and audit trails kept

Event logs and audit trails are kept securely for a defined period.

  • Mailbox auditing is on for the organisation.

Mailbox audit logging is enabled in Exchange Online, recording access to and actions on mailboxes. Mailbox auditing is on for the organisation.

What Microsoft 365 can't show: Judged from Exchange Online mailbox auditing and the unified audit log.

Change this answer

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Not collected
Sign-in attempts watched

The organisation watches who is trying to access its information and from where.

  • Not checked: no accounts are at risk in Entra ID Protection (Risky users need Entra ID P2).
  • Not checked: no risky sign-ins succeeded (Sign-in risk needs Entra ID P2).

Risky users need Entra ID P2.

Sign-ins are monitored for suspicious activity by [tool or service], and alerts are reviewed by [team or provider] [within one working day].

What Microsoft 365 can't show: Judged from Entra ID Protection (needs Entra ID P2 for the full detections).

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Warnings and reports reviewed

Security warnings and reports are reviewed regularly and security settings are rechecked.

  • But: 1 suspicious inbox rule.
  • But: 1 domain had sign-in settings changed in the last 30 days.

Security alerts and sign-in logs are reviewed [daily or weekly] by [team or provider]. Logs are kept for [period] where users can't change them.

What Microsoft 365 can't show: Microsoft 365 shows what's logged and flagged; describe who reviews it and how often.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Change management

Your evidence

Changes are planned, tested and approved, only approved software is installed, and new uses of personal data get an impact assessment first.

Your evidence
Changes approved and tested

Changes to systems, applications and networks are recorded, tested and approved before they're made.

Changes to systems, applications and networks are logged in [ticket system], checked for their security effect, tested where possible and approved by [role] before they're made. Emergency changes are reviewed afterwards.

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Only approved software installed

Computers and servers are set up only with approved software, and software nobody needs is removed.

New devices are set up from [a standard build or Windows Autopilot] without unnecessary software, and unused software and services are removed [during regular reviews by the IT provider].

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Impact assessments before high-risk processing

A data protection impact assessment is carried out before high-risk processing starts.

A data protection impact assessment is carried out before any new system or process that is likely to be high risk to people, using [the ICO's template]. [Role] signs each one off, and the ICO would be consulted if a high risk remained.

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Business continuity

Your evidence

Continuity and disaster recovery plans exist, are reviewed and tested every year, and are signed off.

Your evidence
Continuity and recovery plans tested yearly

Business impact assessments and continuity and recovery plans are in place, reviewed and tested at least once a year, and approved at board level.

A business continuity and disaster recovery plan covers [key systems and services]. Recovery targets are [time to restore] to restore service and no more than [data loss window] of data loss. It was last tested on [date].

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Incident management

Your evidence

Incidents are reported, recorded and investigated, the right outside bodies are told, and lessons are learned.

Your evidence
Incidents reported, investigated and learned from

Security incidents and suspected weaknesses are reported and recorded, investigated for their cause, and the lessons fed back, with clear roles for everyone involved.

A documented incident response plan sets out roles, contacts and the steps to contain and recover from a cyber incident, including notifying [the insurer and IT provider]. It was last reviewed on [date] and tested on [date].

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
A compromised account is contained

There is a process for when an account or password may be compromised.

If an account may be compromised, [IT provider] resets the password, signs the account out of every session, checks its MFA methods and inbox rules, and reviews its sign-ins. Staff report concerns to [contact].

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

Your evidence
Breaches reported to the ICO when required

Incidents are reported to outside bodies as required, including personal data breaches to the ICO.

Every personal data breach is recorded in a breach log with what happened, its effects and what was done. [Role] decides whether it must be reported; reportable breaches go to the ICO within 72 hours of the organisation becoming aware, and to the people affected when the risk to them is high. Lessons learned are reviewed by [role].

What Microsoft 365 can't show: All of this. Answer from the organisation's own records.

Write this answer for Northwind Traders

Saved for Northwind Traders only. It replaces the text in every scheme and question set that asks this.

What the assessor checks

The on-site tests, what each needs, and what Microsoft 365 already shows for it.

Level 2: documents and interviews

At Level 2 an auditor asks to see the evidence behind the Level 1 answers (policies, the risk assessment, the asset register, training records, the breach log) and interviews staff.

Microsoft 365 shows: Microsoft 365 can show the technical evidence on the day: the MFA, admin, logging and leavers controls on this page, with the rows behind them.

Fail MFA on every cloud accountFail Few, separate, named administratorsPass Logs and audit trails keptFail Access removed when people leave

About this pack

Cyber Essentials, or IASME Cyber Baseline, must be held before applying; use the Cyber Essentials pack for the technical controls.

The answers must be approved by a director, partner, owner or trustee before they're submitted.

Scope: Cyber Assurance covers the whole organisation or a named business unit, including paper records. A Pass here covers Microsoft 365; the answer should say what covers the rest.

Requirements: IASME Cyber Assurance, Level 1 (verified self-assessment) and Level 2 (audit). Requirements paraphrased by theme from IASME's Cyber Assurance question set. Question numbers change between versions, so match each answer to its question by wording, and check the current question set in the IASME portal before you submit. Source

Pass and Fail are judged from Microsoft 365 settings and accounts read with read-only access; accepted risks count as documented exceptions. Oldest data used: .