Submission
Maple Park PLLC
Firm metadata
- Chief Operating Officer (COO)
- coo@maple-park.example
- Pennsylvania
- 31-50 people
- m365
- current · renews 2027-02
- corporate, ip
Posture summary
Findings by control
Governance
- PARTIAL C-01 Written Information Security Program (self-reported)
- PARTIAL C-02 Periodic Risk Assessment (self-reported)
- PASS C-03 Leadership Oversight & Accountability (self-reported)
Identity & Email
- PASS C-04 Multi-Factor Authentication on Email and Identity
- PASS C-05 Privileged Access Separation
- PASS C-06 Email Security Filtering
- PASS C-07 Security Awareness Training & Phishing Simulation
Operational & Technical
- PASS C-08 Managed Endpoint Detection & Response (EDR)
- PASS C-09 Patch & Vulnerability Management
- PASS C-10 Endpoint Encryption
- PARTIAL C-11 Personal Device Access Controls
- PASS C-12 Backup Coverage
- PASS C-13 Backup Isolation & Restoration Testing
- PASS C-14 Data-at-Rest Encryption
- PASS C-15 Joiner/Mover/Leaver Process
- PASS C-16 Acceptable Use & Written Security Agreements
- PASS C-17 Documented Onboarding Security Checklist
- PARTIAL C-18 Vendor Security Due Diligence
- PARTIAL C-19 Vendor Contractual Security Requirements
- PASS C-20 Regulatory Scope Awareness
- PARTIAL C-21 Written Incident Response Plan
- PASS C-22 Continuous Security Monitoring
Material gaps
Open-text answers
Q-23 - Who handles IT and security?
In-house IT director + Microsoft Partner MSP.
Q-24 - Top cybersecurity concern
Mostly governance documentation — carrier pushed us on it.
Actions
Raw submission JSON
Expand JSON
{
"id": "33333333-3333-4333-8333-333333333333",
"submitted_at": "2026-05-18T20:18:02.000Z",
"schema_version": "1.1.0",
"crosswalk_reference": "framework-system-v2-section-2.md v1.0.2 (content v2.0)",
"email": "coo@maple-park.example",
"firm_name": "Maple Park PLLC",
"contact_name": "Chief Operating Officer",
"contact_role": "COO",
"firm_size": "large",
"state": "PA",
"practice_areas": [
"corporate",
"ip"
],
"email_platform": "m365",
"insurance_status": "current",
"insurance_renewal": "2027-02",
"answers": {
"Q-01": "all",
"Q-02": "hardware",
"Q-23": "In-house IT director + Microsoft Partner MSP.",
"Q-24": "Mostly governance documentation — carrier pushed us on it."
},
"scores_by_control": {
"C-01": "PARTIAL",
"C-02": "PARTIAL",
"C-03": "PASS",
"C-04": "PASS",
"C-05": "PASS",
"C-06": "PASS",
"C-07": "PASS",
"C-08": "PASS",
"C-09": "PASS",
"C-10": "PASS",
"C-11": "PARTIAL",
"C-12": "PASS",
"C-13": "PASS",
"C-14": "PASS",
"C-15": "PASS",
"C-16": "PASS",
"C-17": "PASS",
"C-18": "PARTIAL",
"C-19": "PARTIAL",
"C-20": "PASS",
"C-21": "PARTIAL",
"C-22": "PASS"
},
"score_counts": {
"pass": 15,
"partial": 7,
"gap": 0,
"total_scored": 22
},
"visible_questions": [],
"status": "report_sent",
"internal_notes": null,
"deleted_at": null
}