This is a sample report. “Lakeside Community Services” is a fictional non-profit — every excerpt below is invented. This is exactly what you see after uploading your own policies: explore the tabs, click any control to read the evidence behind its rating.

Compliance alignment report — Lakeside Community Services

9 documents analyzed · NIST CSF 2.0 + HIPAA, AI-governance & education lenses

45.3%

NIST CSF 2.0 coverage

38 covered · 20 partial · 48 not found, across 106 subcategories

GovernStrategy, roles, and risk management

CoveredGV.OC-01Define the organization's mission and how cybersecurity supports it

Source — a document your team uploaded

  • Lakeside-Data-Governance-Memo.pdfanalyzed July 2, 2026 · latest assessment

    Lakeside's mission is to provide accessible counseling, housing assistance, and youth programs. Protecting the personal information families share with us is essential to that mission, and this memo describes how we secure the systems our programs depend on.

CoveredGV.OC-02Identify stakeholders and their cybersecurity-related expectations

Source — a document your team uploaded

  • Lakeside-Data-Governance-Memo.pdfanalyzed July 2, 2026 · latest assessment

    Our board, county contract officers, grant funders, and the families we serve each expect client records to be handled confidentially. The Operations Director maintains the list of these expectations and reviews it with the board each January.

CoveredGV.OC-03Identify legal, regulatory, and contractual cybersecurity requirements

Source — a document your team uploaded

  • Lakeside-Data-Governance-Memo.pdfanalyzed July 2, 2026 · latest assessment

    Lakeside is subject to HIPAA for its counseling program, state data-breach notification law, and the data-privacy terms in our county service contracts. The Operations Director reviews this list annually.

CoveredGV.RM-01Establish a written risk management policy approved by leadership

Source — a document your team uploaded

  • Lakeside-Risk-Assessment-2025.pdfanalyzed July 2, 2026 · latest assessment

    The board adopted this risk management policy in January 2025. It defines how Lakeside identifies, scores, and responds to risks to client data and program operations.

CoveredGV.RM-02Define risk tolerance levels — acceptable vs. unacceptable risk

Source — a document your team uploaded

  • Lakeside-Risk-Assessment-2025.pdfanalyzed July 2, 2026 · latest assessment

    Risks rated High must be remediated or formally accepted in writing by the Executive Director within 30 days. Medium risks are reviewed quarterly; Low risks are accepted by default and revisited annually.

CoveredGV.RM-03Conduct annual risk assessments

Source — a document your team uploaded

  • Lakeside-Risk-Assessment-2025.pdfanalyzed July 2, 2026 · latest assessment

    Lakeside conducts a risk assessment each fall, facilitated by the IT coordinator with program managers. Results are presented at the November board meeting.

MissingGV.RR-01Assign a designated cybersecurity lead or Information System Security Officer (ISSO)

No policy language found — .

CoveredGV.RR-02Document cybersecurity roles and responsibilities for all staff

Source — a document your team uploaded

  • Lakeside-Employee-Handbook.docxanalyzed July 2, 2026 · latest assessment

    Every job description includes the employee's data-protection responsibilities, and each new hire signs the confidentiality and acceptable-use acknowledgment before receiving system access.

▸ Extended controls (23 — 7 covered, 5 partial)
CoveredGV.OC-04Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated

Source — a document your team uploaded

  • Lakeside-Data-Governance-Memo.pdfanalyzed July 2, 2026 · latest assessment

    Our county contracts specify availability requirements for the housing hotline and data-handling duties for client referrals; these commitments are listed in Appendix A and shared with program managers.

MissingGV.OC-05Outcomes, capabilities, and services that the organization depends on are understood and communicated

No policy language found — .

MissingGV.OV-01Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction

No policy language found — .

MissingGV.OV-02The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks

No policy language found — .

MissingGV.OV-03Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed

No policy language found — .

CoveredGV.PO-01Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced

Source — a document your team uploaded

  • Lakeside-IT-Security-Policy.pdfanalyzed July 2, 2026 · latest assessment

    This policy applies to all staff, contractors, and volunteers who use Lakeside systems. It was approved by the Executive Director and adopted by the board on March 12, 2024.

PartialGV.PO-02Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission⚠ needs review

Source — a document your team uploaded

  • Lakeside-IT-Security-Policy.pdfanalyzed July 2, 2026 · latest assessment

    The IT Security Policy is reviewed every three years or when the Executive Director requests an earlier review.

    A fixed three-year review cycle with no trigger for new threats, technology changes, or incidents means the policy can drift badly out of date between reviews.

CoveredGV.RM-04Strategic direction that describes appropriate risk response options is established and communicated

Source — a document your team uploaded

  • Lakeside-Risk-Assessment-2025.pdfanalyzed July 2, 2026 · latest assessment

    For each identified risk we choose one of four responses: mitigate, accept, transfer (typically through insurance), or avoid the activity. The chosen response and its rationale are recorded in the register.

CoveredGV.RM-05Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties

Source — a document your team uploaded

  • Lakeside-Employee-Handbook.docxanalyzed July 2, 2026 · latest assessment

    Staff report security concerns to the IT coordinator directly or anonymously through the suggestion form. Vendors report issues through their contract contact, who forwards them to the Operations Director.

PartialGV.RM-06A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated⚠ needs review

Source — a document your team uploaded

  • Lakeside-Risk-Assessment-2025.pdfanalyzed July 2, 2026 · latest assessment

    Each risk is scored 1–5 for likelihood and impact, and the scores are multiplied to set the priority ranking.

    The scoring scale exists, but there are no definitions for what a 3 versus a 4 means — different reviewers will score the same risk differently.

MissingGV.RM-07Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions

No policy language found — .

MissingGV.RR-03Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies

No policy language found — .

CoveredGV.RR-04Cybersecurity is included in human resources practices

Source — a document your team uploaded

  • Lakeside-Onboarding-Checklist.docxanalyzed July 2, 2026 · latest assessment

    Hiring includes a background check for roles with access to client records. Onboarding covers the security-awareness module, and the offboarding checklist mirrors it: access removal, equipment return, and exit acknowledgment.

MissingGV.SC-01A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders

No policy language found — .

PartialGV.SC-02Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally⚠ needs review

Source — a document your team uploaded

  • Lakeside-Vendor-Management-Policy.docxanalyzed July 2, 2026 · latest assessment

    Each vendor contract names a Lakeside contract owner responsible for the relationship.

    Contract owners are named, but their security responsibilities aren't defined — nobody is explicitly accountable for reviewing a vendor's security posture.

MissingGV.SC-03Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes

No policy language found — .

CoveredGV.SC-04Suppliers are known and prioritized by criticality

Source — a document your team uploaded

  • Lakeside-Vendor-Management-Policy.docxanalyzed July 2, 2026 · latest assessment

    Appendix B lists all active vendors ranked by criticality: Tier 1 (case-management system, payroll, cloud email) receives annual review; Tier 2 is reviewed at renewal.

CoveredGV.SC-05Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties

Source — a document your team uploaded

  • Lakeside-Vendor-Management-Policy.docxanalyzed July 2, 2026 · latest assessment

    All new contracts involving client data must include our standard data-protection addendum: breach notification within 72 hours, encryption of Lakeside data, and return or destruction of data at contract end.

PartialGV.SC-06Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships⚠ needs review

Source — a document your team uploaded

  • Lakeside-Vendor-Management-Policy.docxanalyzed July 2, 2026 · latest assessment

    Before signing with a new vendor, the contract owner completes the vendor security questionnaire for contracts over $10,000.

    Due diligence applies only above a $10,000 threshold — smaller tools (including free ones) can reach client data with no review at all.

PartialGV.SC-07The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship⚠ needs review

Source — a document your team uploaded

  • Lakeside-Vendor-Management-Policy.docxanalyzed July 2, 2026 · latest assessment

    Tier 1 vendors are reviewed annually against their questionnaire responses.

    Reviews check last year's answers rather than current evidence, and Tier 2 vendors are never re-assessed after signing.

MissingGV.SC-08Relevant suppliers and other third parties are included in incident planning, response, and recovery activities

No policy language found — .

MissingGV.SC-09Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle

No policy language found — .

MissingGV.SC-10Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement

No policy language found — .

IdentifyAssets, risks, and environment

PartialID.AM-01Maintain an inventory of all hardware assets⚠ needs review

Source — a document your team uploaded

  • Lakeside-IT-Security-Policy.pdfanalyzed July 2, 2026 · latest assessment

    The IT coordinator keeps a spreadsheet of laptops and desktops assigned to staff.

    Covers end-user devices only; the file server, network equipment, and donated hardware are not tracked anywhere.

PartialID.AM-02Maintain an inventory of all software and licensed applications⚠ needs review

Source — a document your team uploaded

  • Lakeside-IT-Security-Policy.pdfanalyzed July 2, 2026 · latest assessment

    Appendix C lists Lakeside's approved software and cloud applications. The IT coordinator updates the list as time permits.

    "As time permits" is not a maintenance commitment — an inventory that silently goes stale is close to no inventory.

CoveredID.AM-03Identify and document all data flows including where sensitive data is stored and transmitted

Source — a document your team uploaded

  • Lakeside-Data-Governance-Memo.pdfanalyzed July 2, 2026 · latest assessment

    Client records live in the case-management system; counseling notes stay within its restricted module. Donor data is in the fundraising platform, HR files in the payroll system. The data-flow diagram in Appendix B shows what moves between them and which staff roles touch each store.

CoveredID.AM-04Identify all external-facing systems and third-party services

Source — a document your team uploaded

  • Lakeside-IT-Security-Policy.pdfanalyzed July 2, 2026 · latest assessment

    Lakeside's external-facing services are: cloud email, the public website, the donor portal, the case-management system, and payroll — all vendor-hosted. No systems are hosted from the office network.

PartialID.AM-05Classify assets by criticality and data sensitivity⚠ needs review

Source — a document your team uploaded

  • Lakeside-Data-Governance-Memo.pdfanalyzed July 2, 2026 · latest assessment

    Client counseling records are classified Restricted and require the highest protections; general client records are Confidential.

    Classification exists for client data only — donor, HR, and financial data have no assigned sensitivity level.

MissingID.AM-08Systems, hardware, software, services, and data are managed throughout their life cycles

No policy language found — .

CoveredID.RA-01Identify and document cyber threats relevant to the organization

Source — a document your team uploaded

  • Lakeside-Risk-Assessment-2025.pdfanalyzed July 2, 2026 · latest assessment

    The threat list is reviewed each fall: phishing and business-email compromise, ransomware, loss or theft of a staff laptop, insider error, and a breach at one of our Tier 1 vendors.

PartialID.RA-02Identify vulnerabilities through regular scanning and assessment⚠ needs review

Source — a document your team uploaded

  • Lakeside-Risk-Assessment-2025.pdfanalyzed July 2, 2026 · latest assessment

    The IT coordinator runs a vulnerability scan of workstations when time allows, most recently in June.

    No defined schedule or scope — 'when time allows' means scanning quietly stops the moment things get busy.

CoveredID.RA-03Assess the likelihood and impact of identified risks

Source — a document your team uploaded

  • Lakeside-Risk-Assessment-2025.pdfanalyzed July 2, 2026 · latest assessment

    Each risk is assessed for likelihood and impact using the matrix in Section 4, considering both program disruption and harm to the families whose data we hold.

CoveredID.RA-04Prioritize risk responses based on impact

Source — a document your team uploaded

  • Lakeside-Risk-Assessment-2025.pdfanalyzed July 2, 2026 · latest assessment

    Remediation is prioritized by score: High risks are addressed first regardless of cost, Medium risks are weighed against budget in the quarterly review.

CoveredID.RA-05Document and maintain a risk register

Source — a document your team uploaded

  • Lakeside-Risk-Assessment-2025.pdfanalyzed July 2, 2026 · latest assessment

    The risk register in Appendix A records each risk, its score, chosen response, owner, and target date. The register is a standing item at quarterly leadership meetings.

▸ Extended controls (10 — 2 covered, 0 partial)
MissingID.AM-07Inventories of data and corresponding metadata for designated data types are maintained

No policy language found — .

MissingID.IM-01Improvements are identified from evaluations

No policy language found — .

MissingID.IM-02Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties

No policy language found — .

MissingID.IM-03Improvements are identified from execution of operational processes, procedures, and activities

No policy language found — .

CoveredID.IM-04Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved

Source — a document your team uploaded

  • Lakeside-Incident-Response-Plan.docxanalyzed July 2, 2026 · latest assessment

    This plan is reviewed annually, after every incident, and after each tabletop exercise. The most recent revision incorporated lessons from the March 2024 phishing incident.

CoveredID.RA-06Risk responses are chosen, prioritized, planned, tracked, and communicated

Source — a document your team uploaded

  • Lakeside-Risk-Assessment-2025.pdfanalyzed July 2, 2026 · latest assessment

    Every High and Medium risk has a named owner and a target date, tracked in the register and reported to the board twice a year.

MissingID.RA-07Changes and exceptions are managed, assessed for risk impact, recorded, and tracked

No policy language found — .

MissingID.RA-08Processes for receiving, analyzing, and responding to vulnerability disclosures are established

No policy language found — .

MissingID.RA-09The authenticity and integrity of hardware and software are assessed prior to acquisition and use

No policy language found — .

MissingID.RA-10Critical suppliers are assessed prior to acquisition

No policy language found — .

ProtectSafeguards that limit impact

PartialPR.AA-01Enforce Multi-Factor Authentication (MFA) for all user accounts⚠ needs review

Source — a document your team uploaded

  • Lakeside-IT-Security-Policy.pdfanalyzed July 2, 2026 · latest assessment

    Staff accessing the donor database must use two-factor authentication. Other systems require a strong password.

    MFA is required only for the donor database — email and the case-management system, which hold the most sensitive data, are explicitly excluded.

CoveredPR.AA-02Implement least-privilege access — users only have permissions they need

Source — a document your team uploaded

  • Lakeside-IT-Security-Policy.pdfanalyzed July 2, 2026 · latest assessment

    Access to client records is limited to the case managers assigned to that program. Finance systems are restricted to the finance team, and only the IT coordinator holds administrator accounts.

PartialPR.AA-03Enforce strong password policy including length, complexity, and no reuse⚠ needs review

Source — a document your team uploaded

  • Lakeside-IT-Security-Policy.pdfanalyzed July 2, 2026 · latest assessment

    Passwords must be at least 8 characters, include a number and symbol, and be changed every 90 days.

    Forced 90-day rotation with 8-character minimums reflects outdated guidance — current NIST guidance (SP 800-63B) recommends longer passphrases and rotation only on suspected compromise.

CoveredPR.AA-04Disable or remove accounts immediately upon staff departure or role change

Source — a document your team uploaded

  • Lakeside-Employee-Handbook.docxanalyzed July 2, 2026 · latest assessment

    Upon separation, IT disables all accounts and collects equipment before the end of the employee's final day. The offboarding checklist is signed by the supervisor and IT.

CoveredPR.AA-05Review user account access on a regular basis

Source — a document your team uploaded

  • Lakeside-IT-Security-Policy.pdfanalyzed July 2, 2026 · latest assessment

    Each July, supervisors review their team's access to every system against current job duties. The signed access-review log is retained by the Operations Director.

CoveredPR.AT-01Provide regular cybersecurity awareness training to all staff

Source — a document your team uploaded

  • Lakeside-Employee-Handbook.docxanalyzed July 2, 2026 · latest assessment

    All staff complete security-awareness training at hire and an annual refresher covering phishing, safe handling of client information, and how to report a suspected incident.

MissingPR.AT-02Provide advanced security training to privileged users and IT staff

No policy language found — .

PartialPR.DS-01Encrypt sensitive data at rest⚠ needs review

Source — a document your team uploaded

  • Lakeside-Data-Governance-Memo.pdfanalyzed July 2, 2026 · latest assessment

    Client files stored in the case-management system are encrypted.

    States that data is encrypted but names no method or key management — and says nothing about laptops, backups, or the file server.

CoveredPR.DS-02Encrypt sensitive data in transit using TLS/HTTPS

Source — a document your team uploaded

  • Lakeside-IT-Security-Policy.pdfanalyzed July 2, 2026 · latest assessment

    All Lakeside web services are accessed over HTTPS. The case-management vendor's security summary confirms TLS 1.2 or higher for all connections, and staff may not disable certificate warnings.

MissingPR.PS-01Enforce application allowlisting — only approved software can run

No policy language found — .

CoveredPR.PS-02Keep all systems patched and up to date

Source — a document your team uploaded

  • Lakeside-IT-Security-Policy.pdfanalyzed July 2, 2026 · latest assessment

    Staff workstations receive operating-system and browser updates automatically. The IT coordinator applies file-server updates monthly and records the date in the maintenance log.

PartialPR.PS-03Harden endpoint configurations — disable unused services and ports⚠ needs review

Source — a document your team uploaded

  • Lakeside-IT-Security-Policy.pdfanalyzed July 2, 2026 · latest assessment

    Unused services were disabled on the file server during the 2024 IT review.

    One-time hardening of a single server — there is no configuration baseline for workstations and no process to keep settings from drifting back.

CoveredPR.PS-04Deploy endpoint detection and response (EDR) or antivirus on all endpoints

Source — a document your team uploaded

  • Lakeside-IT-Security-Policy.pdfanalyzed July 2, 2026 · latest assessment

    Endpoint protection is enabled on every staff laptop and desktop. The IT coordinator verifies coverage quarterly against the device spreadsheet.

MissingPR.PS-05Implement network segmentation to isolate systems and limit lateral movement

No policy language found — .

MissingPR.PS-06Establish firewall change management — all rule changes require approval and documentation

No policy language found — .

▸ Extended controls (7 — 2 covered, 1 partial)
CoveredPR.AA-06Physical access to assets is managed, monitored, and enforced commensurate with risk

Source — a document your team uploaded

  • Lakeside-Employee-Handbook.docxanalyzed July 2, 2026 · latest assessment

    Building access requires a key fob, and the server closet stays locked with access limited to the IT coordinator and Operations Director. Visitors sign in at the front desk and are escorted in program areas.

MissingPR.DS-10The confidentiality, integrity, and availability of data-in-use are protected

No policy language found — .

PartialPR.DS-11Backups of data are created, protected, maintained, and tested⚠ needs review

Source — a document your team uploaded

  • Lakeside-Backup-Procedures.txtanalyzed July 2, 2026 · latest assessment

    Cloud backups run nightly for the file server and the case-management system export.

    Backups run, but no restore test is documented — an untested backup is a hope, not a plan.

CoveredPR.IR-01Networks and environments are protected from unauthorized logical access and usage

Source — a document your team uploaded

  • Lakeside-IT-Security-Policy.pdfanalyzed July 2, 2026 · latest assessment

    The office network sits behind a firewall managed by our IT support vendor. Guest Wi-Fi is isolated from the staff network, and remote access to the file server requires the VPN.

MissingPR.IR-02The organization's technology assets are protected from environmental threats

No policy language found — .

MissingPR.IR-03Mechanisms are implemented to achieve resilience requirements in normal and adverse situations

No policy language found — .

MissingPR.IR-04Adequate resource capacity to ensure availability is maintained

No policy language found — .

DetectFinding events in time

MissingDE.AE-02Correlate events from multiple sources to identify potential incidents

No policy language found — .

PartialDE.CM-01Monitor all endpoints for malicious activity in real time⚠ needs review

Source — a document your team uploaded

  • Lakeside-IT-Security-Policy.pdfanalyzed July 2, 2026 · latest assessment

    Endpoint-protection alerts are emailed to the IT coordinator.

    Alerts go to one inbox and are reviewed when noticed — there is no real-time monitoring and no coverage when the coordinator is out.

MissingDE.CM-02Monitor network traffic for anomalies and threats

No policy language found — .

PartialDE.CM-03Monitor and alert on failed login attempts and account lockouts⚠ needs review

Source — a document your team uploaded

  • Lakeside-IT-Security-Policy.pdfanalyzed July 2, 2026 · latest assessment

    Accounts lock after five failed sign-in attempts and require IT to unlock.

    Lockouts happen but are never logged or reviewed — a password-spraying attempt would look like a forgetful employee.

MissingDE.CM-09Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

No policy language found — .

▸ Extended controls (6)
MissingDE.AE-03Information is correlated from multiple sources

No policy language found — .

MissingDE.AE-04The estimated impact and scope of adverse events are understood

No policy language found — .

MissingDE.AE-06Information on adverse events is provided to authorized staff and tools

No policy language found — .

MissingDE.AE-07Cyber threat intelligence and other contextual information are integrated into the analysis

No policy language found — .

MissingDE.AE-08Incidents are declared when adverse events meet the defined incident criteria

No policy language found — .

MissingDE.CM-06External service provider activities and services are monitored to find potentially adverse events

No policy language found — .

RespondActing on incidents

CoveredRS.CO-02Document breach notification procedures and regulatory timelines

Source — a document your team uploaded

  • Lakeside-Incident-Response-Plan.docxanalyzed July 2, 2026 · latest assessment

    Section 6 lists our notification obligations: state breach-notification law (30 days), HIPAA breach notification for counseling records (60 days), county contract notice (72 hours), and our cyber-insurance carrier's reporting line.

CoveredRS.CO-03Establish procedures for engaging law enforcement or CISA in significant incidents

Source — a document your team uploaded

  • Lakeside-Incident-Response-Plan.docxanalyzed July 2, 2026 · latest assessment

    For incidents involving extortion, theft of client data, or suspected criminal activity, the Executive Director contacts the FBI field office or CISA using the contacts in Appendix B.

CoveredRS.MA-01Create and maintain an Incident Response Plan (IRP)

Source — a document your team uploaded

  • Lakeside-Incident-Response-Plan.docxanalyzed July 2, 2026 · latest assessment

    This plan designates the Operations Director as incident commander, lists the response team and their backups, and walks through detection, containment, notification, and recovery steps for our most likely incidents.

CoveredRS.MA-02Define incident severity levels and escalation procedures

Source — a document your team uploaded

  • Lakeside-Incident-Response-Plan.docxanalyzed July 2, 2026 · latest assessment

    Incidents are classified Severity 1–3. Severity definitions and examples are in Section 3; anything touching client counseling records is automatically Severity 1.

PartialRS.MA-03Establish an after-hours contact escalation chain for security incidents⚠ needs review

Source — a document your team uploaded

  • Lakeside-Incident-Response-Plan.docxanalyzed July 2, 2026 · latest assessment

    After hours, staff call the IT coordinator's cell phone.

    A single after-hours contact with no backup is a single point of failure — an incident during their vacation goes unanswered.

▸ Extended controls (8 — 1 covered, 1 partial)
MissingRS.AN-03Analysis is performed to establish what has taken place during an incident and the root cause of the incident

No policy language found — .

MissingRS.AN-06Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved

No policy language found — .

MissingRS.AN-07Incident data and metadata are collected, and their integrity and provenance are preserved

No policy language found — .

MissingRS.AN-08An incident's magnitude is estimated and validated

No policy language found — .

CoveredRS.MA-04Incidents are escalated or elevated as needed

Source — a document your team uploaded

  • Lakeside-Incident-Response-Plan.docxanalyzed July 2, 2026 · latest assessment

    Severity 1 and 2 incidents are escalated to the Executive Director within one hour of declaration; Severity 1 incidents also trigger board notification within 24 hours.

MissingRS.MA-05The criteria for initiating incident recovery are applied

No policy language found — .

PartialRS.MI-01Incidents are contained⚠ needs review

Source — a document your team uploaded

  • Lakeside-Incident-Response-Plan.docxanalyzed July 2, 2026 · latest assessment

    For suspected ransomware, immediately disconnect the affected machine from the network and Wi-Fi; do not power it off.

    Containment steps exist for ransomware only — no equivalent playbook for a compromised email account or a vendor breach, which are more likely.

MissingRS.MI-02Incidents are eradicated

No policy language found — .

RecoverRestoring after incidents

PartialRC.RP-01Create a Business Continuity and Disaster Recovery Plan (BCP/DRP)⚠ needs review

Source — a document your team uploaded

  • Lakeside-Backup-Procedures.txtanalyzed July 2, 2026 · latest assessment

    If the office is unavailable, staff work remotely and use paper intake forms until systems are restored.

    Two sentences of continuity notes stand in for a business continuity / disaster recovery plan — no recovery priorities, no time objectives, no assigned roles.

PartialRC.RP-02Test backup and recovery procedures at least annually⚠ needs review

Source — a document your team uploaded

  • Lakeside-Backup-Procedures.txtanalyzed July 2, 2026 · latest assessment

    Cloud backups run nightly for the file server and client-records system.

    Backups run, but no restore test is documented — the first real test of recovery would be an actual disaster.

CoveredRC.RP-03Ensure critical data is backed up regularly and stored off-site or in the cloud

Source — a document your team uploaded

  • Lakeside-Backup-Procedures.txtanalyzed July 2, 2026 · latest assessment

    Nightly backups of the file server and the case-management export are stored in the cloud, in a separate account from day-to-day systems, and retained for 30 days.

CoveredRC.RP-04Document lessons learned after any incident or recovery exercise

Source — a document your team uploaded

  • Lakeside-Incident-Response-Plan.docxanalyzed July 2, 2026 · latest assessment

    After the March 2024 phishing incident, the response team documented lessons learned; the external-sender email banner and the annual refresher module both came out of that review.

▸ Extended controls (4)
MissingRC.CO-03Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders

No policy language found — .

MissingRC.CO-04Public updates on incident recovery are shared using approved methods and messaging

No policy language found — .

MissingRC.RP-05The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed

No policy language found — .

MissingRC.RP-06The end of incident recovery is declared based on criteria, and incident-related documentation is completed

No policy language found — .

Your policies. This report. About five minutes.

Upload the documents you already have and get this same control-by-control picture for your organization — with every finding citing the exact policy language it came from.

Request early access