12 questions in this section
partialIs endpoint detection & response (EDR) deployed with central monitoring?
partialIs next-generation antivirus (NGAV) deployed on all endpoints?
partialWhat percentage of endpoints have EDR deployed?
partialDoes the Applicant use any operating system, hardware or software that is no longer supported / End-of-Life?
partialHow frequently is software updated, vulnerabilities patched, unnecessary services disabled?
partialWhat is the critical patching target (24h / 72h / 7d / >7d)?
partialIs data encrypted at rest on endpoints (laptops, desktops, portable devices)?
partialIs software installation automatically controlled and unauthorized software blocked?
attestedWhich Endpoint Detection & Response (EDR) product does the Applicant use?
partialIs endpoint security centrally managed to monitor and force signature/agent updates?
attestedIs application allow-listing enforced on critical servers to block unauthorized programs and scripts?
partialAre unnecessary or unauthorized browser extensions blocked?
Stop answering this from memory
Connect Microsoft 365, Entra ID, and Azure read-only. Insurance Posture reads the live configuration behind each application answer and shows you which ones you can prove before you sign.
Assess your posture