RogueLogics · Illustrative Sample · July 2026

Sample Security Evidence Pack — illustrative preview

A page-by-page preview of a finalized, insurer-audience Security Evidence Pack, rendered with fictional sample data. This is the artifact a prospect scrutinizes hardest — so it shows the honest gaps as plainly as the substantiated evidence.

Illustrative visual preview — not an export of a real generated pack. This is a page-by-page preview of the Security Evidence Pack's layout, rendered with fictional sample data. The SHA-256 value shown is an illustrative sample, not a real hash.
Security Evidence Pack
Northwind Financial
Audience: Insurer — cyber-insurance underwriting
Point-in-time: 2026-07-02 · Status: Finalized

Security Evidence Pack


Prepared for: a cyber-insurance underwriting conversation
Organization: Northwind Financial (fictional demonstration company)
Evidence sources: Microsoft 365 (read-only) · unified asset inventory
Snapshot date: 2026-07-02 · Prepared by: RogueLogics ClearTrust

13
Automated claims
Machine-collected from connectors
2
Derived claims
From the unified inventory
5
Honest gaps disclosed
Not evidenced — shown, not hidden

15 claims total · every claim shows its basis, source system, collection timestamp, and freshness band.

SHA-256 integrity hash 9b7c1e4a2f0d8c6b5a3e7f1029d4c8b6e5a2f7c9d1b0348e6f5a2c7d9b1e04a3 Sealed at finalization

This PDF was rendered once and frozen; the hash above lets a recipient confirm it has not been altered since finalization. (Illustrative sample value.)

SAMPLE — Northwind Financial is a fictional demonstration company. Data shown is sample data.Page 1 · Summary
Security Evidence Pack · Northwind Financial
Identity & MFA posture
Basis: Automated
Source: Microsoft 365

Section 1

Multi-factor authentication registration

Stated the honest way — the unregistered accounts are counted and disclosed, and the measurement method is labeled.

3 of 5 enabled users have MFA registered  ·  2 not registered  ·  0 unknown
◆ MFA Source: Per User Methods

The aggregate Microsoft Entra registration report was not available on this tenant, so each enabled user was checked individually for strong second factors (Microsoft Authenticator, FIDO2 security keys, phone, Windows Hello for Business, or software OTP). Passwords and email are never counted as a second factor. This is expected behavior on tenants without the premium registration report — not an error.

Basis
Automated
Source system
Microsoft 365
Collected
2026-07-02 08:14 UTC
Freshness
Fresh < 24h

Unknowns are reported separately and never counted as registered. On this snapshot there are zero unknowns; where a user's methods cannot be determined, that user is reported as unknown — not as covered.

SAMPLE — Northwind Financial is a fictional demonstration company. Data shown is sample data.Page 2 · Identity & MFA
Security Evidence Pack · Northwind Financial
Asset inventory
Basis: Derived / inventory
Source: Unified inventory

Section 2

Domains & email identities

Aggregate counts from the platform's unified inventory. Individual identities are not enumerated in this pack — the per-user appendix is off by default.

3
Domains
6
Email identities
Domain (fictional)RoleEmail identities
northwindfinancial.comPrimary4
nwf-pay.comSecondary1
northwind-financial.ioSecondary1

Counts are aggregate. These two inventory claims (domains; email identities) are the pack's 2 Derived claims. All domains shown are fictional and belong to the Northwind demonstration company.

SAMPLE — Northwind Financial is a fictional demonstration company. Data shown is sample data.Page 3 · Asset inventory
Security Evidence Pack · Northwind Financial
Controls substantiated by evidence
12 control claims
SOC 2 · ISO 27001 · ISO 27002

Section 3

Mapped controls (12)

Each control is substantiated by mapped Microsoft 365 evidence — meaning supporting evidence exists. A mapping is not an assertion that a control was formally tested or audited.

ControlWhat the evidence substantiatesBasisSourceCollectedFreshness
CC6.1
SOC 2
Logical access protected by strong authentication (MFA registration posture)AutoM365 · MFA posture2026-07-02< 24h
CC6.2
SOC 2
User registration & authorization tracked against the enabled-account rosterAutoM365 · user roster2026-07-02< 24h
CC6.3
SOC 2
Access aligned to the current enabled-user rosterAutoM365 · user roster2026-07-02< 24h
CC7.1
SOC 2
Security posture monitored via the Microsoft Secure Score snapshotAutoM365 · Secure Score2026-07-02< 24h
A.5.15
ISO 27001
Access control governed against the enabled-account rosterAutoM365 · user roster2026-07-02< 24h
A.5.16
ISO 27001
Identity lifecycle observed from the connected user rosterAutoM365 · user roster2026-07-02< 24h
A.5.17
ISO 27001
Authentication information strengthened by registered second factorsAutoM365 · MFA posture2026-07-02< 24h
A.8.5
ISO 27001
Secure authentication evidenced by MFA registration postureAutoM365 · MFA posture2026-07-02< 24h
5.15
ISO 27002
Access-control guidance supported by roster evidenceAutoM365 · user roster2026-07-02< 24h
5.16
ISO 27002
Identity-management guidance supported by roster evidenceAutoM365 · user roster2026-07-02< 24h
5.17
ISO 27002
Authentication-information guidance supported by MFA postureAutoM365 · MFA posture2026-07-02< 24h
8.5
ISO 27002
Secure-authentication guidance supported by MFA postureAutoM365 · MFA posture2026-07-02< 24h

"Substantiated by evidence" ≠ "tested." The pack never renders "passing" or "tested" controls — the visible Basis column shows how each mapping was evidenced. ISO 27001 Annex A and ISO 27002 share control numbering by design; both are listed to reflect how the same evidence maps across frameworks.

SAMPLE — Northwind Financial is a fictional demonstration company. Data shown is sample data.Page 4 · Controls
Security Evidence Pack · Northwind Financial
Gaps & limitations
5 gaps disclosed
with suggested remedies

Section 4

Honest gaps (5)

The credibility of the whole pack rests here. Anything the platform cannot evidence is shown as a gap — never as a pass — with a suggested next step.

SOC 2
35 of 39 controls without mapped connector evidence
Remedy: connect additional evidence sources (device/MDM, logging) and map documents to the remaining controls to raise substantiated coverage.
ISO 27001
29 of 32 controls without mapped connector evidence
Remedy: extend connector coverage and attach control documentation; ISO controls beyond identity need sources this pack does not yet collect.
PCI DSS
18 of 18 — no mapped connector evidence yet
Remedy: PCI scope requires network, logging, and cardholder-data-environment evidence not covered by the Microsoft 365 identity connector. Shown as fully unevidenced, honestly.
Coverage
No device / MDM connector — no endpoint posture collected
Remedy: connect a device / MDM source to add disk-encryption, patch-state, and endpoint-protection evidence.
Evidence
1 evidence item collected but not yet mapped to a control
Remedy: map the unmapped item to the relevant control(s) so it counts toward substantiated coverage.
Reading rule: a gap means the platform has not (or cannot yet) collect evidence for that item. It is never upgraded to a "pass" or a "control met." That is the difference between an evidence snapshot and a questionnaire filled in from memory.
SAMPLE — Northwind Financial is a fictional demonstration company. Data shown is sample data.Page 5 · Gaps
Security Evidence Pack · Northwind Financial
Disclosures & evidence sources
Point-in-time
2026-07-02

Section 5

Disclosures

The plain-language disclosures every pack ships with. Quoted here as they appear in the finalized document.

Nature of this document

"This Security Evidence Pack is a point-in-time snapshot of evidence collected from connected sources on the date shown. It is not a compliance certification, an audit, or an audit opinion. Control references are informational mappings that indicate supporting evidence exists; they do not assert that a control was formally tested."

Insurer audience

"Prepared to support a cyber-insurance underwriting conversation. It does not constitute an insurance application or a guarantee of coverage."

Connector scope

The Microsoft 365 connector is read-only. It collects the user roster, MFA registration posture, and a Microsoft Secure Score snapshot. It does not collect mailbox or email content, conditional-access policies, or security defaults, and it never writes back to the tenant.

MFA measurement

"MFA Source: Per User Methods" indicates the aggregate Entra registration report was unavailable, so each user was checked individually for strong second factors. Passwords and email are not counted as MFA.

Integrity & sharing

Finalized packs are rendered once, frozen, and fingerprinted with a SHA-256 integrity hash. Shared links expire (30-day default), are revocable, are excluded from search indexing, and every view is audit-logged.

Evidence sources consulted

CollectedMicrosoft 365 — user rosterread-only · 2026-07-02
CollectedMicrosoft 365 — MFA registration postureread-only · 2026-07-02
CollectedMicrosoft 365 — Secure Score snapshotread-only · 2026-07-02
Not connectedDevice / MDM — endpoint postureno evidence collected

Sources are recorded whether or not they returned evidence — including unavailable ones — so the reader can see exactly what was and was not consulted.

SAMPLE — Northwind Financial is a fictional demonstration company. Data shown is sample data.Page 6 · Disclosures