ClearGlass Inc. Clarity Is Power Ontario Security Quick-Audit

Methodology v1.0 · published 14 August 2026

Evidence before conclusions.

The Ontario Security Quick-Audit is a limited, read-only baseline. It identifies defensible next actions without presenting a small engagement as a certification, penetration test or guarantee.

Written authorizationScope and an authorized contact are confirmed first.
Least evidence necessaryRead-only sources are preferred; secrets are never requested.
Explicit uncertaintyObserved, supplied, inferred and not verified stay distinct.
What is the Security Quick-Audit methodology?

ClearGlass confirms authorization and scope, collects only necessary read-only evidence, compares that evidence with recognized baseline guidance, scores each supported risk using likelihood × impact, records confidence separately, and delivers prioritized actions with limitations. Missing evidence is marked “not verified” and is not converted into a pass or failure.

Assessment phases.

The sequence protects both the client and the integrity of the conclusions.

Authorize and bound the scope

Record the legal organization, authorized contact, in-scope domains or tenant, exclusions, evidence sources, permitted actions and delivery date. No testing begins from a payment alone.

Collect minimal evidence

Use passive public observations and client-supplied, read-only exports or screenshots. Do not request passwords, recovery codes, private keys, patient data, payment-card data or unrestricted administrator credentials.

Evaluate baseline controls

Review domain and email controls, Microsoft 365 identity and privileged-access evidence, and basic response-and-recovery readiness within the agreed scope.

Rate risk and confidence

Assign likelihood and impact only where evidence supports an exposure. Record the evidence source, reasoning, confidence and affected scope separately.

Prioritize and review

Recommend the smallest practical action, accountable owner, target horizon and verification evidence. Review the report with the authorized contact.

Evidence classes.

The report labels how every material statement is supported.

ClassMeaningTypical exampleHandling
ObservedVisible through an authorized passive or read-only check.Published DNS record or dated configuration export.Record source, time and relevant value.
Client-suppliedProvided by the authorized contact.Policy index, screenshot or redacted report.Identify provenance and any completeness limit.
InferredA bounded conclusion derived from evidence.A likely exposure supported by a control state.State the reasoning and confidence; never present inference as direct observation.
Not verifiedRequired evidence was unavailable or inconclusive.No restore-test record supplied.Do not score as a pass or failure; state what would verify it.

Risk and confidence.

Severity prioritizes action. Confidence communicates evidence strength. They are reported separately so uncertainty is visible.

Risk score = likelihood × impact

Likelihood and impact each use a 1–5 scale. The score guides ordering within this limited assessment; it is not a probability, financial forecast or universal risk model.

  • Critical · 20–25 immediate executive attention
  • High · 15–19 prioritized remediation
  • Medium · 8–14 planned corrective action
  • Low · 1–7 monitor or improve when practical

Confidence is independent

  • High: current, direct evidence supports the conclusion.
  • Medium: evidence supports the direction but contains a meaningful limitation.
  • Low: evidence is incomplete; the conclusion is provisional.
  • Not verified: no defensible conclusion is made.

Coverage and exclusions.

Baseline coverage

  • Domain, DNS, TLS and email-authentication posture visible within scope
  • Authorized Microsoft 365 identity, MFA and privileged-access evidence
  • Basic ownership, update, backup, restore and incident-readiness evidence
  • Risk-ranked findings, limitations and practical next actions

Explicit exclusions

  • No exploitation, credential testing, evasion, destructive action or red teaming
  • No source-code review, vulnerability scan or exhaustive asset discovery unless separately authorized
  • No certification, assurance opinion, legal advice or compliance attestation
  • No guarantee that every vulnerability, compromise or control weakness will be found

Data handling.

ClearGlass requests the minimum evidence necessary for the agreed questions. Evidence channels, access duration, retention and deletion are confirmed with the client. Sensitive data not needed for the assessment should be redacted before transfer. Findings are shared only with authorized contacts.

Quality control.

Every material finding should include an observation, affected scope, risk statement, recommendation, verification step, confidence level and limitation. Unsupported claims are removed or relabeled as hypotheses requiring evidence.

Reference baselines.

These primary sources inform control questions; ClearGlass applies only what is relevant to the authorized scope and does not imply endorsement or certification.

Method governance: material changes update the version and publication date. Questions or correction requests can be sent to desmond@clearglassinc.com.