Authorize and bound the scope
Record the legal organization, authorized contact, in-scope domains or tenant, exclusions, evidence sources, permitted actions and delivery date. No testing begins from a payment alone.
Methodology v1.0 · published 14 August 2026
The Ontario Security Quick-Audit is a limited, read-only baseline. It identifies defensible next actions without presenting a small engagement as a certification, penetration test or guarantee.
ClearGlass confirms authorization and scope, collects only necessary read-only evidence, compares that evidence with recognized baseline guidance, scores each supported risk using likelihood × impact, records confidence separately, and delivers prioritized actions with limitations. Missing evidence is marked “not verified” and is not converted into a pass or failure.
The sequence protects both the client and the integrity of the conclusions.
Record the legal organization, authorized contact, in-scope domains or tenant, exclusions, evidence sources, permitted actions and delivery date. No testing begins from a payment alone.
Use passive public observations and client-supplied, read-only exports or screenshots. Do not request passwords, recovery codes, private keys, patient data, payment-card data or unrestricted administrator credentials.
Review domain and email controls, Microsoft 365 identity and privileged-access evidence, and basic response-and-recovery readiness within the agreed scope.
Assign likelihood and impact only where evidence supports an exposure. Record the evidence source, reasoning, confidence and affected scope separately.
Recommend the smallest practical action, accountable owner, target horizon and verification evidence. Review the report with the authorized contact.
The report labels how every material statement is supported.
| Class | Meaning | Typical example | Handling |
|---|---|---|---|
| Observed | Visible through an authorized passive or read-only check. | Published DNS record or dated configuration export. | Record source, time and relevant value. |
| Client-supplied | Provided by the authorized contact. | Policy index, screenshot or redacted report. | Identify provenance and any completeness limit. |
| Inferred | A bounded conclusion derived from evidence. | A likely exposure supported by a control state. | State the reasoning and confidence; never present inference as direct observation. |
| Not verified | Required evidence was unavailable or inconclusive. | No restore-test record supplied. | Do not score as a pass or failure; state what would verify it. |
Severity prioritizes action. Confidence communicates evidence strength. They are reported separately so uncertainty is visible.
Likelihood and impact each use a 1–5 scale. The score guides ordering within this limited assessment; it is not a probability, financial forecast or universal risk model.
ClearGlass requests the minimum evidence necessary for the agreed questions. Evidence channels, access duration, retention and deletion are confirmed with the client. Sensitive data not needed for the assessment should be redacted before transfer. Findings are shared only with authorized contacts.
Every material finding should include an observation, affected scope, risk statement, recommendation, verification step, confidence level and limitation. Unsupported claims are removed or relabeled as hypotheses requiring evidence.
These primary sources inform control questions; ClearGlass applies only what is relevant to the authorized scope and does not imply endorsement or certification.
Method governance: material changes update the version and publication date. Questions or correction requests can be sent to desmond@clearglassinc.com.