Daedalus
HomeReviewsDesignBlueprintsHistorySettings
Northwind/Reviews/Supplier Onboarding Portal
rv-2026-0371

Supplier Onboarding Portal

Approved
Close out findings

Submitted by Elena Marchetti of Procurement Digital·19 Aug 2026·Google Cloud, scored under CIS Controls v8.1 and Northwind’s own standards·matched to Customer-facing web application on Cloud Run at 93%·read from supplier-onboarding-portal-lld-v2.0.pdf and supplier-onboarding-portal-architecture.png

9 of 32 safeguards failThe document and the diagram agree
Framework
Safeguards in scope32Everything that governs a design of this shape
Failing9To close or accept before approval
Closed with evidence0Nothing closed yet
Accepted as gaps0No gap accepted
Answered0%0 of 9
Failthe design does not show the safeguard is met, whether it contradicts it or is silent on itPassthe design shows it is met, and the register cites whereSafeguards that do not govern a design of this shape are not listed.
Maps to
6.3Require MFA for Externally-Exposed ApplicationsSupplier accounts sign in with a password aloneIdentitySecurityPR.AA-03High
Fail
Missing
3 cited, none proving it is built
Identity Engineering18 Sept 2026
11.4Establish and Maintain an Isolated Instance of Recovery DataBackups are isolated in a separate project, but a restore has never been performedResilienceSecurityPR.DS-11Medium
Fail
Missing
3 cited, none proving it is built
Cloud Platform Engineering18 Oct 2026
12.2Establish and Maintain a Secure Network ArchitectureNo documented zone model, and any internet destination is reachable from the application subnetNetworkSecurityPR.IR-01Medium
Fail
Missing
3 cited, none proving it is built
Network Engineering18 Oct 2026
AP-1Shared databaseShared database: portal-web and review-console both reach supplier-db directlyDesign patternReliabilityDesign patternsMedium
Fail
Missing
1 cited, none proving it is built
Procurement Digital18 Oct 2026
CAT-1Every service is in the catalogue and permitted1 component is not in the service catalogueEstate fitEstate fitService catalogueMedium
Fail
Missing
Cyber Security18 Oct 2026
COST-4Spend is visible and attributedNo budget, alert or cost attributionCostCostGCP Architecture FrameworkMedium
Fail
Missing
Cloud Platform Engineering18 Oct 2026
MBSS-1The design names the baselines it is built to6 baselines apply and none is named in the designEstate fitEstate fitMBSS baselinesMedium
Fail
Missing
Cyber Security18 Oct 2026
OPS-4Runbooks exist for the likely failuresNo runbooks are referencedOperationsOperationsGCP Architecture FrameworkLow
Fail
Missing
Cloud Platform Engineering17 Nov 2026
PERF-3Static content is served from the edgeEvery asset is fetched from the application tierPerformancePerformanceGCP Architecture FrameworkLow
Fail
Missing
Procurement Digital17 Nov 2026
3.10Encrypt Sensitive Data in TransitTLS at the edge and enforced encryption on every database sessionDataSecurityPR.DS-02Low
Pass
Data Platform Engineering—
3.11Encrypt Sensitive Data at RestData at rest uses Google default encryption, which the standard accepts for Confidential dataDataSecurityPR.DS-01Low
Pass
Data Platform Engineering—
3.12Segment Data Processing and Storage Based on SensitivityThe database and the document bucket sit inside the procurement perimeterDataSecurityPR.IR-01 · PR.DS-01Low
Pass
Data Platform Engineering—
6.5Require MFA for Administrative AccessBuyers reach the console through IAP and project administrators use security keysIdentitySecurityPR.AA-03 · PR.AA-05Low
Pass
Identity Engineering—
8.9Centralize Audit LogsAudit logs leave the project through the organisation sinkLoggingSecurityPR.PS-04Low
Pass
Cyber Security—
13.10Perform Application Layer FilteringCloud Armor filters application-layer traffic with the OWASP rule set, rate limiting and a body limitNetworkSecurityPR.IR-01 · DE.CM-01Low
Pass
Network Engineering—
16.10Apply Secure Design Principles in Application ArchitecturesEach service runs as its own account with roles limited to what it touchesApplicationSecurityPR.PS-06Low
Pass
Procurement Digital—
AP-2Third party in the data pathNo third party on the request pathDesign patternReliabilityDesign patternsLow
Pass
Not assessedProcurement Digital—
AP-4Snowflake environmentThe environment is reproducibleDesign patternOperationsDesign patternsLow
Pass
Cloud Platform Engineering—
CAT-2Conditional services are used on their terms12 conditional services are used within their termsEstate fitEstate fitService catalogueLow
Pass
Not assessedCyber Security—
CAT-3Nothing depends on a service that is going awayNothing in the design is retiring or unassessedEstate fitEstate fitService catalogueLow
Pass
Not assessedCyber Security—
CAT-4Data is held only where its class is permittedEvery store is assessed for the class it holdsEstate fitEstate fitService catalogueLow
Pass
Not assessedCyber Security—
COST-1Capacity follows demandNothing runs when nothing is happeningCostCostGCP Architecture FrameworkLow
Pass
Not assessedCloud Platform Engineering—
COST-2Storage has a lifecycleStored data has a stated lifetimeCostCostGCP Architecture FrameworkLow
Pass
Cloud Platform Engineering—
COST-3Traffic that leaves is accounted forTraffic leaving the estate is accounted forCostCostGCP Architecture FrameworkLow
Pass
Cloud Platform Engineering—
OPS-1Infrastructure is defined as codeThe environment is defined as codeOperationsOperationsGCP Architecture FrameworkLow
Pass
Cloud Platform Engineering—
OPS-2Releases are staged and reversibleReleases are staged and can be withdrawnOperationsOperationsGCP Architecture FrameworkLow
Pass
Cloud Platform Engineering—
OPS-3Monitoring reaches a personAlerts reach a named rotaOperationsOperationsGCP Architecture FrameworkLow
Pass
Cloud Platform Engineering—
PERF-1Latency and throughput targets are statedThe design states what it is built to servePerformancePerformanceGCP Architecture FrameworkLow
Pass
Procurement Digital—
PERF-4Scaling bounds are definedScaling bounds are setPerformancePerformanceGCP Architecture FrameworkLow
Pass
Procurement Digital—
REL-1No single point of failure on the critical pathThe data tier survives the loss of a zoneReliabilityReliabilityGCP Architecture FrameworkLow
Pass
Procurement Digital—
REL-2Recovery objectives are statedRecovery objectives are statedReliabilityReliabilityGCP Architecture FrameworkLow
Pass
Procurement Digital—
REL-3Recovery is tested, not assumedA restore has been performed and timedReliabilityReliabilityGCP Architecture FrameworkLow
Pass
Procurement Digital—
32 of 32 rows · scored under CIS Controls v8.1A target date runs from the submission: 30 days for high, 60 for medium, 90 for low.
Ask about this reviewAnswers cite the record; click a citation to see it.
Try