Daedalus
HomeReviewsDesignBlueprintsHistorySettings
Northwind/Reviews/IT Service Desk Assistant
rv-2026-0389

IT Service Desk Assistant

Approved
Close out findings

Submitted by Aisha Khan of IS Service Management·25 Aug 2026·Google Cloud, scored under CIS Controls v8.1 and Northwind’s own standards·matched to Internal GenAI assistant with retrieval at 84%·read from it-service-desk-assistant-lld-v2.0.pdf and it-service-desk-assistant-architecture.png

11 of 38 safeguards fail1 contradiction with the document
Framework
Safeguards in scope38Everything that governs a design of this shape
Failing11To close or accept before approval
Closed with evidence0Nothing closed yet
Accepted as gaps0No gap accepted
Answered0%0 of 11
Failthe design does not show the safeguard is met, whether it contradicts it or is silent on itPassthe design shows it is met, and the register cites whereSafeguards that do not govern a design of this shape are not listed.
Maps to
CAT-2Conditional services are used on their termsVertex AI is used outside its conditions of useEstate fitEstate fitService catalogueHigh
Fail
Missing
1 cited, none proving it is built
Cyber Security24 Sept 2026
LLM01Prompt InjectionPrompts, retrieved chunks and tool results reach Gemini without screeningAISecurityOWASP LLM Top 10High
Fail
Missing
3 cited, none proving it is built
IS Service Management24 Sept 2026
LLM02Sensitive Information DisclosureRestricted knowledge content can be surfaced to any employee, and replies are not screenedAISecurityOWASP LLM Top 10High
Fail
Missing
4 cited, none proving it is built
IS Service Management24 Sept 2026
LLM08Vector and Embedding WeaknessesThe vector index carries no entitlements: every employee can retrieve every chunkAISecurityOWASP LLM Top 10High
Fail
Missing
4 cited, none proving it is built
IS Service Management24 Sept 2026
REL-1No single point of failure on the critical pathThe primary data store has no standbyReliabilityReliabilityGCP Architecture FrameworkHigh
Fail
Missing
IS Service Management24 Sept 2026
AP-2Third party in the data pathThird party in the data path: ServiceNow (northwindprod)Design patternReliabilityDesign patternsMedium
Fail
Missing
IS Service Management24 Oct 2026
COST-4Spend is visible and attributedNo budget, alert or cost attributionCostCostGCP Architecture FrameworkMedium
Fail
Missing
Cloud Platform Engineering24 Oct 2026
LLM06Excessive AgencyThe model decides when to raise an incident; no user confirmation is documentedAISecurityOWASP LLM Top 10Medium
Fail
Missing
2 cited, none proving it is built
IS Service Management24 Oct 2026
MBSS-1The design names the baselines it is built to6 baselines apply and none is named in the designEstate fitEstate fitMBSS baselinesMedium
Fail
Missing
Cyber Security24 Oct 2026
REL-3Recovery is tested, not assumedThe restore path has never been exercisedReliabilityReliabilityGCP Architecture FrameworkMedium
Fail
Missing
1 cited, none proving it is built
IS Service Management24 Oct 2026
REL-5Dependencies fail without taking the application downA call to ServiceNow (northwindprod) has no stated failure behaviourReliabilityReliabilityGCP Architecture FrameworkMedium
Fail
Missing
IS Service Management24 Oct 2026
3.10Encrypt Sensitive Data in TransitTLS on every hop, including an enforced encrypted connection to Cloud SQLDataSecurityPR.DS-02Low
Pass
Data Platform Engineering—
3.11Encrypt Sensitive Data at RestData at rest uses Google default encryption, which the standard accepts for Confidential dataDataSecurityPR.DS-01Low
Pass
Data Platform Engineering—
3.12Segment Data Processing and Storage Based on SensitivityThe index and the conversation database sit inside a VPC Service Controls perimeterDataSecurityPR.IR-01 · PR.DS-01Low
Pass
Data Platform Engineering—
6.3Require MFA for Externally-Exposed ApplicationsIdentity-Aware Proxy enforces corporate sign-in and MFA before requests reach the applicationIdentitySecurityPR.AA-03Low
Pass
Identity Engineering—
6.5Require MFA for Administrative AccessProject administrators use 2-Step Verification with security keysIdentitySecurityPR.AA-03 · PR.AA-05Low
Pass
Identity Engineering—
8.9Centralize Audit LogsAudit logs leave the project through the organisation-level sink, and every tool call is loggedLoggingSecurityPR.PS-04Low
Pass
Cyber Security—
11.4Establish and Maintain an Isolated Instance of Recovery DataDatabase backups go to a vault in a separate project with enforced retentionResilienceSecurityPR.DS-11Low
Pass
Cloud Platform Engineering—
12.2Establish and Maintain a Secure Network ArchitecturePrivate IP database, Private Google Access and two allow-listed external destinationsNetworkSecurityPR.IR-01Low
Pass
Network Engineering—
13.10Perform Application Layer FilteringCloud Armor with the OWASP rule set on the only public entry pointNetworkSecurityPR.IR-01 · DE.CM-01Low
Pass
Network Engineering—
16.10Apply Secure Design Principles in Application ArchitecturesPer-workload service accounts and a ServiceNow integration user limited to what the tools needApplicationSecurityPR.PS-06Low
Pass
IS Service Management—
AP-1Shared databaseNo shared databaseDesign patternReliabilityDesign patternsLow
Pass
Not assessedIS Service Management—
AP-4Snowflake environmentThe environment is reproducibleDesign patternOperationsDesign patternsLow
Pass
Cloud Platform Engineering—
CAT-1Every service is in the catalogue and permittedAll 11 services are in the catalogue and permittedEstate fitEstate fitService catalogueLow
Pass
Not assessedCyber Security—
CAT-3Nothing depends on a service that is going awayNothing in the design is retiring or unassessedEstate fitEstate fitService catalogueLow
Pass
Not assessedCyber Security—
CAT-4Data is held only where its class is permittedEvery store is assessed for the class it holdsEstate fitEstate fitService catalogueLow
Pass
Not assessedCyber Security—
COST-1Capacity follows demandNothing runs when nothing is happeningCostCostGCP Architecture FrameworkLow
Pass
Not assessedCloud Platform Engineering—
COST-3Traffic that leaves is accounted forTraffic leaving the estate is accounted forCostCostGCP Architecture FrameworkLow
Pass
Cloud Platform Engineering—
LLM05Improper Output HandlingTool arguments are schema-validated and incident text is inserted as plain textAISecurityOWASP LLM Top 10Low
Pass
IS Service Management—
LLM07System Prompt LeakageThe system prompt holds instructions only; integration credentials are in Secret ManagerAISecurityOWASP LLM Top 10Low
Pass
IS Service Management—
LLM10Unbounded ConsumptionPer-user quotas keyed on the IAP identity and a project budget with alertsAISecurityOWASP LLM Top 10Low
Pass
IS Service Management—
OPS-1Infrastructure is defined as codeThe environment is defined as codeOperationsOperationsGCP Architecture FrameworkLow
Pass
Cloud Platform Engineering—
OPS-2Releases are staged and reversibleReleases are staged and can be withdrawnOperationsOperationsGCP Architecture FrameworkLow
Pass
Cloud Platform Engineering—
OPS-3Monitoring reaches a personAlerts reach a named rotaOperationsOperationsGCP Architecture FrameworkLow
Pass
Cloud Platform Engineering—
OPS-4Runbooks exist for the likely failuresRunbooks exist for the likely failuresOperationsOperationsGCP Architecture FrameworkLow
Pass
Cloud Platform Engineering—
PERF-1Latency and throughput targets are statedThe design states what it is built to servePerformancePerformanceGCP Architecture FrameworkLow
Pass
IS Service Management—
PERF-4Scaling bounds are definedScaling bounds are setPerformancePerformanceGCP Architecture FrameworkLow
Pass
IS Service Management—
REL-2Recovery objectives are statedRecovery objectives are statedReliabilityReliabilityGCP Architecture FrameworkLow
Pass
IS Service Management—
38 of 38 rows · scored under CIS Controls v8.1A target date runs from the submission: 30 days for high, 60 for medium, 90 for low.
Ask about this reviewAnswers cite the record; click a citation to see it.
Try