Death Star Evil Corp™
Assurance. Governance. Compliance. Domination. "We don't just manage risk. We weaponise the paperwork."
INTERNAL MEMORANDUM TO: All Sentient Personnel, Droids (Category B and above), Dark Lords (where applicable) FROM: Office of the Chief Governance, Risk & Compliance Officer RE: Annual Information Security Assurance Programme — Mandatory Participation CLASSIFICATION: RESTRICTED / AMBER / DO NOT ACTION / FOR INFORMATION ONLY
1. PROGRAMME OVERVIEW
Death Star Evil Corp™ is pleased to announce the commencement of its FY26 Information Security Assurance Programme, in full alignment with ISO 27001, NIST CSF, SOC 2 Type II, the Galactic Imperial Compliance Framework (GICF v4.2), and the Dark Side Operational Risk Standard (DSORS), which was ratified last quarter by a committee whose members we cannot disclose for reasons of organisational security.
The programme will be led by our newly appointed Third Party Assurance Partner, Deloitte McKinsey PricewaterhouseForce LLP, hereafter referred to as "the Auditors."
The Auditors have been briefed.
The Auditors have not been briefed on what we actually do here.
This is intentional.
2. SCOPE
Following extensive scoping workshops, the following systems and processes are confirmed IN SCOPE for this year's assurance programme:
— The staff canteen ordering system (Sector 7-G) — The visitor sign-in iPad (Main Atrium, currently showing 34% battery) — The SharePoint site that nobody uses — The policy repository (last updated: pre-Alderaan incident) — The HR onboarding checklist for new Stormtroopers
The following are confirmed OUT OF SCOPE:
— The Death Star itself — The superlaser — The exhaust port — The exhaust port vulnerability that Lord Vader's threat modelling team flagged in 2019 — The second exhaust port (we built another one) — The third-party contractor arrangements with Palpatine Consulting — The 47 AWS accounts registered to a gmail address belonging to Grand Moff Tarkin — Grand Moff Tarkin — The incident last Thursday — What happened on Endor — All of it
Scope was agreed by the Steering Committee on 14th March. The Steering Committee has not met since 14th March. The Steering Committee calendar invite for the next meeting has been declined by six of seven members. The seventh member is a protocol droid who cannot decline calendar invites.
3. EVIDENCE REQUIREMENTS
All business units are required to provide evidence of compliance with the Death Star Evil Corp™ Information Security Control Framework by close of play Friday.
Close of play Friday has meant different things each week. This week it means Thursday at 4pm because the lead auditor has a half day.
Evidence must be submitted via the Assurance Portal.
The Assurance Portal is down.
The Assurance Portal has been down since the incident last Thursday.
We cannot confirm what the incident was.
Please email evidence to [email protected]
This inbox is monitored by an intern named Chad who joined three weeks ago and is no longer sure what sector he works in.
Required evidence includes but is not limited to:
— Your department's Information Security Policy — Evidence that your Information Security Policy has been read — Evidence that the evidence of reading was conducted by humans and not droids (Note: droid attestation is not accepted under GICF v4.2 Annex D) — Your Business Continuity Plan — Evidence that your Business Continuity Plan accounts for scenarios where the business is entirely destroyed by a single proton torpedo — Your patch management policy — Evidence that TIE Fighter firmware is patched within SLA — Evidence that the SLA exists — A signed attestation that the exhaust port is not a known vulnerability — A second signed attestation confirming the first attestation was signed by an authorised signatory — The authorised signatory register — Evidence that the authorised signatory register is current (Note: Lord Vader has not recertified his signing authority since his near-death experience. This is a finding.)
4. FINDINGS TO DATE
The Auditors have been on site for eleven days.
They have raised 34 findings.
Critical (6):
— No documented process for reviewing documented processes — Patch management policy references a patching tool decommissioned in FY23 — The Business Continuity Plan lists the Death Star as the primary recovery site — The Death Star is not available as a recovery site (see: last Thursday) — Access review for Force users has not been completed since Q2. It is Q4. — Lord Vader has admin rights to every system in the organisation including systems he has never heard of, including the canteen ordering system, through which he has, on four occasions, ordered a decaf
High (11):
— No multi-factor authentication on the Emperor's personal Holocron account — The Emperor's password is "Order66!" — it has not been rotated since Order 66 — Thirteen Stormtroopers share a single privileged service account called "stormtrooper_admin" — The account password is "Stormtrooper1" — There is no offboarding process. There are 847 active accounts belonging to employees confirmed as deceased — The deceased employees have, in aggregate, more system access than the CISO — The CISO flagged all of this in a memo dated eighteen months ago — The memo is in scope — The memo was not read — This is also a finding — The CISO has handed in their notice
Medium (9):
— The visitor iPad is running iOS 14 — The visitor iPad has not been enrolled in MDM — The visitor iPad has, somehow, local admin rights to the financial reporting system — Nobody knows how — This is the most interesting finding and the Auditors have spent four days on it — The superlaser remains out of scope
Low (8):
— The door policy has not been reviewed annually — There are four doors — Three of the doors do not have policies — One of the doors does not have a door — That is where the exhaust port is — The exhaust port is out of scope — The finding is about the door policy — This is rated Low
5. REMEDIATION PLAN
All findings must have a remediation plan submitted within ten business days via the Assurance Portal.
The Assurance Portal is still down.
The Assurance Portal is now also a finding.
Chad is dealing with it.
6. RISK TREATMENT
Following review by the Risk Committee, the following treatment decisions have been approved:
Risk Treatment Rationale Exhaust port vulnerability Accept Out of scope Second exhaust port vulnerability Accept Also out of scope 847 active accounts for deceased staff Accept Offboarding process in roadmap for FY27 Emperor's password not rotated since Order 66 Accept Change management process required — low priority Visitor iPad with admin rights to finance system Accept Legacy architecture — remediation complex No BCP for total organisational destruction Transfer Insurance policy under review The incident last Thursday Deny What incident
7. EXECUTIVE SUMMARY
"Whilst Death Star Evil Corp™ demonstrates a commitment to information security governance, however, evidence was not provided to confirm this commitment is operationalised. Whilst the organisation has invested significantly in security infrastructure, however, the infrastructure was not available for review. Whilst senior leadership has demonstrated awareness of the risk landscape, however, the risk landscape includes at minimum two exhaust ports, neither of which is in scope.
Overall, the organisation's assurance posture is assessed as AMBER.
We recommend a follow-up engagement in Q1 FY27 at a day rate of £2,400 per auditor.
There are four auditors."
8. BOARD REPORTING
The board pack has been prepared.
Slide 4 shows a risk heatmap.
The heatmap is green.
The heatmap has been green since Q3.
The heatmap does not include exhaust ports.
The board has approved the heatmap.
The board meeting lasted eleven minutes.
Lord Vader attended by phone.
He did not speak.
Everyone rated the call as "very productive" in the post-meeting survey.
9. PROGRAMME CLOSURE
The FY26 Assurance Programme is hereby closed.
23 findings remain open.
6 findings were closed by updating the finding status to "Closed."
No controls were changed.
The risk register has been updated.
The risk register now contains 847 risks.
The top risk is "failure to complete risk register on time."
It is rated Critical.
It is owned by the person who left last Thursday.
They are in Bali.
The galaxy is secure.
The paperwork says so.
The paperwork is all we have left.
DEATH STAR EVIL CORP™ "Governance at Galactic Scale" ISO 27001 Certified · SOC 2 Type II Attested · Alderaan Incident Under Review
Threat intelligence every morning — new victims, new groups, what matters, in plain English. Free, with receipts.
Subscribe to the Daily →
Scott Gardner ·