Web security · appears in CAIQ, SIG, ISO 27001
Has the public web surface (server identification, exposed paths) been reviewed?
Public files — robots.txt, sitemap.xml, head meta — are what attackers see first during reconnaissance. Misadvertised paths, stale sitemaps, and verbose generators leak more than intended (ISO 27001 A.8.9).
How to answer this
Whichever verdict your domain earns, this is the wording to put in the response box. Reviewers mark an answer down for vagueness more often than for a "No", so say which state you are in and what evidences it.
- Yes
- Public web surface inspection found no obvious exposure
- Partial
- Public web surface inspection raised minor concerns
- No
- Public web surface inspection raised significant concerns
Controls this evidences
| Framework | Control | Why it maps |
|---|---|---|
| SOC 2 | CC6.6 | Public-surface inventory aids vulnerability management. |
| ISO 27001 | A.8.9 | — |
| NIST 800-53 | CM-7 | — |
Domain Posture is not an audit and does not replace an auditor. See methodology v1 for how each verdict is reached.
When a "Yes" stops being true
A new public-surface exposure appeared (verbose generator banner, stale/over-broad sitemap, or leaked path).
That is the whole problem with answering a questionnaire from a screenshot: the answer was true the day you took it. A signed evidence pack is dated, and a schedule re-checks it so you find out before your reviewer does.