IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP
Documentation / Coverage

How to read the coverage pages

Source-derived mappings, not a blanket compliance or scanner claim.

Three different coverage labels

Mapped technical checks: an explicit requirement-to-test record exists in the packaged mapping files. For ISO 27001, this is the engine ControlRefs mapping. For CMMC and NIST Rev. 2, it is the explicit requirement mapping CSV.

Family supporting scope: the module applicability profile permits collector/test-prefix families for the requirement family. This is not an exact test mapping and is not advertised as automatic requirement satisfaction.

Manual / no exact mapping: no exact mapping or applicable family scope is shown by those sources. This is not a failed control; it requires suitable assessment evidence and review.

What the counts mean

The mapping reference for MSP 4.1.0 contains 24 frameworks/profiles and 509 entries, carried forward from the historical catalog. Some entries represent entire families, clause groups or readiness topics rather than official leaf-level controls. These are mapping counts, not 509 independently tested automated controls.

No substituted mappings

The site does not turn every technical test in a family into an exact mapped result for every family requirement. The 4.1.0 applicability service uses explicit requirement mappings for result attribution; family-level execution plans are shown only as collection scope.

Scope and edition limits

Mapping presence is not proof a collector will run on a particular asset or pass. Permissions, dependencies, vendor support, exclusions and runtime results still apply. This extract is MSP 4.1.0-specific. Do not apply its counts to Free or Professional without checking that edition separately.

Publication basis

The mapping reference is carried forward from the historical product catalog. It is not evidence that a new installer or framework workflow has passed runtime acceptance testing.

Browse frameworks