IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP
Archived guide — original release identity

This guide describes a previous release. Use the current 4.1.0 documentation for new installations.

Documentation

Framework-specific workflows

Follow framework-native incident, corrective-action and governance processes.

MSPR68 bundled reference
All documentation / MSP / R68 bundled reference
This reference is bundled with the R68 engine and may retain earlier UI terminology. Use the current R68 installation/security guides for the new wizard and activation steps. Its procedures apply to MSP; use the separate Free or Professional guide for those editions.

IT Audit Factory — Framework Workflows

Framework Workflows provides editable, exportable governance response workflows that change with the active framework/program. The same underlying workflow engine is used across editions, while persistence and isolation follow each edition's architecture.

How to use

  1. Select the client/organization and active certification program where applicable.
  2. Open Framework Workflows.
  3. Review the framework-native stages and default guidance.
  4. Assign owners, contacts, status, priority/severity and stage notes.
  5. Record timeline/actions, evidence references and closure/lessons learned.
  6. Save, then export a DOCX when an auditor/client deliverable is needed.

Framework behavior

FrameworkWorkflow
CMMC Level 2Simple 3.6.1 incident handling: preparation, detection, analysis, containment, recovery and user response.
ISO/IEC 27001Information-security event/incident assessment, response, recovery, learning and evidence preservation.
ISO 9001Nonconformity, correction/control, cause evaluation, corrective action, effectiveness review and closure.
SOC 2Security incident detection, evaluation, containment, communication, remediation, recovery and evidence.
Other supported packsFramework-native issue/incident/service/privacy/continuity/AI workflow when applicable.

CMMC 3.6.1 escalation defaults

The times below are IT Audit Factory recommended internal defaults, not CMMC-mandated intervals. They are customizable.
SeverityInitial escalationIf not acknowledged
SEV-1 CriticalImmediately5 minutes
SEV-2 HighImmediately15 minutes
SEV-3 MediumWithin 30 minutes30 minutes
SEV-4 LowWithin 4 business hours4 business hours

Escalation order: User/Reporter → Service Desk/Incident Intake → Security/IT Lead → Incident Commander → IT/Infrastructure + affected System/Application Owner → Executive/Business Leadership → Legal/Privacy/Compliance → authorized external parties when required. If the primary contact does not acknowledge, contact the backup and advance to the next escalation level.

Isolation

MSP and Enterprise workflows are owned by the active client and certification program. Cross-client view, write, link, export and copy are prohibited. Switching clients must load a separate workflow. Free Edition is single-organization and stores separate local workflow state by framework.

Guide basis

R68 package: Framework-Workflows-Guide.html

Published as a website guide on 1 October 2026. Where a bundled reference is older, the version-specific guide and installed interface take precedence.