IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP
Archived guide — original release identity

This guide describes a previous release. Use the current 4.1.0 documentation for new installations.

Documentation

Continuous assurance reference

Drift, evidence freshness and recurring assurance concepts in the packaged guide.

MSPR68 bundled reference
All documentation / MSP / R68 bundled reference
This reference is bundled with the R68 engine and may retain earlier UI terminology. Use the current R68 installation/security guides for the new wizard and activation steps. Its procedures apply to MSP; use the separate Free or Professional guide for those editions.

Continuous Assurance Foundation

ITAuditFactory ISO 27001 Audit Toolkit v2.0.0-RC4

Explicit conclusion states

ConclusionMeaning
PassThe declared technical condition was observed. Human scope and control review still apply.
FailThe declared technical condition was not met.
Needs ReviewThe result is ambiguous, informational, or needs a human conclusion.
Not ApplicableThe test was explicitly excluded from the evaluated scope.
Not CollectedEvidence was not obtained; this is not a pass.
Collection ErrorCollection failed because of a runtime, authorization, dependency, or data error.
Suppressed ExceptionAn approved, time-bounded exception suppresses operational action; it does not rewrite the observation.

Transparent Test Contract v2

Every exported result includes the purpose, expected and observed values, permissions, data source, collector and rule versions, ISO mapping rationale, evidence lineage, last successful collection, and evidence age. Existing RC47 collectors remain compatible. Until a collector explicitly declares every required semantic field, its contract is marked PARTIAL and lists the gaps.

Collector preflight and health

Each selected module records READY, READY_WITH_LIMITATIONS, or BLOCKED before collection. The records are stored as 04-Logs\Collector-Preflight.csv and 04-Logs\Collector-Preflight.json and are included in the HTML report. Preflight does not probe or disclose passwords; authorization and connectivity are confirmed by the read-only collector.

Evidence Integrity v2

Each completed run contains:

  • Evidence-Integrity-v2.json — sorted package-relative path, size, and SHA-256 for every included file.
  • Evidence-Integrity-v2.sha256 — the SHA-256 of the manifest itself.
  • SHA256SUMS.txt — the legacy manifest retained for compatibility.

The v2 manifest is independently verifiable but is not claimed to be certificate-signed. Certificate-backed signing and trusted timestamp integration remain future controlled work.

Verify a package

powershell.exe -NoLogo -NoProfile -ExecutionPolicy Bypass -File "C:\Program Files\ITAuditFactory\ITAuditFactory ISO 27001 Audit Toolkit\Scripts\Verify-ITAuditFactoryEvidencePackage.ps1" -PackageRoot "D:\Evidence\Run-20260904"

Exit code 0 means the manifest and every listed file hash match. Exit code 1 means verification failed. To save a JSON report, pass -ReportPath pointing outside the evidence package.

Review sequence

  1. Review collector preflight and resolve blocked or limited modules.
  2. Review explicit conclusion states; do not rely on the legacy status alone.
  3. Open each test contract and resolve partial-contract gaps.
  4. Review raw evidence, scope, mapping, remediation, and human governance records.
  5. Run the standalone verifier before auditor handoff and retain its result outside the package.

Guide basis

R68 package: Continuous-Assurance-Foundation.html

Published as a website guide on 1 October 2026. Where a bundled reference is older, the version-specific guide and installed interface take precedence.