IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP
Documentation

Framework-specific workflows

Follow framework-native incident, corrective-action and governance processes.

MSP4.1.0
All documentation / MSP / 4.1.0
This reference is bundled with the 4.1.0 engine and may retain earlier UI terminology. Use the current 4.1.0 installation/security guides for the new wizard and activation steps. Its procedures apply to MSP; use the separate Free or Professional guide for those editions.

Use the approved 4.1.0 installer for your edition and confirm the version shown in the installed application. Published package availability is shown in Downloads & beta access.

IT Audit Factory — Framework Workflows

Framework Workflows provides editable, exportable governance response workflows that change with the active framework/program. The same underlying workflow engine is used across editions, while persistence and isolation follow each edition's architecture.

How to use

  1. Select the client/organization and active certification program where applicable.
  2. Open Framework Workflows.
  3. Review the framework-native stages and default guidance.
  4. Assign owners, contacts, status, priority/severity and stage notes.
  5. Record timeline/actions, evidence references and closure/lessons learned.
  6. Save, then export a DOCX when an auditor/client deliverable is needed.

Framework behavior

FrameworkWorkflow
CMMC Level 2Simple 3.6.1 incident handling: preparation, detection, analysis, containment, recovery and user response.
ISO/IEC 27001Information-security event/incident assessment, response, recovery, learning and evidence preservation.
ISO 9001Nonconformity, correction/control, cause evaluation, corrective action, effectiveness review and closure.
SOC 2Security incident detection, evaluation, containment, communication, remediation, recovery and evidence.
Other supported packsFramework-native issue/incident/service/privacy/continuity/AI workflow when applicable.

CMMC 3.6.1 escalation defaults

The times below are IT Audit Factory recommended internal defaults, not CMMC-mandated intervals. They are customizable.
SeverityInitial escalationIf not acknowledged
SEV-1 CriticalImmediately5 minutes
SEV-2 HighImmediately15 minutes
SEV-3 MediumWithin 30 minutes30 minutes
SEV-4 LowWithin 4 business hours4 business hours

Escalation order: User/Reporter → Service Desk/Incident Intake → Security/IT Lead → Incident Commander → IT/Infrastructure + affected System/Application Owner → Executive/Business Leadership → Legal/Privacy/Compliance → authorized external parties when required. If the primary contact does not acknowledge, contact the backup and advance to the next escalation level.

Isolation

MSP and Enterprise workflows are owned by the active client and certification program. Cross-client view, write, link, export and copy are prohibited. Switching clients must load a separate workflow. Free Edition is single-organization and stores separate local workflow state by framework.