IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP
Documentation

Framework pack reference

Read framework catalogs, mapping boundaries and independent assessment decisions.

MSP4.1.0
All documentation / MSP / 4.1.0
This reference is bundled with the 4.1.0 engine and may retain earlier UI terminology. Use the current 4.1.0 installation/security guides for the new wizard and activation steps. Its procedures apply to MSP; use the separate Free or Professional guide for those editions.

Use the approved 4.1.0 installer for your edition and confirm the version shown in the installed application. Published package availability is shown in Downloads & beta access.

IT Audit Factory MSP — Framework Pack Guide

Standards licensing boundary: IT Audit Factory ships non-verbatim identifiers, paraphrased readiness labels and technical mappings. It does not replace the licensed/official text of ISO, SOC, CIS, PCI or other standards. The organization and auditor must use the authoritative source for conformity decisions.

Built-in framework workspaces

FrameworkWorkspaceAutomated testing policy
ISO/IEC 27001Program-specific checklist with applicability, implementation and evidence stateOnly technically testable items receive collector evidence; governance/legal/process items require manual review.
CMMC Level 2Program-specific checklist with applicability, implementation and evidence stateOnly technically testable items receive collector evidence; governance/legal/process items require manual review.
NIST SP 800-171Program-specific checklist with applicability, implementation and evidence stateOnly technically testable items receive collector evidence; governance/legal/process items require manual review.
CIS ControlsProgram-specific checklist with applicability, implementation and evidence stateOnly technically testable items receive collector evidence; governance/legal/process items require manual review.
SOC 2Program-specific checklist with applicability, implementation and evidence stateOnly technically testable items receive collector evidence; governance/legal/process items require manual review.
ISO 9001Program-specific checklist with applicability, implementation and evidence stateOnly technically testable items receive collector evidence; governance/legal/process items require manual review.
PCI DSSProgram-specific checklist with applicability, implementation and evidence stateOnly technically testable items receive collector evidence; governance/legal/process items require manual review.
ISO/IEC 20000-1Program-specific checklist with applicability, implementation and evidence stateOnly technically testable items receive collector evidence; governance/legal/process items require manual review.
ISO 22301Program-specific checklist with applicability, implementation and evidence stateOnly technically testable items receive collector evidence; governance/legal/process items require manual review.
ISO/IEC 27017Program-specific checklist with applicability, implementation and evidence stateOnly technically testable items receive collector evidence; governance/legal/process items require manual review.
ISO/IEC 27018Program-specific checklist with applicability, implementation and evidence stateOnly technically testable items receive collector evidence; governance/legal/process items require manual review.
ISO/IEC 27701Program-specific checklist with applicability, implementation and evidence stateOnly technically testable items receive collector evidence; governance/legal/process items require manual review.
HIPAA SecurityProgram-specific checklist with applicability, implementation and evidence stateOnly technically testable items receive collector evidence; governance/legal/process items require manual review.
NIST CSF 2.0Program-specific checklist with applicability, implementation and evidence stateOnly technically testable items receive collector evidence; governance/legal/process items require manual review.
NIST SP 800-53 / FedRAMPProgram-specific checklist with applicability, implementation and evidence stateOnly technically testable items receive collector evidence; governance/legal/process items require manual review.

Assessment interpretation

A collector result is evidence, not certification. The same evidence may be reused across programs, but applicability and conformity are evaluated independently.

Supported frameworks and automated checks (4.1.0)

See Supported Frameworks and Automated Checks for the complete user-facing framework/collector matrix. ISO 9001 now includes supporting technical evidence for technically observable portions of clauses 6–9 using asset/scope reconciliation, backup/recovery, Group Policy/configuration, Windows/Linux servers, network, storage and VMware collectors. Clauses 4–5 and 10, and governance/process portions of clauses 6–9, remain manual and cannot be automatically declared conforming.