IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP
Documentation

Audit modules and applicability

Distinguish applicable collectors from manual work and exact requirement-level mappings.

MSP4.1.0
All documentation / MSP / 4.1.0
This reference is bundled with the 4.1.0 engine and may retain earlier UI terminology. Use the current 4.1.0 installation/security guides for the new wizard and activation steps. Its procedures apply to MSP; use the separate Free or Professional guide for those editions.

Use the approved 4.1.0 installer for your edition and confirm the version shown in the installed application. Published package availability is shown in Downloads & beta access.

IT Audit Modules

The shared source of truth contains 25 audit modules. Collection may be reused, but framework evaluation and published results are scoped by framework/program applicability.

  1. Asset & Scope Discovery
  2. Identity/MFA/PAM
  3. Endpoint Security/EDR/MDM
  4. Vulnerability Management
  5. SIEM/Logging/Monitoring
  6. Cloud Infrastructure
  7. Data Protection/DLP/Encryption
  8. Privacy/Data Governance
  9. Business Continuity/Disaster Recovery
  10. Third-Party/Supply Chain Risk
  11. Incident Response/SOC
  12. Application Security/SDLC/DevSecOps
  13. Containers/Kubernetes
  14. ITSM/Change/Service Management
  15. Physical & Environmental Security
  16. Personnel/HR Security
  17. Security Awareness/Phishing
  18. Wireless/NAC/Segmentation
  19. DNS/Domain/Internet Exposure
  20. OT/IoT/Industrial Systems
  21. AI Governance
  22. Software Supply Chain/SBOM
  23. Database Security
  24. PKI/Certificates/Secrets
  25. Email & Collaboration Security

Inapplicable tests are excluded or marked Not Applicable with an explicit basis; they are never converted to failures merely because a collector exists.

Supported frameworks and automated checks (4.1.0)

See Supported Frameworks and Automated Checks for the complete user-facing framework/collector matrix. ISO 9001 now includes supporting technical evidence for technically observable portions of clauses 6–9 using asset/scope reconciliation, backup/recovery, Group Policy/configuration, Windows/Linux servers, network, storage and VMware collectors. Clauses 4–5 and 10, and governance/process portions of clauses 6–9, remain manual and cannot be automatically declared conforming.