Use the approved 4.1.0 installer for your edition and confirm the version shown in the installed application. Published package availability is shown in Downloads & beta access.
IT Audit Modules
The shared source of truth contains 25 audit modules. Collection may be reused, but framework evaluation and published results are scoped by framework/program applicability.
- Asset & Scope Discovery
- Identity/MFA/PAM
- Endpoint Security/EDR/MDM
- Vulnerability Management
- SIEM/Logging/Monitoring
- Cloud Infrastructure
- Data Protection/DLP/Encryption
- Privacy/Data Governance
- Business Continuity/Disaster Recovery
- Third-Party/Supply Chain Risk
- Incident Response/SOC
- Application Security/SDLC/DevSecOps
- Containers/Kubernetes
- ITSM/Change/Service Management
- Physical & Environmental Security
- Personnel/HR Security
- Security Awareness/Phishing
- Wireless/NAC/Segmentation
- DNS/Domain/Internet Exposure
- OT/IoT/Industrial Systems
- AI Governance
- Software Supply Chain/SBOM
- Database Security
- PKI/Certificates/Secrets
- Email & Collaboration Security
Inapplicable tests are excluded or marked Not Applicable with an explicit basis; they are never converted to failures merely because a collector exists.
Supported frameworks and automated checks (4.1.0)
See Supported Frameworks and Automated Checks for the complete user-facing framework/collector matrix. ISO 9001 now includes supporting technical evidence for technically observable portions of clauses 6–9 using asset/scope reconciliation, backup/recovery, Group Policy/configuration, Windows/Linux servers, network, storage and VMware collectors. Clauses 4–5 and 10, and governance/process portions of clauses 6–9, remain manual and cannot be automatically declared conforming.