FFIEC IT examination readiness
89 scoped preparation workpapers and 299 evidence review actions
All available frameworksWhat the app checks
Technical checks run for the selected scope, available connectors and credentials. Results provide evidence for review; missing data is not a pass.
Explicit requirement-to-test mappings
| Requirement | Collector / test | What it checks or supports |
|---|---|---|
| FFIEC-IS-O04 | WINDOWS / WIN-INVENTORY-COVERAGE-001 | Asset observations support risk-identification population review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| FFIEC-IS-O06 | ADSEC / AD-LIFECYCLE-001 | Account observations support access-control procedure review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| FFIEC-IS-O06 | ADSEC / AD-PRIV-001 | Privileged groups support least-privilege review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| FFIEC-IS-O06 | CERTTLS / CERTTLS-POSTURE-001 | TLS observations support encryption review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| FFIEC-IS-O06 | WINDOWS / WIN-FW-001 | Host firewall state supports network-protection review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| FFIEC-IS-O06 | WINDOWS / WIN-AV-001 | Endpoint protection state supports malware-control review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| FFIEC-IS-O06 | STORAGE / STOR-AT-REST-ENCRYPTION-001 | Storage encryption state supports data-protection review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| FFIEC-IS-O08 | WINDOWS / WIN-PATCH-FRESHNESS-001 | Patch observations support security-operations review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| FFIEC-IS-O10 | VULN / VULN-IMPORT-001 | External vulnerability findings support assurance review; they do not replace independent penetration testing. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| FFIEC-BCM-O06 | BACKUP / VEEAM-JOB-001 | Backup job results support resilience review; restoration and continuity exercises remain manual. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| FFIEC-BCM-O06 | BACKUP / VEEAM-REPO-001 | Repository observations support backup protection review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| FFIEC-AIO-O04 | WINDOWS / WIN-INVENTORY-COVERAGE-001 | Host population observations support IT asset management. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| FFIEC-AIO-O04 | NETWORK / NET-INVENTORY-001 | Network device inventory supports IT asset management. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| FFIEC-AIO-O13 | CERTTLS / CERTTLS-POSTURE-001 | Endpoint transport observations support infrastructure security review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| FFIEC-AIO-O14 | WINDOWS / WIN-AV-001 | Endpoint protection supports operational safeguard review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| FFIEC-DAM-O13 | WINDOWS / WIN-PATCH-INVENTORY-001 | Installed patch inventory supports maintenance review; change approval and testing remain manual. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
What requires manual review
Confirm scope and applicability, review the requirement guidance, collect policies and records, conduct interviews or observations where needed, and assess evidence relevance and freshness. Record owners, rationale, workpaper conclusions and remediation. An assessor makes the final decision; a technical pass does not approve the whole framework.
Seven core IT booklets: Audit; Business Continuity Management; Development, Acquisition, and Maintenance; Information Security; Management; Architecture, Infrastructure, and Operations; Outsourcing Technology Services. Payments-system and supervisory-program booklets and agency-specific requirements need separate review. This is examination preparation, not the retired FFIEC CAT, an official rating, or a regulatory examination. Scope steps according to risk and applicable regulator guidance. Original IT Audit Factory preparation workpapers with public U.S. government source references. ITAF identifiers are not official assessment procedure IDs. No paid or proprietary control catalog is bundled. No publisher or government endorsement is implied.
Where it is available
This preparation framework is listed in the C32 Professional/MSP application catalog. Free retains its ISO assessment limits. Availability of a framework is separate from the extent of automated scanning.
Coverage shown here comes from the application’s C32 requirement and mapping catalogs.