SEC Regulation S-P — safeguards
27 scoped preparation workpapers and 54 evidence review actions
All available frameworksWhat the app checks
Technical checks run for the selected scope, available connectors and credentials. Results provide evidence for review; missing data is not a pass.
Explicit requirement-to-test mappings
| Requirement | Collector / test | What it checks or supports |
|---|---|---|
| SEC-REGSP-INFORMATION | WINDOWS / WIN-INVENTORY-COVERAGE-001 | Host inventory supports customer-information system reconciliation. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| SEC-REGSP-CONFIDENTIALITY | CERTTLS / CERTTLS-POSTURE-001 | Endpoint TLS observations support transport protection review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| SEC-REGSP-CONFIDENTIALITY | STORAGE / STOR-AT-REST-ENCRYPTION-001 | Storage encryption observations support confidentiality review on authorized selected storage. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| SEC-REGSP-THREATS | VULN / VULN-HIGH-001 | Imported high-severity findings support vulnerability risk review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| SEC-REGSP-UNAUTHORIZED | ADSEC / AD-LIFECYCLE-001 | Stale enabled accounts support identity-lifecycle review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
| SEC-REGSP-UNAUTHORIZED | ADSEC / AD-PRIV-001 | Privileged group observations support authorized-access review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision. |
What requires manual review
Confirm scope and applicability, review the requirement guidance, collect policies and records, conduct interviews or observations where needed, and assess evidence relevance and freshness. Record owners, rationale, workpaper conclusions and remediation. An assessor makes the final decision; a technical pass does not approve the whole framework.
Preparation for the amended safeguards, disposal, records and annual-notice provisions. Determine covered-entity status and institution-specific recordkeeping rules with qualified review. This is not the entire Regulation S-P privacy-rule catalog. Notification decisions and submissions remain the institution's responsibility; no notices are sent automatically. Original IT Audit Factory preparation workpapers with public U.S. government source references. ITAF identifiers are not official assessment procedure IDs. No paid or proprietary control catalog is bundled. No publisher or government endorsement is implied.
Where it is available
This preparation framework is listed in the C32 Professional/MSP application catalog. Free retains its ISO assessment limits. Availability of a framework is separate from the extent of automated scanning.
Coverage shown here comes from the application’s C32 requirement and mapping catalogs.