IT Audit Factory — evidence-first audit & compliance operations
Free • Professional • MSP
Frameworks & Controls

SEC Regulation S-P — safeguards

27 scoped preparation workpapers and 54 evidence review actions

All available frameworks

What the app checks

Technical checks run for the selected scope, available connectors and credentials. Results provide evidence for review; missing data is not a pass.

Explicit requirement-to-test mappings

RequirementCollector / testWhat it checks or supports
SEC-REGSP-INFORMATIONWINDOWS / WIN-INVENTORY-COVERAGE-001Host inventory supports customer-information system reconciliation. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
SEC-REGSP-CONFIDENTIALITYCERTTLS / CERTTLS-POSTURE-001Endpoint TLS observations support transport protection review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
SEC-REGSP-CONFIDENTIALITYSTORAGE / STOR-AT-REST-ENCRYPTION-001Storage encryption observations support confidentiality review on authorized selected storage. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
SEC-REGSP-THREATSVULN / VULN-HIGH-001Imported high-severity findings support vulnerability risk review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
SEC-REGSP-UNAUTHORIZEDADSEC / AD-LIFECYCLE-001Stale enabled accounts support identity-lifecycle review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.
SEC-REGSP-UNAUTHORIZEDADSEC / AD-PRIV-001Privileged group observations support authorized-access review. Partial supporting observation only; verify the scoped population and actual operation. No automatic conformity decision.

What requires manual review

Confirm scope and applicability, review the requirement guidance, collect policies and records, conduct interviews or observations where needed, and assess evidence relevance and freshness. Record owners, rationale, workpaper conclusions and remediation. An assessor makes the final decision; a technical pass does not approve the whole framework.

Preparation for the amended safeguards, disposal, records and annual-notice provisions. Determine covered-entity status and institution-specific recordkeeping rules with qualified review. This is not the entire Regulation S-P privacy-rule catalog. Notification decisions and submissions remain the institution's responsibility; no notices are sent automatically. Original IT Audit Factory preparation workpapers with public U.S. government source references. ITAF identifiers are not official assessment procedure IDs. No paid or proprietary control catalog is bundled. No publisher or government endorsement is implied.

Where it is available

This preparation framework is listed in the C32 Professional/MSP application catalog. Free retains its ISO assessment limits. Availability of a framework is separate from the extent of automated scanning.

Coverage shown here comes from the application’s C32 requirement and mapping catalogs.