Context and applicability before answering
Organizations configure context once and reuse it. Before the questionnaire they can decide which controls apply, do not apply or are out of scope, with a rationale for each exclusion.
- Context is stored with the audit
- Exclusions remain visible in results and exports
- N/A and out-of-scope controls do not lower the score
Framework-specific remediation
Recommendations include actions, suggested owners, expected evidence, acceptance criteria, effort, tools and future review. Tasks keep the source control context.
- Operational closure shows pending, completed and overdue work
- A completed task does not automatically make a control compliant
- Re-audits recalculate the result from actual progress
Representative scoring and security
YES, PARTIAL and NO have proportional impact and controls can be weighted. Server validation keeps calculations consistent. Drafts, saving and 2FA deactivation were also hardened.
- Audits can be saved and resumed
- Sessions are invalidated when 2FA is disabled
- Mandatory-2FA plans cannot remove it