Auditing toolkit¶
The toolkit is the reference layer that applies across all four frameworks: the concepts and obligations, the working methods, the audit process itself, and the tooling. For a reader arriving from a playbook stage, the map points at the tools that usually apply there.
Arriving from |
Worth opening |
|---|---|
Choosing and scoping a route (the map room, exploring the crossing, the floor walk, surveying the fortress) |
Scope definition, ISO/IEC standards, OT/ICS standards, EU regulations |
Assessing risk and impact (the risk tent, understanding the river, storm charts, knowing the besiegers) |
Threat register, Risk scoring, Business impact analysis, Arrows and shields, Interview facilitation |
Building the controls (the gear depot, building a raft, the emergency systems, walls and gates, locks and patrols) |
|
Operating and testing (the climb, into the current, running the drills, testing the defences) |
|
Facing the audit (base camp checks, the summit push, the far bank, the dossier, the inspection) |
Evidence, Findings and reporting, Certification bodies, Interview facilitation |
Staying compliant (the flag, staying afloat, after the storm, keeping watch) |
Continuous monitoring, Corrective action, AI tooling, BI tooling |
References¶
The vocabulary: what is being protected, what attacks it, and which standards and laws frame it.
Methods¶
Drawing boundaries, weighing impact and risk, and building the evidence base.
Audit process¶
Gathering testimony, receiving findings, fixing at the right level, and living with auditors.
Tooling¶
AI and BI options for evidence work at scale.
Last updated: 8 July 2026