# 7. Security Audits — Test Cases

User Type: **Super Administrator**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: security_audits.md — every feature, sub-feature, and rule covered

---

## Test Execution Policy
- Zero tolerance: any deviation from documented behavior = FAILED = bug
- Every bug is immediately logged/reported (Bug ID, feature, sub-feature,
  expected vs actual, severity) and fixed 100% before the group passes
- Feature group passes only at 100% test pass rate

## Coverage Matrix
| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 7.1 Regular Security Audits | Audit: the audit (the audit, the scope, the finding, the date) | TC-SA-22-07-001 |
| 7.1 Regular Security Audits | Scope: the scope (the scope of the audit, the area, the date) | TC-SA-22-07-002 |
| 7.1 Regular Security Audits | Finding: the finding (the finding of the audit, the issue, the date) | TC-SA-22-07-003 |
| 7.1 Regular Security Audits | Audit frequency: the frequency (the frequency of the audit, e.g., the monthly, the quarterly) | TC-SA-22-07-004 |
| 7.1 Regular Security Audits | Audit status: the status (the completed, the in-progress, the scheduled) | TC-SA-22-07-005 |
| 7.1 Regular Security Audits | Audit count: the count (the count of the audits) | TC-SA-22-07-006 |
| 7.1 Regular Security Audits | Audit view: the view (the audits, the scopes, the findings, the dates) | TC-SA-22-07-007 |
| 7.1 Regular Security Audits | Audit logging of the security audits | TC-SA-22-07-008 |
| 7.1 Regular Security Audits | Rule: the audit is the review (the audit, the scope, the finding, the date); the audit is the inspection | TC-SA-22-07-001 |
| 7.1 Regular Security Audits | Rule: the scope is the boundary (the scope of the audit, the area, the date); the scope is the limit | TC-SA-22-07-002 |
| 7.1 Regular Security Audits | Rule: the finding is the result (the finding of the audit, the issue, the date); the finding is the issue | TC-SA-22-07-003 |
| 7.1 Regular Security Audits | Rule: the audit frequency is the cadence (the frequency of the audit, e.g., the monthly, the quarterly); the frequency is the rhythm | TC-SA-22-07-004 |
| 7.1 Regular Security Audits | Rule: the security is audited (the audits, the scopes, the findings, the dates); the review is managed | TC-SA-22-07-007 |
| 7.1 Regular Security Audits | Rule: security audits are audit-logged with the audit, scope, and timestamp | TC-SA-22-07-008 |
| 7.2 Audit Logging and Review | Log: the log (the log, the action, the user, the date) | TC-SA-22-07-009 |
| 7.2 Audit Logging and Review | Action: the action (the action of the log, the type, the date) | TC-SA-22-07-010 |
| 7.2 Audit Logging and Review | User: the user (the user, the name, the log) | TC-SA-22-07-011 |
| 7.2 Audit Logging and Review | Review: the review (the review, the log, the date) | TC-SA-22-07-012 |
| 7.2 Audit Logging and Review | Log status: the status (the logged, the reviewed) | TC-SA-22-07-013 |
| 7.2 Audit Logging and Review | Log count: the count (the count of the logs) | TC-SA-22-07-014 |
| 7.2 Audit Logging and Review | Log view: the view (the logs, the actions, the users, the dates) | TC-SA-22-07-015 |
| 7.2 Audit Logging and Review | Audit logging of the audit logging and review | TC-SA-22-07-016 |
| 7.2 Audit Logging and Review | Rule: the log is the record (the log, the action, the user, the date); the log is the trail | TC-SA-22-07-009 |
| 7.2 Audit Logging and Review | Rule: the action is the event (the action of the log, the type, the date); the action is the occurrence | TC-SA-22-07-010 |
| 7.2 Audit Logging and Review | Rule: the user is the actor (the user, the name, the log); the user is the performer | TC-SA-22-07-011 |
| 7.2 Audit Logging and Review | Rule: the review is the check (the review, the log, the date); the review is the inspection | TC-SA-22-07-012 |
| 7.2 Audit Logging and Review | Rule: the audits are logged and reviewed (the logs, the actions, the users, the dates); the record is managed | TC-SA-22-07-015 |
| 7.2 Audit Logging and Review | Rule: audit logging and review is audit-logged with the log, action, and timestamp | TC-SA-22-07-016 |

## 7.1 Regular Security Audits

### TC-SA-22-07-001 — Audit: the audit (the audit, the scope, the finding, the date); the audit is the inspection
**Type:** Positive
**Covers:** 7.1 → Audit: the audit (the audit, the scope, the finding, the date); Rule: the audit is the review (the audit, the scope, the finding, the date); the audit is the inspection
**Preconditions:** Super Admin is logged in; a security audit has been performed.
**Steps:**
1. Open Data Protection & Compliance → Security Audits → Regular Security Audits.
2. Record the audit: the audit (the audit, the scope, the finding, the date) — verify the audit is the review.
3. Verify the audit shows the scope, the finding, and the date.
4. Verify the audit covers the documented security areas (access control, data protection, content protection).
**Expected Result:** The audit is recorded — the audit, the scope, the finding, and the date are the inspection.
**Priority:** Critical

### TC-SA-22-07-002 — Scope: the scope (the scope of the audit, the area, the date); the scope is the limit
**Type:** Positive
**Covers:** 7.1 → Scope: the scope (the scope of the audit, the area, the date); Rule: the scope is the boundary (the scope of the audit, the area, the date); the scope is the limit
**Preconditions:** Audits with different scopes exist.
**Steps:**
1. Select the scope: the scope (the scope of the audit, the area, the date) — verify the scope is the boundary.
2. Verify the scope shows the area and the date.
3. Verify each audit is limited to its declared scope (no out-of-scope areas are reported as findings).
**Expected Result:** The scope is selected — the scope of the audit, the area, and the date are the limit.
**Priority:** High

### TC-SA-22-07-003 — Finding: the finding (the finding of the audit, the issue, the date); the finding is the issue
**Type:** Edge
**Covers:** 7.1 → Finding: the finding (the finding of the audit, the issue, the date); Rule: the finding is the result (the finding of the audit, the issue, the date); the finding is the issue
**Preconditions:** Audits with findings exist; an audit that discovers a critical security issue (critical-finding edge) is also prepared.
**Steps:**
1. View the finding: the finding (the finding of the audit, the issue, the date) — verify the finding is the result.
2. Verify the finding shows the issue and the date.
3. Check the critical finding — verify it is flagged with the documented severity and triggers the documented remediation workflow (alert to Super Admin, tracked to closure); a critical finding is never left untracked.
**Expected Result:** The finding is shown — the finding of the audit, the issue, and the date are the issue; critical findings always trigger documented remediation.
**Priority:** High

### TC-SA-22-07-004 — Audit frequency: the frequency (the frequency of the audit, e.g., the monthly, the quarterly); the frequency is the rhythm
**Type:** Edge
**Covers:** 7.1 → Audit frequency: the frequency (the frequency of the audit, e.g., the monthly, the quarterly); Rule: the audit frequency is the cadence (the frequency of the audit, e.g., the monthly, the quarterly); the frequency is the rhythm
**Preconditions:** Audit frequency is set to monthly; a scenario where a monthly audit is missed (missed-cadence edge) is also prepared.
**Steps:**
1. Set the audit frequency: the frequency (the frequency of the audit, e.g., the monthly, the quarterly) — verify the frequency is the cadence.
2. Verify audits are scheduled per the frequency.
3. Let the monthly audit be missed — verify the system raises the documented alert (overdue-audit notification to Super Admin); a missed audit cadence is never silent.
**Expected Result:** The audit frequency is set — the frequency of the audit (the monthly, the quarterly) is the rhythm; missed cadences always alert.
**Priority:** High

### TC-SA-22-07-005 — Audit status: the status (the completed, the in-progress, the scheduled); the status is the control
**Type:** Positive
**Covers:** 7.1 → Audit status: the status (the completed, the in-progress, the scheduled); Rule: the audit status is the state (the completed, the in-progress, the scheduled); the status is the control
**Preconditions:** Audits with completed, in-progress, and scheduled statuses exist.
**Steps:**
1. View the audit status: the status (the completed, the in-progress, the scheduled) — verify the audit status is the state.
2. Verify a new audit shows scheduled, moves to in-progress when started, and to completed when finished.
3. Verify status transitions are sequential (no audit jumps from scheduled to completed without being in-progress).
**Expected Result:** The audit status is shown — the completed, the in-progress, and the scheduled are the control; transitions are always sequential.
**Priority:** High

### TC-SA-22-07-006 — Audit count: the count (the count of the audits); the count is the measure
**Type:** Positive
**Covers:** 7.1 → Audit count: the count (the count of the audits)
**Preconditions:** Multiple audits exist.
**Steps:**
1. View the audit count: the count (the count of the audits) — verify the count is the measure.
2. Verify the count matches the actual number of audits.
3. Complete a new audit — verify the count increments.
**Expected Result:** The audit count is shown — the count of the audits is the measure.
**Priority:** High

### TC-SA-22-07-007 — Audit view: the view (the audits, the scopes, the findings, the dates); the review is managed
**Type:** Positive
**Covers:** 7.1 → Audit view: the view (the audits, the scopes, the findings, the dates); Rule: the security is audited (the audits, the scopes, the findings, the dates); the review is managed
**Preconditions:** Multiple audits exist.
**Steps:**
1. View the audits: the view (the audits, the scopes, the findings, the dates) — verify the security is audited.
2. Verify each audit shows the scope, the finding, and the date.
3. Verify the review is managed (view, schedule, run, close).
**Expected Result:** The audits are viewed — the audits, the scopes, the findings, and the dates are visible; the review is managed.
**Priority:** High

### TC-SA-22-07-008 — Security audits are audit-logged with the audit, scope, and timestamp
**Type:** Positive
**Covers:** 7.1 → Audit logging of the security audits; Rule: security audits are audit-logged with the audit, scope, and timestamp
**Preconditions:** Super Admin has recorded a security audit.
**Steps:**
1. Open the audit trail and filter by "security audit".
2. Verify entries show the audit, the scope, and the timestamp.
**Expected Result:** The security audits are audit-logged with the audit, scope, and timestamp.
**Priority:** Critical

## 7.2 Audit Logging and Review

### TC-SA-22-07-009 — Log: the log (the log, the action, the user, the date); the log is the trail
**Type:** Positive
**Covers:** 7.2 → Log: the log (the log, the action, the user, the date); Rule: the log is the record (the log, the action, the user, the date); the log is the trail
**Preconditions:** Super Admin is logged in; platform actions have generated log entries.
**Steps:**
1. Open Data Protection & Compliance → Security Audits → Audit Logging and Review.
2. Review the log: the log (the log, the action, the user, the date) — verify the log is the record.
3. Verify the log shows the action, the user, and the date.
4. Verify the log is tamper-evident (entries cannot be edited or deleted by any role, including Super Admin).
**Expected Result:** The log is recorded — the log, the action, the user, and the date are the trail; no entry can be altered or removed.
**Priority:** Critical

### TC-SA-22-07-010 — Action: the action (the action of the log, the type, the date); the action is the occurrence
**Type:** Positive
**Covers:** 7.2 → Action: the action (the action of the log, the type, the date); Rule: the action is the event (the action of the log, the type, the date); the action is the occurrence
**Preconditions:** Logs with various action types exist.
**Steps:**
1. Select the action: the action (the action of the log, the type, the date) — verify the action is the event.
2. Verify the action shows the type and the date.
3. Verify logs can be filtered by action type.
**Expected Result:** The action is selected — the action of the log, the type, and the date are the occurrence.
**Priority:** High

### TC-SA-22-07-011 — User: the user (the user, the name, the log); the user is the performer
**Type:** Positive
**Covers:** 7.2 → User: the user (the user, the name, the log); Rule: the user is the actor (the user, the name, the log); the user is the performer
**Preconditions:** Logs from multiple users exist.
**Steps:**
1. Select the user: the user (the user, the name, the log) — verify the user is the actor.
2. Verify the user shows the name and the log.
3. Verify each log entry is attributed to the correct performing user (no anonymous or misattributed entries).
**Expected Result:** The user is selected — the user, the name, and the log are the performer; every entry is correctly attributed.
**Priority:** High

### TC-SA-22-07-012 — Review: the review (the review, the log, the date); the review is the inspection
**Type:** Positive
**Covers:** 7.2 → Review: the review (the review, the log, the date); Rule: the review is the check (the review, the log, the date); the review is the inspection
**Preconditions:** Log entries exist that are pending review.
**Steps:**
1. Perform the review: the review (the review, the log, the date) — verify the review is the check.
2. Verify the review shows the log and the date.
3. Verify reviewed logs are marked as reviewed with the reviewer and the date.
**Expected Result:** The review is performed — the review, the log, and the date are the inspection; reviewed logs carry reviewer and date.
**Priority:** High

### TC-SA-22-07-013 — Log status: the status (the logged, the reviewed); the status is the control
**Type:** Edge
**Covers:** 7.2 → Log status: the status (the logged, the reviewed); Rule: the log status is the state (the logged, the reviewed); the status is the control
**Preconditions:** Logged and reviewed entries exist; a batch of new log entries that remain unreviewed past the documented review window (unreviewed-log edge) is also prepared.
**Steps:**
1. View the log status: the status (the logged, the reviewed) — verify the log status is the state.
2. Verify a new entry shows logged and moves to reviewed after the review.
3. Check the unreviewed batch — verify the documented escalation fires (alert to Super Admin / review queue priority); logs are never silently left unreviewed beyond the window.
**Expected Result:** The log status is shown — the logged and the reviewed are the control; unreviewed logs beyond the window always escalate.
**Priority:** High

### TC-SA-22-07-014 — Log count: the count (the count of the logs); the count is the measure
**Type:** Positive
**Covers:** 7.2 → Log count: the count (the count of the logs)
**Preconditions:** Multiple log entries exist.
**Steps:**
1. View the log count: the count (the count of the logs) — verify the count is the measure.
2. Verify the count matches the actual number of log entries.
3. Perform a new action — verify the count increments.
**Expected Result:** The log count is shown — the count of the logs is the measure.
**Priority:** High

### TC-SA-22-07-015 — Log view: the view (the logs, the actions, the users, the dates); the record is managed
**Type:** Positive
**Covers:** 7.2 → Log view: the view (the logs, the actions, the users, the dates); Rule: the audits are logged and reviewed (the logs, the actions, the users, the dates); the record is managed
**Preconditions:** Multiple log entries exist.
**Steps:**
1. View the logs: the view (the logs, the actions, the users, the dates) — verify the audits are logged and reviewed.
2. Verify each log shows the action, the user, and the date.
3. Verify the record is managed (view, filter, review, export for compliance).
**Expected Result:** The logs are viewed — the logs, the actions, the users, and the dates are visible; the record is managed.
**Priority:** High

### TC-SA-22-07-016 — Audit logging and review is audit-logged with the log, action, and timestamp
**Type:** Positive
**Covers:** 7.2 → Audit logging of the audit logging and review; Rule: audit logging and review is audit-logged with the log, action, and timestamp
**Preconditions:** Super Admin has reviewed log entries.
**Steps:**
1. Open the audit trail and filter by "audit logging and review".
2. Verify entries show the log, the action, and the timestamp.
**Expected Result:** The audit logging and review is audit-logged with the log, action, and timestamp.
**Priority:** Critical
