# 7. Security Audits

User Type: **Super Administrator**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 7. Security Audits

### 7.1 Regular Security Audits
**What it does:** Performs the regular security audits: the audit of the security (the audit, the scope, the finding, the date) is performed regularly, so the security is audited (the audit is the review). The Super Administrator performs the regular security audits (the audit, the scope, the finding, the date) so the audit is structured and the review is explicit.

**Sub-features:**
- Audit: the audit (the audit, the scope, the finding, the date)
- Scope: the scope (the scope of the audit, the area, the date)
- Finding: the finding (the finding of the audit, the issue, the date)
- Audit frequency: the frequency (the frequency of the audit, e.g., the monthly, the quarterly)
- Audit status: the status (the completed, the in-progress, the scheduled)
- Audit count: the count (the count of the audits)
- Audit view: the view (the audits, the scopes, the findings, the dates)
- Audit logging of the security audits

**Super Administrator User Journey:**
1. Super Admin performs the regular security audit: the audit (the audit, the scope, the finding, the date), the scope (the scope of the audit, the area, the date), and the finding (the finding of the audit, the issue, the date); the audit is explicit.
2. Sets the scope: the scope (the scope of the audit, the area, the date); the scope is the boundary.
3. Records the finding: the finding (the finding of the audit, the issue, the date); the finding is the result.
4. Sets the audit frequency: the frequency (the frequency of the audit, e.g., the monthly, the quarterly); the frequency is the cadence.
5. Views the audit status: the status (the completed, the in-progress, the scheduled); the status is the state.
6. Views the audit count: the count (the count of the audits); the count is the measure.
7. The security is audited: the audits, the scopes, the findings, the dates, so the review is complete.
8. The security audits are audit-logged with the audit, the scope, and the timestamp.

**Rules & Edge Cases:**
- The audit is the review (the audit, the scope, the finding, the date); the audit is the inspection.
- The scope is the boundary (the scope of the audit, the area, the date); the scope is the limit.
- The finding is the result (the finding of the audit, the issue, the date); the finding is the issue.
- The audit frequency is the cadence (the frequency of the audit, e.g., the monthly, the quarterly); the frequency is the rhythm.
- The security is audited (the audits, the scopes, the findings, the dates); the review is managed.
- Security audits are audit-logged with the audit, scope, and timestamp.

### 7.2 Audit Logging and Review
**What it does:** Logs and reviews the audits: the log of the audits (the log, the action, the user, the date) is recorded, and the review (the review, the log, the date) is done, so the audits are logged and reviewed (the log is the record). The Super Administrator logs and reviews the audits (the log, the action, the user, the date) so the log is structured and the record is explicit.

**Sub-features:**
- Log: the log (the log, the action, the user, the date)
- Action: the action (the action of the log, the type, the date)
- User: the user (the user, the name, the log)
- Review: the review (the review, the log, the date)
- Log status: the status (the logged, the reviewed)
- Log count: the count (the count of the logs)
- Log view: the view (the logs, the actions, the users, the dates)
- Audit logging of the audit logging and review

**Super Administrator User Journey:**
1. Super Admin logs and reviews the audit: the log (the log, the action, the user, the date), the action (the action of the log, the type, the date), and the user (the user, the name, the log); the log is explicit.
2. Records the action: the action (the action of the log, the type, the date); the action is the event.
3. Selects the user: the user (the user, the name, the log); the user is the actor.
4. Performs the review: the review (the review, the log, the date); the review is the check.
5. Views the log status: the status (the logged, the reviewed); the status is the state.
6. Views the log count: the count (the count of the logs); the count is the measure.
7. The audits are logged and reviewed: the logs, the actions, the users, the dates, so the record is complete.
8. The audit logging and review is audit-logged with the log, the action, and the timestamp.

**Rules & Edge Cases:**
- The log is the record (the log, the action, the user, the date); the log is the trail.
- The action is the event (the action of the log, the type, the date); the action is the occurrence.
- The user is the actor (the user, the name, the log); the user is the performer.
- The review is the check (the review, the log, the date); the review is the inspection.
- The audits are logged and reviewed (the logs, the actions, the users, the dates); the record is managed.
- Audit logging and review is audit-logged with the log, action, and timestamp.
