DeftTrust

Control evidence

60 controls across the seeded policy set. Status is computed from stored artifacts, not from whether a scheduled job fired.

0
Overdue
Evidence older than the cadence allows
31
No evidence
Never collected
0
Current
Within cadence
29
Event-driven
No clock — evidenced per event
9/41
Automated
Of the controls a collector could satisfy
0
Collectors failing
Latest attempt failed — 0 failed artifacts
0
Artifacts
Stored, append-only
0
Assets in scope
Hosts and domains observed
9
Collectors
Registered and scheduled

Needs attention (31)

ControlStatusCadenceLast evidenceDescription
IS-02:AC-03 No evidence Monthly MFA enforced on all applicable systems
IS-02:AC-04 No evidence Quarterly Quarterly review of Access Matrix — verify users, roles, remove stale access
IS-02:AC-05 No evidence Quarterly Privileged access restricted to CTO, Head of People, CEO; reviewed quarterly
IS-02:AC-08 No evidence Monthly Password policy enforced: complexity, rotation, vault storage
IS-07:IR-05 No evidence Semi-annual Tabletop exercise with scenario, participants, findings, remediation documented
IS-07:IR-06 No evidence Annual Full-scale IR test or formal tabletop conducted and documented annually
IS-07:IR-07 No evidence Annual All employees receive IR awareness training; IRT specialised training annually
IS-11:VM-01 No evidence Weekly Weekly authenticated internal vulnerability scans on all critical systems
IS-11:VM-02 No evidence Monthly Monthly external-facing system vulnerability scans (the quarterly third-party validatio…
IS-11:VM-02-3P No evidence Quarterly Quarterly third-party external scanning for independent validation. Component of IS-11 …
IS-11:VM-03 No evidence Bi-weekly Bi-weekly automated web application scanning vs OWASP Top 10, CI/CD integrated
IS-11:VM-06 No evidence Quarterly Quarterly formal review of scan trends; critical/high closed or risk-accepted

Showing 12 of 31 — see all overdue.

Recent evidence

CollectedCollectorResultSatisfiesSource
No evidence collected yet. Run a collector.