DeftTrust

Control calendar

Cadence comes from policy — it is what an auditor measures. How often a collector samples is a separate thing, shown on the Collectors page.

Status All Overdue No evidence Current Event-driven
Policy All IT-05 8 IT-03 1 IT-02 8 IS-02 9 IT-04 8 IS-11 10 IS-07 8 LEG-01 8
ControlStatusCadenceLastNext due TSCDescription
IS-02:AC-03 No evidence Monthly CC6.1 MFA enforced on all applicable systems
IS-02:AC-04 No evidence Quarterly CC6.2 Quarterly review of Access Matrix — verify users, roles, remove stale acc…
IS-02:AC-05 No evidence Quarterly CC6.1 Privileged access restricted to CTO, Head of People, CEO; reviewed quarte…
IS-02:AC-08 No evidence Monthly CC6.1 Password policy enforced: complexity, rotation, vault storage
IS-07:IR-05 No evidence Semi-annual CC7.5 Tabletop exercise with scenario, participants, findings, remediation docu… manual
IS-07:IR-06 No evidence Annual CC7.5 Full-scale IR test or formal tabletop conducted and documented annually manual
IS-07:IR-07 No evidence Annual CC7.3 All employees receive IR awareness training; IRT specialised training ann…
IS-11:VM-01 No evidence Weekly CC7.1 Weekly authenticated internal vulnerability scans on all critical systems
IS-11:VM-02 No evidence Monthly CC7.1 Monthly external-facing system vulnerability scans (the quarterly third-p…
IS-11:VM-02-3P No evidence Quarterly CC7.1 Quarterly third-party external scanning for independent validation. Compo… manual
IS-11:VM-03 No evidence Bi-weekly CC7.1 Bi-weekly automated web application scanning vs OWASP Top 10, CI/CD integ…
IS-11:VM-06 No evidence Quarterly CC7.2 Quarterly formal review of scan trends; critical/high closed or risk-acce…
IS-11:VM-07 No evidence Monthly CC7.2 Risk exceptions approved by Security Officer or Executive; reviewed month… manual
IS-11:VM-08-SCA No evidence Weekly CC7.1 Software composition analysis tracks third-party components. Component of…
IT-02:BC-01 No evidence Daily A1.2 Automated daily database backups; repositories version-controlled
IT-02:BC-02 No evidence Annual A1.2 RTO of 4 hours and RPO of 1 hour defined and documented
IT-02:BC-03 No evidence Annual A1.2 Recovery procedures documented; runbooks maintained; roles defined manual
IT-02:BC-05 No evidence Semi-annual A1.2 Semi-annual BC/DR readiness review with evidence captured manual
IT-02:BC-06 No evidence Annual A1.3 Annual formal BC/DR test: date, participants, results, corrective actions
IT-02:BC-08 No evidence Annual A1.2 All critical roles can operate remotely; no physical office dependency manual
IT-03:AM-01 No evidence Quarterly CC7.1 Asset inventory maintained, classified by criticality, and kept current
IT-04:NET-01 No evidence Quarterly CC6.1 §5.1 Production and customer-data environments isolated from non-producti…
IT-04:NET-02 No evidence Annual CC6.6 §6 Firewalls restrict inbound/outbound traffic; only approved ports permi…
IT-04:NET-03 No evidence Annual CC6.6 §6.2 Firewall configurations reviewed at least annually; changes tracked
IT-04:NET-04 No evidence Annual CC6.6 §7 Data in transit encrypted with industry-standard protocols; deprecated…
IT-04:NET-05 No evidence Annual CC6.6 §10 System and network hardening standards maintained and reviewed annual…
IT-04:NET-07 No evidence Quarterly CC6.6CC6.7 §5 Remote access to production occurs only over an encrypted channel
IT-04:NET-08 No evidence Quarterly CC6.1 §5 Remote access to production requires MFA; no shared or hardcoded crede… manual
IT-05:CM-07 No evidence Quarterly CC8.1 Version-controlled configs, environment consistency, drift prevention
LEG-01:VM-05 No evidence Annual CC9.2 Annual review of all vendors; high-risk vendors reviewed quarterly manual
LEG-01:VM-08 No evidence Annual CC9.1 High-risk vendors: invoices, contracts and SOC reports maintained
IS-02:AC-01 Event-driven Event-driven CC6.1 Access provisioned upon hire per Access Matrix and least privilege
IS-02:AC-02 Event-driven Event-driven CC6.3 Access revoked no later than final working day; immediate for high-risk
IS-02:AC-06 Event-driven Event-driven CC6.3 Supplier / vendor access time-bound, MFA required, logged, removed on com…
IS-02:AC-07 Event-driven Continuous CC6.1 Customer environments segregated per org; support access logged
IS-02:AC-09 Event-driven Continuous CC6.1 BYOD mitigated via cloud-only access, MFA, RBAC, session revocation manual
IS-07:IR-01 Event-driven Continuous CC7.3 Security monitoring continuous; incidents triaged and classified within 3…
IS-07:IR-02 Event-driven Event-driven CC7.3 All incidents logged in Jira with type, severity, actions, resolution
IS-07:IR-03 Event-driven Event-driven CC7.4 P1/P2 incidents escalated to executives; regulatory notification in requi… manual
IS-07:IR-04 Event-driven Event-driven CC7.5 Post-incident review conducted; lessons learned documented manual
IS-07:IR-08 Event-driven Event-driven CC7.4 Vendor incident response requirements in contracts; notification within 1… manual
IS-11:VM-04 Event-driven Per scan CC7.2 CVSS-based risk scoring and P0–P5 prioritisation applied to all findings
IS-11:VM-05 Event-driven Event-driven CC7.2 P0: patch within 24h if available; workaround within 48h if not
IS-11:VM-08 Event-driven Continuous CC7.1 Vendors disclose vulnerabilities within 24h (the software composition ana…
IT-02:BC-04 Event-driven Event-driven CC7.5 BC/DR activation only through the formal Incident Escalation workflow manual
IT-02:BC-07 Event-driven Event-driven A1.3 Post-disaster root cause analysis and corrective actions documented manual
IT-04:NET-06 Event-driven Continuous CC7.2 §9 Network activity logged and reviewed to detect unauthorised activity
IT-05:CM-01 Event-driven Per change CC8.1 Production changes documented in Jira with risk, test evidence, rollback …
IT-05:CM-02 Event-driven Per change CC8.1 Normal changes require independent reviewer approval before deployment
IT-05:CM-03 Event-driven Per change CC8.1 Changes tested or validated prior to deployment; evidence documented
IT-05:CM-04 Event-driven Continuous CC8.1 Only authorized personnel may implement production changes
IT-05:CM-05 Event-driven Event-driven CC8.2 Emergency changes documented immediately, approved post-implementation
IT-05:CM-06 Event-driven Continuous CC8.1 Change activity logged capturing who, when, and what was changed
IT-05:CM-08 Event-driven Event-driven CC8.2 Post-implementation review for emergency changes manual
LEG-01:VM-01 Event-driven Event-driven CC9.1 All vendors risk-assessed and classified (Low/Medium/High) before engagem… manual
LEG-01:VM-02 Event-driven Event-driven CC9.1 Vendor agreements include confidentiality, data protection, security obli… manual
LEG-01:VM-03 Event-driven Event-driven CC9.1 Vendor access approved, documented, time-bound, minimum required resources
LEG-01:VM-04 Event-driven Event-driven CC9.1 All vendors recorded in the Vendor Register before access is granted
LEG-01:VM-06 Event-driven Event-driven CC9.2 Vendor access revoked immediately on contract termination or completion
LEG-01:VM-07 Event-driven Event-driven CC9.2 Vendor security incidents reported and handled per IS-07 manual

60 controls shown.