Control calendar
Cadence comes from policy — it is what an auditor measures. How often a collector samples is a separate thing, shown on the Collectors page.
| Control | Status | Cadence | Last | Next due | TSC | Description |
|---|---|---|---|---|---|---|
| IS-02:AC-03 | No evidence | Monthly | — | — | CC6.1 | MFA enforced on all applicable systems |
| IS-02:AC-04 | No evidence | Quarterly | — | — | CC6.2 | Quarterly review of Access Matrix — verify users, roles, remove stale acc… |
| IS-02:AC-05 | No evidence | Quarterly | — | — | CC6.1 | Privileged access restricted to CTO, Head of People, CEO; reviewed quarte… |
| IS-02:AC-08 | No evidence | Monthly | — | — | CC6.1 | Password policy enforced: complexity, rotation, vault storage |
| IS-07:IR-05 | No evidence | Semi-annual | — | — | CC7.5 | Tabletop exercise with scenario, participants, findings, remediation docu… manual |
| IS-07:IR-06 | No evidence | Annual | — | — | CC7.5 | Full-scale IR test or formal tabletop conducted and documented annually manual |
| IS-07:IR-07 | No evidence | Annual | — | — | CC7.3 | All employees receive IR awareness training; IRT specialised training ann… |
| IS-11:VM-01 | No evidence | Weekly | — | — | CC7.1 | Weekly authenticated internal vulnerability scans on all critical systems |
| IS-11:VM-02 | No evidence | Monthly | — | — | CC7.1 | Monthly external-facing system vulnerability scans (the quarterly third-p… |
| IS-11:VM-02-3P | No evidence | Quarterly | — | — | CC7.1 | Quarterly third-party external scanning for independent validation. Compo… manual |
| IS-11:VM-03 | No evidence | Bi-weekly | — | — | CC7.1 | Bi-weekly automated web application scanning vs OWASP Top 10, CI/CD integ… |
| IS-11:VM-06 | No evidence | Quarterly | — | — | CC7.2 | Quarterly formal review of scan trends; critical/high closed or risk-acce… |
| IS-11:VM-07 | No evidence | Monthly | — | — | CC7.2 | Risk exceptions approved by Security Officer or Executive; reviewed month… manual |
| IS-11:VM-08-SCA | No evidence | Weekly | — | — | CC7.1 | Software composition analysis tracks third-party components. Component of… |
| IT-02:BC-01 | No evidence | Daily | — | — | A1.2 | Automated daily database backups; repositories version-controlled |
| IT-02:BC-02 | No evidence | Annual | — | — | A1.2 | RTO of 4 hours and RPO of 1 hour defined and documented |
| IT-02:BC-03 | No evidence | Annual | — | — | A1.2 | Recovery procedures documented; runbooks maintained; roles defined manual |
| IT-02:BC-05 | No evidence | Semi-annual | — | — | A1.2 | Semi-annual BC/DR readiness review with evidence captured manual |
| IT-02:BC-06 | No evidence | Annual | — | — | A1.3 | Annual formal BC/DR test: date, participants, results, corrective actions |
| IT-02:BC-08 | No evidence | Annual | — | — | A1.2 | All critical roles can operate remotely; no physical office dependency manual |
| IT-03:AM-01 | No evidence | Quarterly | — | — | CC7.1 | Asset inventory maintained, classified by criticality, and kept current |
| IT-04:NET-01 | No evidence | Quarterly | — | — | CC6.1 | §5.1 Production and customer-data environments isolated from non-producti… |
| IT-04:NET-02 | No evidence | Annual | — | — | CC6.6 | §6 Firewalls restrict inbound/outbound traffic; only approved ports permi… |
| IT-04:NET-03 | No evidence | Annual | — | — | CC6.6 | §6.2 Firewall configurations reviewed at least annually; changes tracked |
| IT-04:NET-04 | No evidence | Annual | — | — | CC6.6 | §7 Data in transit encrypted with industry-standard protocols; deprecated… |
| IT-04:NET-05 | No evidence | Annual | — | — | CC6.6 | §10 System and network hardening standards maintained and reviewed annual… |
| IT-04:NET-07 | No evidence | Quarterly | — | — | CC6.6CC6.7 | §5 Remote access to production occurs only over an encrypted channel |
| IT-04:NET-08 | No evidence | Quarterly | — | — | CC6.1 | §5 Remote access to production requires MFA; no shared or hardcoded crede… manual |
| IT-05:CM-07 | No evidence | Quarterly | — | — | CC8.1 | Version-controlled configs, environment consistency, drift prevention |
| LEG-01:VM-05 | No evidence | Annual | — | — | CC9.2 | Annual review of all vendors; high-risk vendors reviewed quarterly manual |
| LEG-01:VM-08 | No evidence | Annual | — | — | CC9.1 | High-risk vendors: invoices, contracts and SOC reports maintained |
| IS-02:AC-01 | Event-driven | Event-driven | — | — | CC6.1 | Access provisioned upon hire per Access Matrix and least privilege |
| IS-02:AC-02 | Event-driven | Event-driven | — | — | CC6.3 | Access revoked no later than final working day; immediate for high-risk |
| IS-02:AC-06 | Event-driven | Event-driven | — | — | CC6.3 | Supplier / vendor access time-bound, MFA required, logged, removed on com… |
| IS-02:AC-07 | Event-driven | Continuous | — | — | CC6.1 | Customer environments segregated per org; support access logged |
| IS-02:AC-09 | Event-driven | Continuous | — | — | CC6.1 | BYOD mitigated via cloud-only access, MFA, RBAC, session revocation manual |
| IS-07:IR-01 | Event-driven | Continuous | — | — | CC7.3 | Security monitoring continuous; incidents triaged and classified within 3… |
| IS-07:IR-02 | Event-driven | Event-driven | — | — | CC7.3 | All incidents logged in Jira with type, severity, actions, resolution |
| IS-07:IR-03 | Event-driven | Event-driven | — | — | CC7.4 | P1/P2 incidents escalated to executives; regulatory notification in requi… manual |
| IS-07:IR-04 | Event-driven | Event-driven | — | — | CC7.5 | Post-incident review conducted; lessons learned documented manual |
| IS-07:IR-08 | Event-driven | Event-driven | — | — | CC7.4 | Vendor incident response requirements in contracts; notification within 1… manual |
| IS-11:VM-04 | Event-driven | Per scan | — | — | CC7.2 | CVSS-based risk scoring and P0–P5 prioritisation applied to all findings |
| IS-11:VM-05 | Event-driven | Event-driven | — | — | CC7.2 | P0: patch within 24h if available; workaround within 48h if not |
| IS-11:VM-08 | Event-driven | Continuous | — | — | CC7.1 | Vendors disclose vulnerabilities within 24h (the software composition ana… |
| IT-02:BC-04 | Event-driven | Event-driven | — | — | CC7.5 | BC/DR activation only through the formal Incident Escalation workflow manual |
| IT-02:BC-07 | Event-driven | Event-driven | — | — | A1.3 | Post-disaster root cause analysis and corrective actions documented manual |
| IT-04:NET-06 | Event-driven | Continuous | — | — | CC7.2 | §9 Network activity logged and reviewed to detect unauthorised activity |
| IT-05:CM-01 | Event-driven | Per change | — | — | CC8.1 | Production changes documented in Jira with risk, test evidence, rollback … |
| IT-05:CM-02 | Event-driven | Per change | — | — | CC8.1 | Normal changes require independent reviewer approval before deployment |
| IT-05:CM-03 | Event-driven | Per change | — | — | CC8.1 | Changes tested or validated prior to deployment; evidence documented |
| IT-05:CM-04 | Event-driven | Continuous | — | — | CC8.1 | Only authorized personnel may implement production changes |
| IT-05:CM-05 | Event-driven | Event-driven | — | — | CC8.2 | Emergency changes documented immediately, approved post-implementation |
| IT-05:CM-06 | Event-driven | Continuous | — | — | CC8.1 | Change activity logged capturing who, when, and what was changed |
| IT-05:CM-08 | Event-driven | Event-driven | — | — | CC8.2 | Post-implementation review for emergency changes manual |
| LEG-01:VM-01 | Event-driven | Event-driven | — | — | CC9.1 | All vendors risk-assessed and classified (Low/Medium/High) before engagem… manual |
| LEG-01:VM-02 | Event-driven | Event-driven | — | — | CC9.1 | Vendor agreements include confidentiality, data protection, security obli… manual |
| LEG-01:VM-03 | Event-driven | Event-driven | — | — | CC9.1 | Vendor access approved, documented, time-bound, minimum required resources |
| LEG-01:VM-04 | Event-driven | Event-driven | — | — | CC9.1 | All vendors recorded in the Vendor Register before access is granted |
| LEG-01:VM-06 | Event-driven | Event-driven | — | — | CC9.2 | Vendor access revoked immediately on contract termination or completion |
| LEG-01:VM-07 | Event-driven | Event-driven | — | — | CC9.2 | Vendor security incidents reported and handled per IS-07 manual |
60 controls shown.