Control calendar
Cadence comes from policy — it is what an auditor measures. How often a collector samples is a separate thing, shown on the Collectors page.
| Control | Status | Cadence | Last | Next due | TSC | Description |
|---|---|---|---|---|---|---|
| IS-02:AC-03 | No evidence | Monthly | — | — | CC6.1 | MFA enforced on all applicable systems |
| IS-02:AC-04 | No evidence | Quarterly | — | — | CC6.2 | Quarterly review of Access Matrix — verify users, roles, remove stale acc… |
| IS-02:AC-05 | No evidence | Quarterly | — | — | CC6.1 | Privileged access restricted to CTO, Head of People, CEO; reviewed quarte… |
| IS-02:AC-08 | No evidence | Monthly | — | — | CC6.1 | Password policy enforced: complexity, rotation, vault storage |
| IS-02:AC-01 | Event-driven | Event-driven | — | — | CC6.1 | Access provisioned upon hire per Access Matrix and least privilege |
| IS-02:AC-02 | Event-driven | Event-driven | — | — | CC6.3 | Access revoked no later than final working day; immediate for high-risk |
| IS-02:AC-06 | Event-driven | Event-driven | — | — | CC6.3 | Supplier / vendor access time-bound, MFA required, logged, removed on com… |
| IS-02:AC-07 | Event-driven | Continuous | — | — | CC6.1 | Customer environments segregated per org; support access logged |
| IS-02:AC-09 | Event-driven | Continuous | — | — | CC6.1 | BYOD mitigated via cloud-only access, MFA, RBAC, session revocation manual |
9 controls shown.