Control calendar
Cadence comes from policy — it is what an auditor measures. How often a collector samples is a separate thing, shown on the Collectors page.
| Control | Status | Cadence | Last | Next due | TSC | Description |
|---|---|---|---|---|---|---|
| IS-11:VM-01 | No evidence | Weekly | — | — | CC7.1 | Weekly authenticated internal vulnerability scans on all critical systems |
| IS-11:VM-02 | No evidence | Monthly | — | — | CC7.1 | Monthly external-facing system vulnerability scans (the quarterly third-p… |
| IS-11:VM-02-3P | No evidence | Quarterly | — | — | CC7.1 | Quarterly third-party external scanning for independent validation. Compo… manual |
| IS-11:VM-03 | No evidence | Bi-weekly | — | — | CC7.1 | Bi-weekly automated web application scanning vs OWASP Top 10, CI/CD integ… |
| IS-11:VM-06 | No evidence | Quarterly | — | — | CC7.2 | Quarterly formal review of scan trends; critical/high closed or risk-acce… |
| IS-11:VM-07 | No evidence | Monthly | — | — | CC7.2 | Risk exceptions approved by Security Officer or Executive; reviewed month… manual |
| IS-11:VM-08-SCA | No evidence | Weekly | — | — | CC7.1 | Software composition analysis tracks third-party components. Component of… |
| IS-11:VM-04 | Event-driven | Per scan | — | — | CC7.2 | CVSS-based risk scoring and P0–P5 prioritisation applied to all findings |
| IS-11:VM-05 | Event-driven | Event-driven | — | — | CC7.2 | P0: patch within 24h if available; workaround within 48h if not |
| IS-11:VM-08 | Event-driven | Continuous | — | — | CC7.1 | Vendors disclose vulnerabilities within 24h (the software composition ana… |
10 controls shown.