Control calendar
Cadence comes from policy — it is what an auditor measures. How often a collector samples is a separate thing, shown on the Collectors page.
| Control | Status | Cadence | Last | Next due | TSC | Description |
|---|---|---|---|---|---|---|
| IS-11:VM-01 | No evidence | Weekly | — | — | CC7.1 | Weekly authenticated internal vulnerability scans on all critical systems |
| IS-11:VM-02 | No evidence | Monthly | — | — | CC7.1 | Monthly external-facing system vulnerability scans (the quarterly third-p… |
| IS-11:VM-02-3P | No evidence | Quarterly | — | — | CC7.1 | Quarterly third-party external scanning for independent validation. Compo… manual |
| IS-11:VM-03 | No evidence | Bi-weekly | — | — | CC7.1 | Bi-weekly automated web application scanning vs OWASP Top 10, CI/CD integ… |
| IS-11:VM-06 | No evidence | Quarterly | — | — | CC7.2 | Quarterly formal review of scan trends; critical/high closed or risk-acce… |
| IS-11:VM-07 | No evidence | Monthly | — | — | CC7.2 | Risk exceptions approved by Security Officer or Executive; reviewed month… manual |
| IS-11:VM-08-SCA | No evidence | Weekly | — | — | CC7.1 | Software composition analysis tracks third-party components. Component of… |
7 controls shown.