DeftTrust

Control calendar

Cadence comes from policy — it is what an auditor measures. How often a collector samples is a separate thing, shown on the Collectors page.

Status All Overdue No evidence Current Event-driven
Policy All IT-05 8 IT-03 1 IT-02 8 IS-02 9 IT-04 8 IS-11 10 IS-07 8 LEG-01 8
ControlStatusCadenceLastNext due TSCDescription
IS-11:VM-01 No evidence Weekly CC7.1 Weekly authenticated internal vulnerability scans on all critical systems
IS-11:VM-02 No evidence Monthly CC7.1 Monthly external-facing system vulnerability scans (the quarterly third-p…
IS-11:VM-02-3P No evidence Quarterly CC7.1 Quarterly third-party external scanning for independent validation. Compo… manual
IS-11:VM-03 No evidence Bi-weekly CC7.1 Bi-weekly automated web application scanning vs OWASP Top 10, CI/CD integ…
IS-11:VM-06 No evidence Quarterly CC7.2 Quarterly formal review of scan trends; critical/high closed or risk-acce…
IS-11:VM-07 No evidence Monthly CC7.2 Risk exceptions approved by Security Officer or Executive; reviewed month… manual
IS-11:VM-08-SCA No evidence Weekly CC7.1 Software composition analysis tracks third-party components. Component of…

7 controls shown.