DeftTrust

Control calendar

Cadence comes from policy — it is what an auditor measures. How often a collector samples is a separate thing, shown on the Collectors page.

Status All Overdue No evidence Current Event-driven
Policy All IT-05 8 IT-03 1 IT-02 8 IS-02 9 IT-04 8 IS-11 10 IS-07 8 LEG-01 8
ControlStatusCadenceLastNext due TSCDescription
IT-02:BC-01 No evidence Daily A1.2 Automated daily database backups; repositories version-controlled
IT-02:BC-02 No evidence Annual A1.2 RTO of 4 hours and RPO of 1 hour defined and documented
IT-02:BC-03 No evidence Annual A1.2 Recovery procedures documented; runbooks maintained; roles defined manual
IT-02:BC-05 No evidence Semi-annual A1.2 Semi-annual BC/DR readiness review with evidence captured manual
IT-02:BC-06 No evidence Annual A1.3 Annual formal BC/DR test: date, participants, results, corrective actions
IT-02:BC-08 No evidence Annual A1.2 All critical roles can operate remotely; no physical office dependency manual
IT-02:BC-04 Event-driven Event-driven CC7.5 BC/DR activation only through the formal Incident Escalation workflow manual
IT-02:BC-07 Event-driven Event-driven A1.3 Post-disaster root cause analysis and corrective actions documented manual

8 controls shown.