Control calendar
Cadence comes from policy — it is what an auditor measures. How often a collector samples is a separate thing, shown on the Collectors page.
| Control | Status | Cadence | Last | Next due | TSC | Description |
|---|---|---|---|---|---|---|
| IT-04:NET-01 | No evidence | Quarterly | — | — | CC6.1 | §5.1 Production and customer-data environments isolated from non-producti… |
| IT-04:NET-02 | No evidence | Annual | — | — | CC6.6 | §6 Firewalls restrict inbound/outbound traffic; only approved ports permi… |
| IT-04:NET-03 | No evidence | Annual | — | — | CC6.6 | §6.2 Firewall configurations reviewed at least annually; changes tracked |
| IT-04:NET-04 | No evidence | Annual | — | — | CC6.6 | §7 Data in transit encrypted with industry-standard protocols; deprecated… |
| IT-04:NET-05 | No evidence | Annual | — | — | CC6.6 | §10 System and network hardening standards maintained and reviewed annual… |
| IT-04:NET-07 | No evidence | Quarterly | — | — | CC6.6CC6.7 | §5 Remote access to production occurs only over an encrypted channel |
| IT-04:NET-08 | No evidence | Quarterly | — | — | CC6.1 | §5 Remote access to production requires MFA; no shared or hardcoded crede… manual |
| IT-04:NET-06 | Event-driven | Continuous | — | — | CC7.2 | §9 Network activity logged and reviewed to detect unauthorised activity |
8 controls shown.