DeftTrust

Control calendar

Cadence comes from policy — it is what an auditor measures. How often a collector samples is a separate thing, shown on the Collectors page.

Status All Overdue No evidence Current Event-driven
Policy All IT-05 8 IT-03 1 IT-02 8 IS-02 9 IT-04 8 IS-11 10 IS-07 8 LEG-01 8
ControlStatusCadenceLastNext due TSCDescription
IT-05:CM-07 No evidence Quarterly CC8.1 Version-controlled configs, environment consistency, drift prevention
IT-05:CM-01 Event-driven Per change CC8.1 Production changes documented in Jira with risk, test evidence, rollback …
IT-05:CM-02 Event-driven Per change CC8.1 Normal changes require independent reviewer approval before deployment
IT-05:CM-03 Event-driven Per change CC8.1 Changes tested or validated prior to deployment; evidence documented
IT-05:CM-04 Event-driven Continuous CC8.1 Only authorized personnel may implement production changes
IT-05:CM-05 Event-driven Event-driven CC8.2 Emergency changes documented immediately, approved post-implementation
IT-05:CM-06 Event-driven Continuous CC8.1 Change activity logged capturing who, when, and what was changed
IT-05:CM-08 Event-driven Event-driven CC8.2 Post-implementation review for emergency changes manual

8 controls shown.