DeftTrust

Control calendar

Cadence comes from policy — it is what an auditor measures. How often a collector samples is a separate thing, shown on the Collectors page.

Status All Overdue No evidence Current Event-driven
Policy All IT-05 8 IT-03 1 IT-02 8 IS-02 9 IT-04 8 IS-11 10 IS-07 8 LEG-01 8
ControlStatusCadenceLastNext due TSCDescription
LEG-01:VM-05 No evidence Annual CC9.2 Annual review of all vendors; high-risk vendors reviewed quarterly manual
LEG-01:VM-08 No evidence Annual CC9.1 High-risk vendors: invoices, contracts and SOC reports maintained
LEG-01:VM-01 Event-driven Event-driven CC9.1 All vendors risk-assessed and classified (Low/Medium/High) before engagem… manual
LEG-01:VM-02 Event-driven Event-driven CC9.1 Vendor agreements include confidentiality, data protection, security obli… manual
LEG-01:VM-03 Event-driven Event-driven CC9.1 Vendor access approved, documented, time-bound, minimum required resources
LEG-01:VM-04 Event-driven Event-driven CC9.1 All vendors recorded in the Vendor Register before access is granted
LEG-01:VM-06 Event-driven Event-driven CC9.2 Vendor access revoked immediately on contract termination or completion
LEG-01:VM-07 Event-driven Event-driven CC9.2 Vendor security incidents reported and handled per IS-07 manual

8 controls shown.