Control calendar
Cadence comes from policy — it is what an auditor measures. How often a collector samples is a separate thing, shown on the Collectors page.
| Control | Status | Cadence | Last | Next due | TSC | Description |
|---|---|---|---|---|---|---|
| LEG-01:VM-05 | No evidence | Annual | — | — | CC9.2 | Annual review of all vendors; high-risk vendors reviewed quarterly manual |
| LEG-01:VM-08 | No evidence | Annual | — | — | CC9.1 | High-risk vendors: invoices, contracts and SOC reports maintained |
| LEG-01:VM-01 | Event-driven | Event-driven | — | — | CC9.1 | All vendors risk-assessed and classified (Low/Medium/High) before engagem… manual |
| LEG-01:VM-02 | Event-driven | Event-driven | — | — | CC9.1 | Vendor agreements include confidentiality, data protection, security obli… manual |
| LEG-01:VM-03 | Event-driven | Event-driven | — | — | CC9.1 | Vendor access approved, documented, time-bound, minimum required resources |
| LEG-01:VM-04 | Event-driven | Event-driven | — | — | CC9.1 | All vendors recorded in the Vendor Register before access is granted |
| LEG-01:VM-06 | Event-driven | Event-driven | — | — | CC9.2 | Vendor access revoked immediately on contract termination or completion |
| LEG-01:VM-07 | Event-driven | Event-driven | — | — | CC9.2 | Vendor security incidents reported and handled per IS-07 manual |
8 controls shown.