Control calendar
Cadence comes from policy — it is what an auditor measures. How often a collector samples is a separate thing, shown on the Collectors page.
| Control | Status | Cadence | Last | Next due | TSC | Description |
|---|---|---|---|---|---|---|
| IS-02:AC-03 | No evidence | Monthly | — | — | CC6.1 | MFA enforced on all applicable systems |
| IS-02:AC-04 | No evidence | Quarterly | — | — | CC6.2 | Quarterly review of Access Matrix — verify users, roles, remove stale acc… |
| IS-02:AC-05 | No evidence | Quarterly | — | — | CC6.1 | Privileged access restricted to CTO, Head of People, CEO; reviewed quarte… |
| IS-02:AC-08 | No evidence | Monthly | — | — | CC6.1 | Password policy enforced: complexity, rotation, vault storage |
| IS-07:IR-05 | No evidence | Semi-annual | — | — | CC7.5 | Tabletop exercise with scenario, participants, findings, remediation docu… manual |
| IS-07:IR-06 | No evidence | Annual | — | — | CC7.5 | Full-scale IR test or formal tabletop conducted and documented annually manual |
| IS-07:IR-07 | No evidence | Annual | — | — | CC7.3 | All employees receive IR awareness training; IRT specialised training ann… |
| IS-11:VM-01 | No evidence | Weekly | — | — | CC7.1 | Weekly authenticated internal vulnerability scans on all critical systems |
| IS-11:VM-02 | No evidence | Monthly | — | — | CC7.1 | Monthly external-facing system vulnerability scans (the quarterly third-p… |
| IS-11:VM-02-3P | No evidence | Quarterly | — | — | CC7.1 | Quarterly third-party external scanning for independent validation. Compo… manual |
| IS-11:VM-03 | No evidence | Bi-weekly | — | — | CC7.1 | Bi-weekly automated web application scanning vs OWASP Top 10, CI/CD integ… |
| IS-11:VM-06 | No evidence | Quarterly | — | — | CC7.2 | Quarterly formal review of scan trends; critical/high closed or risk-acce… |
| IS-11:VM-07 | No evidence | Monthly | — | — | CC7.2 | Risk exceptions approved by Security Officer or Executive; reviewed month… manual |
| IS-11:VM-08-SCA | No evidence | Weekly | — | — | CC7.1 | Software composition analysis tracks third-party components. Component of… |
| IT-02:BC-01 | No evidence | Daily | — | — | A1.2 | Automated daily database backups; repositories version-controlled |
| IT-02:BC-02 | No evidence | Annual | — | — | A1.2 | RTO of 4 hours and RPO of 1 hour defined and documented |
| IT-02:BC-03 | No evidence | Annual | — | — | A1.2 | Recovery procedures documented; runbooks maintained; roles defined manual |
| IT-02:BC-05 | No evidence | Semi-annual | — | — | A1.2 | Semi-annual BC/DR readiness review with evidence captured manual |
| IT-02:BC-06 | No evidence | Annual | — | — | A1.3 | Annual formal BC/DR test: date, participants, results, corrective actions |
| IT-02:BC-08 | No evidence | Annual | — | — | A1.2 | All critical roles can operate remotely; no physical office dependency manual |
| IT-03:AM-01 | No evidence | Quarterly | — | — | CC7.1 | Asset inventory maintained, classified by criticality, and kept current |
| IT-04:NET-01 | No evidence | Quarterly | — | — | CC6.1 | §5.1 Production and customer-data environments isolated from non-producti… |
| IT-04:NET-02 | No evidence | Annual | — | — | CC6.6 | §6 Firewalls restrict inbound/outbound traffic; only approved ports permi… |
| IT-04:NET-03 | No evidence | Annual | — | — | CC6.6 | §6.2 Firewall configurations reviewed at least annually; changes tracked |
| IT-04:NET-04 | No evidence | Annual | — | — | CC6.6 | §7 Data in transit encrypted with industry-standard protocols; deprecated… |
| IT-04:NET-05 | No evidence | Annual | — | — | CC6.6 | §10 System and network hardening standards maintained and reviewed annual… |
| IT-04:NET-07 | No evidence | Quarterly | — | — | CC6.6CC6.7 | §5 Remote access to production occurs only over an encrypted channel |
| IT-04:NET-08 | No evidence | Quarterly | — | — | CC6.1 | §5 Remote access to production requires MFA; no shared or hardcoded crede… manual |
| IT-05:CM-07 | No evidence | Quarterly | — | — | CC8.1 | Version-controlled configs, environment consistency, drift prevention |
| LEG-01:VM-05 | No evidence | Annual | — | — | CC9.2 | Annual review of all vendors; high-risk vendors reviewed quarterly manual |
| LEG-01:VM-08 | No evidence | Annual | — | — | CC9.1 | High-risk vendors: invoices, contracts and SOC reports maintained |
31 controls shown.