DeftTrust

Control calendar

Cadence comes from policy — it is what an auditor measures. How often a collector samples is a separate thing, shown on the Collectors page.

Status All Overdue No evidence Current Event-driven
Policy All IT-05 8 IT-03 1 IT-02 8 IS-02 9 IT-04 8 IS-11 10 IS-07 8 LEG-01 8
ControlStatusCadenceLastNext due TSCDescription
IS-02:AC-03 No evidence Monthly CC6.1 MFA enforced on all applicable systems
IS-02:AC-04 No evidence Quarterly CC6.2 Quarterly review of Access Matrix — verify users, roles, remove stale acc…
IS-02:AC-05 No evidence Quarterly CC6.1 Privileged access restricted to CTO, Head of People, CEO; reviewed quarte…
IS-02:AC-08 No evidence Monthly CC6.1 Password policy enforced: complexity, rotation, vault storage
IS-07:IR-05 No evidence Semi-annual CC7.5 Tabletop exercise with scenario, participants, findings, remediation docu… manual
IS-07:IR-06 No evidence Annual CC7.5 Full-scale IR test or formal tabletop conducted and documented annually manual
IS-07:IR-07 No evidence Annual CC7.3 All employees receive IR awareness training; IRT specialised training ann…
IS-11:VM-01 No evidence Weekly CC7.1 Weekly authenticated internal vulnerability scans on all critical systems
IS-11:VM-02 No evidence Monthly CC7.1 Monthly external-facing system vulnerability scans (the quarterly third-p…
IS-11:VM-02-3P No evidence Quarterly CC7.1 Quarterly third-party external scanning for independent validation. Compo… manual
IS-11:VM-03 No evidence Bi-weekly CC7.1 Bi-weekly automated web application scanning vs OWASP Top 10, CI/CD integ…
IS-11:VM-06 No evidence Quarterly CC7.2 Quarterly formal review of scan trends; critical/high closed or risk-acce…
IS-11:VM-07 No evidence Monthly CC7.2 Risk exceptions approved by Security Officer or Executive; reviewed month… manual
IS-11:VM-08-SCA No evidence Weekly CC7.1 Software composition analysis tracks third-party components. Component of…
IT-02:BC-01 No evidence Daily A1.2 Automated daily database backups; repositories version-controlled
IT-02:BC-02 No evidence Annual A1.2 RTO of 4 hours and RPO of 1 hour defined and documented
IT-02:BC-03 No evidence Annual A1.2 Recovery procedures documented; runbooks maintained; roles defined manual
IT-02:BC-05 No evidence Semi-annual A1.2 Semi-annual BC/DR readiness review with evidence captured manual
IT-02:BC-06 No evidence Annual A1.3 Annual formal BC/DR test: date, participants, results, corrective actions
IT-02:BC-08 No evidence Annual A1.2 All critical roles can operate remotely; no physical office dependency manual
IT-03:AM-01 No evidence Quarterly CC7.1 Asset inventory maintained, classified by criticality, and kept current
IT-04:NET-01 No evidence Quarterly CC6.1 §5.1 Production and customer-data environments isolated from non-producti…
IT-04:NET-02 No evidence Annual CC6.6 §6 Firewalls restrict inbound/outbound traffic; only approved ports permi…
IT-04:NET-03 No evidence Annual CC6.6 §6.2 Firewall configurations reviewed at least annually; changes tracked
IT-04:NET-04 No evidence Annual CC6.6 §7 Data in transit encrypted with industry-standard protocols; deprecated…
IT-04:NET-05 No evidence Annual CC6.6 §10 System and network hardening standards maintained and reviewed annual…
IT-04:NET-07 No evidence Quarterly CC6.6CC6.7 §5 Remote access to production occurs only over an encrypted channel
IT-04:NET-08 No evidence Quarterly CC6.1 §5 Remote access to production requires MFA; no shared or hardcoded crede… manual
IT-05:CM-07 No evidence Quarterly CC8.1 Version-controlled configs, environment consistency, drift prevention
LEG-01:VM-05 No evidence Annual CC9.2 Annual review of all vendors; high-risk vendors reviewed quarterly manual
LEG-01:VM-08 No evidence Annual CC9.1 High-risk vendors: invoices, contracts and SOC reports maintained

31 controls shown.