DeftTrust

Control calendar

Cadence comes from policy — it is what an auditor measures. How often a collector samples is a separate thing, shown on the Collectors page.

Status All Overdue No evidence Current Event-driven
Policy All IT-05 8 IT-03 1 IT-02 8 IS-02 9 IT-04 8 IS-11 10 IS-07 8 LEG-01 8
ControlStatusCadenceLastNext due TSCDescription
IS-02:AC-01 Event-driven Event-driven CC6.1 Access provisioned upon hire per Access Matrix and least privilege
IS-02:AC-02 Event-driven Event-driven CC6.3 Access revoked no later than final working day; immediate for high-risk
IS-02:AC-06 Event-driven Event-driven CC6.3 Supplier / vendor access time-bound, MFA required, logged, removed on com…
IS-02:AC-07 Event-driven Continuous CC6.1 Customer environments segregated per org; support access logged
IS-02:AC-09 Event-driven Continuous CC6.1 BYOD mitigated via cloud-only access, MFA, RBAC, session revocation manual
IS-07:IR-01 Event-driven Continuous CC7.3 Security monitoring continuous; incidents triaged and classified within 3…
IS-07:IR-02 Event-driven Event-driven CC7.3 All incidents logged in Jira with type, severity, actions, resolution
IS-07:IR-03 Event-driven Event-driven CC7.4 P1/P2 incidents escalated to executives; regulatory notification in requi… manual
IS-07:IR-04 Event-driven Event-driven CC7.5 Post-incident review conducted; lessons learned documented manual
IS-07:IR-08 Event-driven Event-driven CC7.4 Vendor incident response requirements in contracts; notification within 1… manual
IS-11:VM-04 Event-driven Per scan CC7.2 CVSS-based risk scoring and P0–P5 prioritisation applied to all findings
IS-11:VM-05 Event-driven Event-driven CC7.2 P0: patch within 24h if available; workaround within 48h if not
IS-11:VM-08 Event-driven Continuous CC7.1 Vendors disclose vulnerabilities within 24h (the software composition ana…
IT-02:BC-04 Event-driven Event-driven CC7.5 BC/DR activation only through the formal Incident Escalation workflow manual
IT-02:BC-07 Event-driven Event-driven A1.3 Post-disaster root cause analysis and corrective actions documented manual
IT-04:NET-06 Event-driven Continuous CC7.2 §9 Network activity logged and reviewed to detect unauthorised activity
IT-05:CM-01 Event-driven Per change CC8.1 Production changes documented in Jira with risk, test evidence, rollback …
IT-05:CM-02 Event-driven Per change CC8.1 Normal changes require independent reviewer approval before deployment
IT-05:CM-03 Event-driven Per change CC8.1 Changes tested or validated prior to deployment; evidence documented
IT-05:CM-04 Event-driven Continuous CC8.1 Only authorized personnel may implement production changes
IT-05:CM-05 Event-driven Event-driven CC8.2 Emergency changes documented immediately, approved post-implementation
IT-05:CM-06 Event-driven Continuous CC8.1 Change activity logged capturing who, when, and what was changed
IT-05:CM-08 Event-driven Event-driven CC8.2 Post-implementation review for emergency changes manual
LEG-01:VM-01 Event-driven Event-driven CC9.1 All vendors risk-assessed and classified (Low/Medium/High) before engagem… manual
LEG-01:VM-02 Event-driven Event-driven CC9.1 Vendor agreements include confidentiality, data protection, security obli… manual
LEG-01:VM-03 Event-driven Event-driven CC9.1 Vendor access approved, documented, time-bound, minimum required resources
LEG-01:VM-04 Event-driven Event-driven CC9.1 All vendors recorded in the Vendor Register before access is granted
LEG-01:VM-06 Event-driven Event-driven CC9.2 Vendor access revoked immediately on contract termination or completion
LEG-01:VM-07 Event-driven Event-driven CC9.2 Vendor security incidents reported and handled per IS-07 manual

29 controls shown.