Control calendar
Cadence comes from policy — it is what an auditor measures. How often a collector samples is a separate thing, shown on the Collectors page.
| Control | Status | Cadence | Last | Next due | TSC | Description |
|---|---|---|---|---|---|---|
| IS-02:AC-01 | Event-driven | Event-driven | — | — | CC6.1 | Access provisioned upon hire per Access Matrix and least privilege |
| IS-02:AC-02 | Event-driven | Event-driven | — | — | CC6.3 | Access revoked no later than final working day; immediate for high-risk |
| IS-02:AC-06 | Event-driven | Event-driven | — | — | CC6.3 | Supplier / vendor access time-bound, MFA required, logged, removed on com… |
| IS-02:AC-07 | Event-driven | Continuous | — | — | CC6.1 | Customer environments segregated per org; support access logged |
| IS-02:AC-09 | Event-driven | Continuous | — | — | CC6.1 | BYOD mitigated via cloud-only access, MFA, RBAC, session revocation manual |
| IS-07:IR-01 | Event-driven | Continuous | — | — | CC7.3 | Security monitoring continuous; incidents triaged and classified within 3… |
| IS-07:IR-02 | Event-driven | Event-driven | — | — | CC7.3 | All incidents logged in Jira with type, severity, actions, resolution |
| IS-07:IR-03 | Event-driven | Event-driven | — | — | CC7.4 | P1/P2 incidents escalated to executives; regulatory notification in requi… manual |
| IS-07:IR-04 | Event-driven | Event-driven | — | — | CC7.5 | Post-incident review conducted; lessons learned documented manual |
| IS-07:IR-08 | Event-driven | Event-driven | — | — | CC7.4 | Vendor incident response requirements in contracts; notification within 1… manual |
| IS-11:VM-04 | Event-driven | Per scan | — | — | CC7.2 | CVSS-based risk scoring and P0–P5 prioritisation applied to all findings |
| IS-11:VM-05 | Event-driven | Event-driven | — | — | CC7.2 | P0: patch within 24h if available; workaround within 48h if not |
| IS-11:VM-08 | Event-driven | Continuous | — | — | CC7.1 | Vendors disclose vulnerabilities within 24h (the software composition ana… |
| IT-02:BC-04 | Event-driven | Event-driven | — | — | CC7.5 | BC/DR activation only through the formal Incident Escalation workflow manual |
| IT-02:BC-07 | Event-driven | Event-driven | — | — | A1.3 | Post-disaster root cause analysis and corrective actions documented manual |
| IT-04:NET-06 | Event-driven | Continuous | — | — | CC7.2 | §9 Network activity logged and reviewed to detect unauthorised activity |
| IT-05:CM-01 | Event-driven | Per change | — | — | CC8.1 | Production changes documented in Jira with risk, test evidence, rollback … |
| IT-05:CM-02 | Event-driven | Per change | — | — | CC8.1 | Normal changes require independent reviewer approval before deployment |
| IT-05:CM-03 | Event-driven | Per change | — | — | CC8.1 | Changes tested or validated prior to deployment; evidence documented |
| IT-05:CM-04 | Event-driven | Continuous | — | — | CC8.1 | Only authorized personnel may implement production changes |
| IT-05:CM-05 | Event-driven | Event-driven | — | — | CC8.2 | Emergency changes documented immediately, approved post-implementation |
| IT-05:CM-06 | Event-driven | Continuous | — | — | CC8.1 | Change activity logged capturing who, when, and what was changed |
| IT-05:CM-08 | Event-driven | Event-driven | — | — | CC8.2 | Post-implementation review for emergency changes manual |
| LEG-01:VM-01 | Event-driven | Event-driven | — | — | CC9.1 | All vendors risk-assessed and classified (Low/Medium/High) before engagem… manual |
| LEG-01:VM-02 | Event-driven | Event-driven | — | — | CC9.1 | Vendor agreements include confidentiality, data protection, security obli… manual |
| LEG-01:VM-03 | Event-driven | Event-driven | — | — | CC9.1 | Vendor access approved, documented, time-bound, minimum required resources |
| LEG-01:VM-04 | Event-driven | Event-driven | — | — | CC9.1 | All vendors recorded in the Vendor Register before access is granted |
| LEG-01:VM-06 | Event-driven | Event-driven | — | — | CC9.2 | Vendor access revoked immediately on contract termination or completion |
| LEG-01:VM-07 | Event-driven | Event-driven | — | — | CC9.2 | Vendor security incidents reported and handled per IS-07 manual |
29 controls shown.