IS-11:VM-07
Risk exceptions approved by Security Officer or Executive; reviewed monthly
Not automatable. DeftTrust schedules this control, prepares the pack and files
the record it produces — it does not perform the judgement. The calendar still tracks it,
so it cannot silently lapse.
Collectors
| Collector | Relationship | Samples | What it observes |
|---|---|---|---|
| No collector references this control yet. | |||
Evidence satisfying this control
| Collected | Collector | Result | Source | Digest |
|---|---|---|---|---|
| No artifact satisfies this control. | ||||
Evidenced by a person. Security Officer / CTO owes this. The
scheduler opens a request 5 days
before it comes due; none is open right now.
Definition history
| Changed | Field | From | To | Source |
|---|---|---|---|---|
| 2026-09-10 03:32 | attestation_lead_days | 7 | 5 | sync_controls |
| 2026-09-10 03:32 | attestation_instructions | — | Monthly review of the risk-exception register: each open ex… | sync_controls |
| 2026-09-10 03:32 | attestation_role | — | Security Officer / CTO | sync_controls |
A cadence change re-judges this control's existing evidence against the new interval, so its status can move the moment the change lands. That is why the change is recorded rather than just applied.