Index
What each rule sets on a scheduled job
Nine regimes can be ticked; three more stand as named references. Each page lists the clock rows the regime sets, with the hours only where the held text states them.
PCI DSS v4.0Sets the daily log review, the three-month scans, the six-month account review and the annual plan test in figures the held text states.ISO/IEC 27001:2022Sets no fixed period on any of these jobs; every row reads no period set by the text, with the ISO/IEC 27002:2022 guidance beside it.DORA (Regulation (EU) 2022/2554)Article 25 sets at least yearly testing of critical ICT systems; the Article 19 reporting timelines are referred to, not stated, in the held text.NIS2 DirectiveArticle 23(4) sets the three reporting clocks in the held text: an early warning within 24 hours, a notification within 72 hours, a final report within one month; Article 23(1) is held as without undue delay.GDPRArticle 33 sets 72 hours from awareness for the notification to the supervisory authority; Articles 5, 28, 30, 32 and 34 set no hours.APRA CPS 234Paragraph 35 sets 72 hours for a material incident, paragraph 36 ten business days for a material control weakness, paragraph 32 an annual test of response plans.ISO 22301:2019Sets planned intervals, never hours; the continuity rows read no period set by the text.NIST SP 800-53 Rev 5Every frequency is organization-defined; the rows read a defined frequency and the register never fills the blank.HIPAA Security RuleReads regularly and periodic; no hours in the held text.
Named references
BCBS 239Named reference only: Principle 5 on timeliness and Principle 7 on reconciled reports, quoted without hours.SOX 404 / ICFRNamed reference only: the close, the ITGC and the audit committee entries, quoted without hours.ISO/IEC 25012:2008A definition beside the data rows: currentness is the degree to which data are of the right age for the use. Never a clock.