GRC Operating Calendar
Good governance runs on a rhythm, not a once-a-year scramble. This reference lays out the Governance, Risk & Compliance (GRC) operating rhythm — from daily monitoring to the annual audit — and ties each cadence to how PlumbTrack models it.
The tool's automation — policy review dates, risk-acceptance and policy-exception expiry, and Service-Level Agreement (SLA) deadlines — is just this calendar encoded, so nothing lapses between cycles. Anything that slips (a review gone overdue, an expired acceptance, a missed SLA) surfaces on the Plan of Action & Milestones (POA&M) NIST glossary: POA&M 800-53 CA-5 instead of being forgotten, and every formal risk assessment NIST SP 800-30, risk acceptance NIST SP 800-37 and control test becomes part of the evidence that proves the Information Security Management System (ISMS) actually runs. The cadences below line up with the Cybersecurity Framework Functions NIST CSF 2.0 — Govern, Identify, Protect, Detect, Respond, Recover.
| Cadence | Typical activities | How PlumbTrack models it |
|---|---|---|
| Daily | Monitor alerts / detections; triage new risks & incidents; work treatment tickets; respond to live incidents. | PlumbWatch alerts auto-create risks in Intake; you move cards through the workflow. |
| Weekly | Risk stand-up reviewing open POA&M items & overdue SLAs; vulnerability-scan review; evidence collection. | The POA&M list + overdue SLA flags. |
| Monthly | Report risk posture to management; access reviews; patch / vulnerability cycle; sample control testing. | Dashboard metrics; evidence (control tests) attached to risks. |
| Quarterly | Formal risk-assessment refresh; policy reviews; access recertification; re-review risk acceptances; incident-response tabletop exercise; steering-committee reporting. | Policy review cadence + acceptance / exception expiry items on the POA&M. |
| Annually | Full risk assessment; approve all policies; internal audit; external / certification audit; penetration test; disaster-recovery test; security-awareness training; management review. | The register + evidence become the audit package. |
Full sources for the standards referenced here are on the Standards page.