Skip to content

Legend

  • ✅ = Must be performed this quarter
  • 🔁 = Performed every month within this quarter
  • ⭐ = At minimum once this quarter
  • * = "Periodically" — NCA does not specify interval; organization defines it (industry standard: annually)

Continuous (every day, every quarter)

# Activity Standard Control Ref Q1 Q2 Q3 Q4 Verified Wording
1 Security event logs 24/7 monitoring & SIEM ECC-2:2024 ECC 2-12-3 ✅ ✅ ✅ ✅ "Periodically" — continuous in practice
2 Critical systems security event monitoring CSCC-1:2019 CSCC 2-12 ✅ ✅ ✅ ✅ "Around the clock" — explicit
3 Telework systems 24/7 monitoring TCC-1:2021 TCC 2-11-1-3 ✅ ✅ ✅ ✅ "Around the clock" — explicit

Monthly (every month, all 4 quarters)

# Activity Standard Control Ref Q1 Q2 Q3 Q4 Verified Wording
4 Cloud external component vulnerability assessment (CSP) CCC-1:2020 CCC 2-9-P-1-1 🔁 🔁 🔁 🔁 "At least once every month" — explicit
5 Security patches on mobile/BYOD telework devices TCC-1:2021 TCC 2-5-1-2 🔁 🔁 🔁 🔁 "At least once every month" — explicit

Quarterly (Q1, Q2, Q3, Q4)

# Activity Standard Control Ref Q1 Q2 Q3 Q4 Verified Wording
6 Security patches for telework systems TCC-1:2021 TCC 2-3-1-1 ✅ ✅ ✅ ✅ "At least once every three months" — explicit
7 Vulnerability assessment on telework systems TCC-1:2021 TCC 2-9-1-1 ✅ ✅ ✅ ✅ "At least once every three months" — explicit
8 Vulnerability remediation for telework systems TCC-1:2021 TCC 2-9-1-2 ✅ ✅ ✅ ✅ "At least once every three months" — explicit
9 Cloud internal component vulnerability assessment (CSP) CCC-1:2020 CCC 2-9-P-1-1 ✅ ✅ ✅ ✅ "At least once every three months" — explicit
10 Cloud vulnerability assessment (CST) CCC-1:2020 CCC 2-9-T-1-1 ✅ ✅ ✅ ✅ "At least once every three months" — explicit
11 OT/ICS vulnerability assessment — Level 1 facility OTCC-1:2022 OTCC 2-9-1-3 ✅ ✅ ✅ ✅ "Every 3 months" — explicit
12 OT/ICS penetration testing — Level 1 facility OTCC-1:2022 OTCC 2-10-1-3 ✅ ✅ ✅ ✅ "Every 3 months" — explicit

# Activity Standard Control Ref Q1 Q2 Q3 Q4 Verified Wording
13 Backup recovery test for telework systems TCC-1:2021 TCC 2-8-2 ✅ — ✅ — "At least once every six months" — explicit
14 Cloud penetration testing (CSP) CCC-1:2020 CCC 2-10-P-1-1 ✅ — ✅ — "At least once every six months" — explicit
15 OT/ICS vulnerability assessment — Level 2 facility OTCC-1:2022 OTCC 2-9-1-3 ✅ — ✅ — "Every 6 months" — explicit
16 OT/ICS penetration testing — Level 2 facility OTCC-1:2022 OTCC 2-10-1-3 ✅ — ✅ — "Every 6 months" — explicit

Annually — Explicit (NCA states "at least once per year" or "annually")

# Activity Standard Control Ref Q1 Q2 Q3 Q4 Verified Wording
17 Telework cybersecurity risk assessment TCC-1:2021 TCC 1-2-1-1 ✅ — — — "At least once per year" — explicit
18 Telework risk register review & update TCC-1:2021 TCC 1-2-1-3 ✅ — — — "At least once a year" — explicit
19 Telework asset inventory update TCC-1:2021 TCC 2-1-1-1 ✅ — — — "Annually-updated" — explicit
20 Telework user access rights review TCC-1:2021 TCC 2-2-2 ✅ — — — "At least once every year" — explicit
21 Telework systems configuration & hardening review TCC-1:2021 TCC 2-3-1-2 ✅ — — — "At least once every year" — explicit
22 Telework firewall rules & configuration review TCC-1:2021 TCC 2-4-1-2 ✅ — — — "At least once every year" — explicit
23 Telework penetration testing TCC-1:2021 TCC 2-10-2 — — ✅ — "At least once every year" — explicit
24 OTCC controls internal review (self-assessment) OTCC-1:2022 OTCC 1-6-1 ✅ — — — "At least annually" — explicit
25 Critical systems cybersecurity risk assessment CSCC-1:2019 CSCC 1-5 ✅ — — — "At least once annually" — explicit
26 Critical systems asset inventory update CSCC-1:2019 CSCC 2-1 ✅ — — — "Annually-updated" — explicit
27 OT/ICS vulnerability assessment — Level 3 facility OTCC-1:2022 OTCC 2-9-1-3 ✅ — — — "Every 12 months" — explicit
28 OT/ICS penetration testing — Level 3 facility OTCC-1:2022 OTCC 2-10-1-3 ✅ — — — "Every 12 months" — explicit

Annually — Periodically* (ECC/CSCC say "periodically"; no specific interval stated)

# Activity Standard Control Ref Q1 Q2 Q3 Q4 NCA Wording
29 Cybersecurity strategy review ECC-2:2024 ECC 1-1-3 ✅* — — — "At planned intervals"
30 Cybersecurity policies & procedures review ECC-2:2024 ECC 1-3-4 ✅* — — — "At planned intervals"
31 Cybersecurity roles & responsibilities review ECC-2:2024 ECC 1-4-2 ✅* — — — "At planned intervals"
32 Cybersecurity risk management methodology review ECC-2:2024 ECC 1-5-4 ✅* — — — "At planned intervals"
33 Cybersecurity in IT project management review ECC-2:2024 ECC 1-6-4 ✅* — — — "Periodically"
34 Internal cybersecurity review / self-assessment ECC-2:2024 ECC 1-8-1 ✅* — — — "Periodically"
35 Independent cybersecurity audit ECC-2:2024 ECC 1-8-2 — — — ✅* "Independently" — no interval stated
36 HR cybersecurity requirements review ECC-2:2024 ECC 1-9-6 ✅* — — — "Periodically"
37 Cybersecurity awareness program delivery ECC-2:2024 ECC 1-10-1/1-10-2 ✅* ✅* ✅* ✅* "Periodically, through multiple channels"
38 Specialized cybersecurity training (CS staff, dev, exec) ECC-2:2024 ECC 1-10-4 ✅* — — — "Periodically"
39 Awareness program effectiveness review ECC-2:2024 ECC 1-10-5 — — — ✅* "Periodically"
40 Asset inventory & management review ECC-2:2024 ECC 2-1-6 ✅* — — — "Periodically"
41 User identities & access rights review ECC-2:2024 ECC 2-2-3.5 ✅* ✅* ✅* ✅* "Periodic review" — no interval
42 IAM requirements review ECC-2:2024 ECC 2-2-4 ✅* — — — "Periodically"
43 Information systems & processing facilities protection review ECC-2:2024 ECC 2-3-4 ✅* — — — "Periodically"
44 Email protection review ECC-2:2024 ECC 2-4-4 ✅* — — — "Periodically"
45 Network security management review ECC-2:2024 ECC 2-5-4 ✅* — — — "Periodically"
46 Mobile device & BYOD security review ECC-2:2024 ECC 2-6-4 ✅* — — — "Periodically"
47 Data & information protection review ECC-2:2024 ECC 2-7-3 ✅* — — — "Periodically"
48 Cryptography requirements review ECC-2:2024 ECC 2-8-4 ✅* — — — "Periodically"
49 Backup & recovery management review ECC-2:2024 ECC 2-9-4 ✅* — — — "Periodically"
50 Backup restoration test ECC-2:2024 ECC 2-9-3 ✅* — ✅* — "Periodically" — no interval
51 Vulnerability assessment (general IT) ECC-2:2024 ECC 2-10-3 ✅* ✅* ✅* ✅* "Periodic assessments" — no interval
52 Vulnerability management review ECC-2:2024 ECC 2-10-4 — — — ✅* "Periodically"
53 Penetration testing (general IT) ECC-2:2024 ECC 2-11-3 — — ✅* — "Periodically" — no interval
54 Penetration testing requirements review ECC-2:2024 ECC 2-11-4 ✅* — — — "Periodically"
55 Security event logs & SIEM configuration review ECC-2:2024 ECC 2-12-4 — ✅* — — "Periodically"
56 Incident response plan review ECC-2:2024 ECC 2-13-4 ✅* — — — "Periodically"
57 Incident response tabletop / simulation exercise ECC-2:2024 ECC 2-13-3 — ✅* — — "Periodically"
58 Physical security review ECC-2:2024 ECC 2-14-4 ✅* — — — "Periodically"
59 Web application security review ECC-2:2024 ECC 2-15-4 — — ✅* — "Periodically"
60 BCP / DR plan review ECC-2:2024 ECC 3-1-4 ✅* — — — "Periodically"
61 BCP / DR exercise / simulation ECC-2:2024 ECC 3-1-3 — — — ✅* "Periodically"
62 Third-party cybersecurity requirements review ECC-2:2024 ECC 4-1-4 — ✅* — — "Periodically"
63 Critical systems penetration testing CSCC-1:2019 CSCC 2-11 — — ✅* — "Periodically" — no interval
64 Critical systems stress / capacity test CSCC-1:2019 CSCC 3-1 — — — ✅* Implied periodically
65 HR screening for critical system personnel CSCC-1:2019 CSCC 1-9 ✅* — — — "Periodically"
66 Source code security review (before release) CSCC-1:2019 CSCC 2-16 ✅* ✅* ✅* ✅* "Before each release"
67 OT/ICS cybersecurity awareness & training OTCC-1:2022 OTCC 1-8 ✅* — — — "Periodically"
68 OT/ICS asset inventory review OTCC-1:2022 OTCC 2-1-2 ✅* ✅* ✅* ✅* "Periodically"
69 OT/ICS backup execution OTCC-1:2022 OTCC 2-8-1-3 ✅* ✅* ✅* ✅* "Periodically per classification"
70 OT/ICS IR simulation exercise (tabletop) OTCC-1:2022 OTCC 2-12-1-7 — — ✅* — "Periodically"
71 OT/ICS physical security simulation exercise OTCC-1:2022 OTCC 2-13-1-9 — — — ✅* "Periodically"
72 OT/ICS BCP / DRP test OTCC-1:2022 OTCC 3-1-1-6 — — — ✅* "Periodic testing and simulation"
73 OT/ICS third-party cybersecurity assessment OTCC-1:2022 OTCC 4-1-1-4 — ✅* — — "Periodic assessment"
74 CCC cloud incident response capability test (CSP) CCC-1:2020 CCC 2-12-P-1-3 — — ✅* — "Periodically"
75 CCC cloud event logs & audit trail review (CSP) CCC-1:2020 CCC 2-11-P-1-6 ✅* ✅* ✅* ✅* "Periodically"
76 CCC key management review (CSP & CST) CCC-1:2020 CCC 2-15-P-4/T-4 ✅* — — — "Periodically"
77 CCC change management review (CSP) CCC-1:2020 CCC 1-5-P-4 ✅* — — — "Periodically"
78 CCC personnel screening — cloud access roles (CSP) CCC-1:2020 CCC 1-4-P-1-2 ✅* — — — "Periodically"
79 Social media account security review OSMACC OSMACC ✅* — — — "Periodically"
80 Social media usage policy review OSMACC OSMACC ✅* — — — "Periodically"

Every 3 Years

# Activity Standard Control Ref Notes
81 Independent review of OTCC controls OTCC-1:2022 OTCC 1-6-2 "At least once every three years" — explicit. Must be by a party independent from the cybersecurity function