Operational Events Calendar
12-month recurring safeguard activities mapped by frequency. Click any month or day to drill into scheduled activities.
Activity Types
Ongoing (Daily/Weekly)
6 activitiesAddress Unauthorized Assets
Weekly · Control 1Utilize an Active Discovery Tool
Daily · Control 1Use Dynamic Host Configuration Protocol (DHCP) Logging to Update Enterprise Asset Inventory
Weekly · Control 1Use a Passive Asset Discovery Tool
Weekly · Control 1Conduct Audit Log Reviews
Weekly · Control 8Perform Automated BackupsĀ
Weekly · Control 11January
28Establish and Maintain Detailed Enterprise Asset Inventory
Review · Bi-annuallyEstablish and Maintain a Software Inventory
Review · Bi-annuallyEnsure Authorized Software is Currently Supported
Review · MonthlyAddress Unauthorized Software
Review · MonthlyAllowlist Authorized Software
Review · Bi-annuallyAllowlist Authorized Libraries
Review · Bi-annuallyAllowlist Authorized Scripts
Review · Bi-annuallyEstablish and Maintain an Inventory of Accounts
Review · QuarterlyEstablish and Maintain an Inventory of Service Accounts
Review · QuarterlyEstablish and Maintain a Remediation Process
Review · MonthlyPerform Automated Operating System Patch Management
Update · MonthlyPerform Automated Application Patch Management
Update · MonthlyPerform Automated Vulnerability Scans of Internal Enterprise Assets
Scan · QuarterlyPerform Automated Vulnerability Scans of Externally>Exposed Enterprise Assets
Scan · MonthlyRemediate Detected Vulnerabilities
Review · MonthlyTest Data Recovery
Test · QuarterlyEnsure Network Infrastructure is Up>to>Date
Review · MonthlyTune Security Event Alerting Thresholds
Review · MonthlyEstablish and Manage an Inventory of Third>Party Software Components
Review · MonthlyDesignate Personnel to Manage Incident Handling
Test · AnnuallyEstablish and Maintain Contact Information for Reporting Security Incidents
Review · AnnuallyEstablish and Maintain an Enterprise Process for Reporting Incidents
Review · AnnuallyEstablish and Maintain an Incident Response Process
Review · AnnuallyAssign Key Roles and Responsibilities
Review · AnnuallyDefine Mechanisms for Communicating During Incident Response
Review · AnnuallyConduct Routine Incident Response Exercises
Test · AnnuallyConduct Post>Incident Reviews
Review · AnnuallyEstablish and Maintain Security Incident Thresholds
Review · AnnuallyFebruary
11Ensure Authorized Software is Currently Supported
Review · MonthlyAddress Unauthorized Software
Review · MonthlyUtilize Automated Software Inventory Tools
Review · AnnuallyEstablish and Maintain a Remediation Process
Review · MonthlyPerform Automated Operating System Patch Management
Update · MonthlyPerform Automated Application Patch Management
Update · MonthlyPerform Automated Vulnerability Scans of Externally>Exposed Enterprise Assets
Scan · MonthlyRemediate Detected Vulnerabilities
Review · MonthlyEnsure Network Infrastructure is Up>to>Date
Review · MonthlyTune Security Event Alerting Thresholds
Review · MonthlyEstablish and Manage an Inventory of Third>Party Software Components
Review · MonthlyMarch
33Ensure Authorized Software is Currently Supported
Review · MonthlyAddress Unauthorized Software
Review · MonthlyEstablish and Maintain a Data Management Process
Review · AnnuallyEncrypt Sensitive Data in Transit
Review · AnnuallyEncrypt Sensitive Data at Rest
Review · AnnuallySegment Data Processing and Storage Based on Sensitivity
Review · AnnuallyDeploy a Data Loss Prevention Solution
Update · AnnuallyLog Sensitive Data Access
Review · AnnuallyEstablish and Maintain a Data Inventory
Review · AnnuallyConfigure Data Access Control Lists
Review · AnnuallyEnforce Data Retention
Review · AnnuallySecurely Dispose of Data
Review · AnnuallyEncrypt Data on End>User Devices
Review · AnnuallyEstablish and Maintain a Data Classification Scheme
Review · AnnuallyDocument Data Flows
Review · AnnuallyEncrypt Data on Removable Media
Review · AnnuallyEstablish and Maintain a Remediation Process
Review · MonthlyPerform Automated Operating System Patch Management
Update · MonthlyPerform Automated Application Patch Management
Update · MonthlyPerform Automated Vulnerability Scans of Externally>Exposed Enterprise Assets
Scan · MonthlyRemediate Detected Vulnerabilities
Review · MonthlyEnsure Network Infrastructure is Up>to>Date
Review · MonthlyTune Security Event Alerting Thresholds
Review · MonthlyEstablish and Maintain a Security Awareness Program
Training · AnnuallyTrain Workforce Members to Recognize Social Engineering Attacks
Training · AnnuallyTrain Workforce Members on Authentication Best Practices
Training · AnnuallyTrain Workforce on Data Handling Best Practices
Training · AnnuallyTrain Workforce Members on Causes of Unintentional Data Exposure
Training · AnnuallyTrain Workforce Members on Recognizing and Reporting Security Incidents
Training · AnnuallyTrain Workforce on How to Identify and Report if Their Enterprise Assets are Missing Security Updates
Training · AnnuallyTrain Workforce on the Dangers of Connecting to and Transmitting Enterprise Data Over Insecure Networks
Training · AnnuallyConduct Role>Specific Security Awareness and Skills Training
Training · AnnuallyEstablish and Manage an Inventory of Third>Party Software Components
Review · MonthlyApril
26Ensure Authorized Software is Currently Supported
Review · MonthlyAddress Unauthorized Software
Review · MonthlyEstablish and Maintain a Secure Configuration Process
Review · AnnuallyEnforce Automatic Device Lockout on Portable End>User Devices
Review · AnnuallyEnforce Remote Wipe Capability on Portable End>User Devices
Review · AnnuallySeparate Enterprise Workspaces on Mobile End>User Devices
Review · AnnuallyEstablish and Maintain a Secure Configuration Process for Network Infrastructure
Review · AnnuallyConfigure Automatic Session Locking on Enterprise Assets
Review · AnnuallyImplement and Manage a Firewall on Servers
Review · AnnuallyImplement and Manage a Firewall on End>User Devices
Review · AnnuallySecurely Manage Enterprise Assets and Software
Review · AnnuallyManage Default Accounts on Enterprise Assets and Software
Review · AnnuallyUninstall or Disable Unnecessary Services on Enterprise Assets and Software
Update · AnnuallyConfigure Trusted DNS Servers on Enterprise Assets
Review · AnnuallyEstablish and Maintain an Inventory of Accounts
Review · QuarterlyEstablish and Maintain an Inventory of Service Accounts
Review · QuarterlyEstablish and Maintain a Remediation Process
Review · MonthlyPerform Automated Operating System Patch Management
Update · MonthlyPerform Automated Application Patch Management
Update · MonthlyPerform Automated Vulnerability Scans of Internal Enterprise Assets
Scan · QuarterlyPerform Automated Vulnerability Scans of Externally>Exposed Enterprise Assets
Scan · MonthlyRemediate Detected Vulnerabilities
Review · MonthlyTest Data Recovery
Test · QuarterlyEnsure Network Infrastructure is Up>to>Date
Review · MonthlyTune Security Event Alerting Thresholds
Review · MonthlyEstablish and Manage an Inventory of Third>Party Software Components
Review · MonthlyMay
21Ensure Authorized Software is Currently Supported
Review · MonthlyAddress Unauthorized Software
Review · MonthlyUse Unique Passwords
Review · AnnuallyDisable Dormant Accounts
Review · AnnuallyRestrict Administrator Privileges to Dedicated Administrator Accounts
Review · AnnuallyCentralize Account Management
Review · AnnuallyEstablish and Maintain a Remediation Process
Review · MonthlyPerform Automated Operating System Patch Management
Update · MonthlyPerform Automated Application Patch Management
Update · MonthlyPerform Automated Vulnerability Scans of Externally>Exposed Enterprise Assets
Scan · MonthlyRemediate Detected Vulnerabilities
Review · MonthlyEnsure Network Infrastructure is Up>to>Date
Review · MonthlyTune Security Event Alerting Thresholds
Review · MonthlyEstablish and Maintain an Inventory of Service Providers
Review · AnnuallyEstablish and Maintain a Service Provider Management Policy
Review · AnnuallyClassify Service Providers
Review · AnnuallyEnsure Service Provider Contracts Include Security Requirements
Review · AnnuallyAssess Service Providers
Review · AnnuallyMonitor Service Providers
Review · AnnuallySecurely Decommission Service Providers
Review · AnnuallyEstablish and Manage an Inventory of Third>Party Software Components
Review · MonthlyJune
18Ensure Authorized Software is Currently Supported
Review · MonthlyAddress Unauthorized Software
Review · MonthlyEstablish an Access Granting Process
Review · AnnuallyEstablish an Access Revoking Process
Review · AnnuallyRequire MFA for Externally>Exposed Applications
Review · AnnuallyRequire MFA for Remote Network Access
Review · AnnuallyRequire MFA for Administrative Access
Review · AnnuallyEstablish and Maintain an Inventory of Authentication and Authorization Systems
Review · AnnuallyCentralize Access Control
Review · AnnuallyDefine and Maintain Role>Based Access Control
Review · AnnuallyEstablish and Maintain a Remediation Process
Review · MonthlyPerform Automated Operating System Patch Management
Update · MonthlyPerform Automated Application Patch Management
Update · MonthlyPerform Automated Vulnerability Scans of Externally>Exposed Enterprise Assets
Scan · MonthlyRemediate Detected Vulnerabilities
Review · MonthlyEnsure Network Infrastructure is Up>to>Date
Review · MonthlyTune Security Event Alerting Thresholds
Review · MonthlyEstablish and Manage an Inventory of Third>Party Software Components
Review · MonthlyJuly
23Establish and Maintain Detailed Enterprise Asset Inventory
Review · Bi-annuallyEstablish and Maintain a Software Inventory
Review · Bi-annuallyEnsure Authorized Software is Currently Supported
Review · MonthlyAddress Unauthorized Software
Review · MonthlyAllowlist Authorized Software
Review · Bi-annuallyAllowlist Authorized Libraries
Review · Bi-annuallyAllowlist Authorized Scripts
Review · Bi-annuallyEstablish and Maintain an Inventory of Accounts
Review · QuarterlyEstablish and Maintain an Inventory of Service Accounts
Review · QuarterlyEstablish and Maintain a Vulnerability Management Process
Review · AnnuallyEstablish and Maintain a Remediation Process
Review · MonthlyPerform Automated Operating System Patch Management
Update · MonthlyPerform Automated Application Patch Management
Update · MonthlyPerform Automated Vulnerability Scans of Internal Enterprise Assets
Scan · QuarterlyPerform Automated Vulnerability Scans of Externally>Exposed Enterprise Assets
Scan · MonthlyRemediate Detected Vulnerabilities
Review · MonthlyEstablish and Maintain a Data Recovery ProcessĀ
Test · AnnuallyProtect Recovery Data
Test · AnnuallyEstablish and Maintain an Isolated Instance of Recovery DataĀ
Test · AnnuallyTest Data Recovery
Test · QuarterlyEnsure Network Infrastructure is Up>to>Date
Review · MonthlyTune Security Event Alerting Thresholds
Review · MonthlyEstablish and Manage an Inventory of Third>Party Software Components
Review · MonthlyAugust
21Ensure Authorized Software is Currently Supported
Review · MonthlyAddress Unauthorized Software
Review · MonthlyEstablish and Maintain a Remediation Process
Review · MonthlyPerform Automated Operating System Patch Management
Update · MonthlyPerform Automated Application Patch Management
Update · MonthlyPerform Automated Vulnerability Scans of Externally>Exposed Enterprise Assets
Scan · MonthlyRemediate Detected Vulnerabilities
Review · MonthlyEstablish and Maintain an Audit Log Management Process
Review · AnnuallyRetain Audit Logs
Review · AnnuallyCollect Service Provider Logs
Review · AnnuallyCollect Audit Logs
Review · AnnuallyEnsure Adequate Audit Log Storage
Review · AnnuallyStandardize Time Synchronization
Review · AnnuallyCollect Detailed Audit Logs
Review · AnnuallyCollect DNS Query Audit Logs
Review · AnnuallyCollect URL Request Audit Logs
Review · AnnuallyCollect Command>Line Audit Logs
Review · AnnuallyCentralize Audit Logs
Review · AnnuallyEnsure Network Infrastructure is Up>to>Date
Review · MonthlyTune Security Event Alerting Thresholds
Review · MonthlyEstablish and Manage an Inventory of Third>Party Software Components
Review · MonthlySeptember
27Ensure Authorized Software is Currently Supported
Review · MonthlyAddress Unauthorized Software
Review · MonthlyEstablish and Maintain a Remediation Process
Review · MonthlyPerform Automated Operating System Patch Management
Update · MonthlyPerform Automated Application Patch Management
Update · MonthlyPerform Automated Vulnerability Scans of Externally>Exposed Enterprise Assets
Scan · MonthlyRemediate Detected Vulnerabilities
Review · MonthlyEnsure Use of Only Fully Supported Browsers and Email Clients
Review · AnnuallyUse DNS Filtering Services
Review · AnnuallyMaintain and Enforce Network>Based URL Filters
Review · AnnuallyRestrict Unnecessary or Unauthorized Browser and Email Client Extensions
Review · AnnuallyImplement DMARC
Review · AnnuallyBlock Unnecessary File Types
Review · AnnuallyDeploy and Maintain Email Server Anti>Malware Protections
Scan · AnnuallyEnsure Network Infrastructure is Up>to>Date
Review · MonthlyCentralize Security Event Alerting
Review · AnnuallyPerform Application Layer Filtering
Review · AnnuallyTune Security Event Alerting Thresholds
Review · MonthlyDeploy a Host>Based Intrusion Detection Solution
Update · AnnuallyDeploy a Network Intrusion Detection Solution
Update · AnnuallyPerform Traffic Filtering Between Network Segments
Review · AnnuallyManage Access Control for Remote Assets
Review · AnnuallyCollect Network Traffic Flow Logs
Review · AnnuallyDeploy a Host>Based Intrusion Prevention Solution
Update · AnnuallyDeploy a Network Intrusion Prevention Solution
Update · AnnuallyDeploy Port>Level Access Control
Update · AnnuallyEstablish and Manage an Inventory of Third>Party Software Components
Review · MonthlyOctober
28Ensure Authorized Software is Currently Supported
Review · MonthlyAddress Unauthorized Software
Review · MonthlyEstablish and Maintain an Inventory of Accounts
Review · QuarterlyEstablish and Maintain an Inventory of Service Accounts
Review · QuarterlyEstablish and Maintain a Remediation Process
Review · MonthlyPerform Automated Operating System Patch Management
Update · MonthlyPerform Automated Application Patch Management
Update · MonthlyPerform Automated Vulnerability Scans of Internal Enterprise Assets
Scan · QuarterlyPerform Automated Vulnerability Scans of Externally>Exposed Enterprise Assets
Scan · MonthlyRemediate Detected Vulnerabilities
Review · MonthlyDeploy and Maintain Anti>Malware Software
Update · AnnuallyConfigure Automatic Anti>Malware Signature Updates
Update · AnnuallyDisable Autorun and Autoplay for Removable Media
Review · AnnuallyConfigure Automatic Anti>Malware Scanning of Removable Media
Scan · AnnuallyEnable Anti>Exploitation Features
Review · AnnuallyCentrally Manage Anti>Malware Software
Review · AnnuallyUse Behavior>Based Anti>Malware Software
Review · AnnuallyTest Data Recovery
Test · QuarterlyEnsure Network Infrastructure is Up>to>Date
Review · MonthlyEstablish and Maintain a Secure Network Architecture
Review · AnnuallySecurely Manage Network Infrastructure
Review · AnnuallyEstablish and Maintain Architecture Diagram(s)
Review · AnnuallyCentralize Network Authentication, Authorization, and Auditing (AAA)
Review · AnnuallyUse of Secure Network Management and Communication ProtocolsĀ
Review · AnnuallyEnsure Remote Devices Utilize a VPN and are Connecting to an Enterpriseās AAA Infrastructure
Review · AnnuallyEstablish and Maintain Dedicated Computing Resources for All Administrative Work
Review · AnnuallyTune Security Event Alerting Thresholds
Review · MonthlyEstablish and Manage an Inventory of Third>Party Software Components
Review · MonthlyNovember
23Ensure Authorized Software is Currently Supported
Review · MonthlyAddress Unauthorized Software
Review · MonthlyEstablish and Maintain a Remediation Process
Review · MonthlyPerform Automated Operating System Patch Management
Update · MonthlyPerform Automated Application Patch Management
Update · MonthlyPerform Automated Vulnerability Scans of Externally>Exposed Enterprise Assets
Scan · MonthlyRemediate Detected Vulnerabilities
Review · MonthlyEnsure Network Infrastructure is Up>to>Date
Review · MonthlyTune Security Event Alerting Thresholds
Review · MonthlyEstablish and Maintain a Secure Application DevelopmentĀ Process
Training · AnnuallyApply Secure Design Principles in Application Architectures
Review · AnnuallyLeverage Vetted Modules or Services for Application Security Components
Review · AnnuallyImplement Code>Level Security Checks
Review · AnnuallyConduct Application Penetration Testing
Assessment · AnnuallyConduct Threat Modeling
Assessment · AnnuallyEstablish and Maintain a Process to Accept and Address Software Vulnerabilities
Review · AnnuallyPerform Root Cause Analysis on Security Vulnerabilities
Review · AnnuallyEstablish and Manage an Inventory of Third>Party Software Components
Review · MonthlyUse Up>to>Date and Trusted Third>Party Software Components
Review · AnnuallyEstablish and Maintain a Severity Rating System and Process for Application Vulnerabilities
Review · AnnuallyUse Standard Hardening Configuration Templates for Application Infrastructure
Review · AnnuallySeparate Production and Non>Production Systems
Review · AnnuallyTrain Developers in Application Security Concepts and Secure Coding
Training · AnnuallyDecember
15Ensure Authorized Software is Currently Supported
Review · MonthlyAddress Unauthorized Software
Review · MonthlyEstablish and Maintain a Remediation Process
Review · MonthlyPerform Automated Operating System Patch Management
Update · MonthlyPerform Automated Application Patch Management
Update · MonthlyPerform Automated Vulnerability Scans of Externally>Exposed Enterprise Assets
Scan · MonthlyRemediate Detected Vulnerabilities
Review · MonthlyEnsure Network Infrastructure is Up>to>Date
Review · MonthlyTune Security Event Alerting Thresholds
Review · MonthlyEstablish and Manage an Inventory of Third>Party Software Components
Review · MonthlyEstablish and Maintain a Penetration Testing Program
Assessment · AnnuallyPerform Periodic External Penetration Tests
Assessment · AnnuallyRemediate Penetration Test Findings
Assessment · AnnuallyValidate Security Measures
Assessment · AnnuallyPerform Periodic Internal Penetration Tests
Assessment · Annually