This program defines a recurring, scheduled review of access logs and policy compliance — the piece SOC2 5.36 / ISO 27001 identifies as missing beyond simply having audit logs available to review on request. It satisfies the requirement for a formal internal audit cadence, scoped appropriately for a one-engineer team (Security Officer self-review, not a separate audit department).
Quarterly, on the 1st business day of January, April, July, and October. An automated reminder email fires on that schedule (see Section 4) so the review does not depend on manual tracking.
An automated quarterly email reminder (Resend, same recipient list as the security-alert/inactive-user notifications) links to this checklist. Completion itself is manual — the Security Officer works through the checklist and notes findings below — but the schedule is enforced by automation, not memory.
| Quarter | Reviewed By | Findings | Actions Taken |
|---|---|---|---|
| No reviews conducted yet — first scheduled review is the next quarterly reminder after this program's effective date. | |||