Plan a security review your team can finish
Set the scope, choose owners and dates, and define the record you want to keep.
Content and source check: October 1, 2026 · Operational suggestions
Start with a specific question
Choose an activity that answers a practical question: who still needs access, whether a response plan can be followed, or what a provider review left unresolved. Write down the boundaries of the review and who can approve its conclusions.
Choose dates deliberately
Select a first due date, a planning horizon and an operational cadence that fit your firm. The planner includes dates on or after the start and before the end of the horizon. A six-month window with a quarterly cadence usually contains two occurrences. An anchor on the 31st clamps to a shorter month's last day and returns to the original day when possible. Weekends do not move.
Assign a role and an evidence expectation
Name a responsible role, then agree on the record that will demonstrate what was reviewed: a dated worksheet, an approved policy version, an attendance record or an action register. Keep evidence in your firm's approved environment. The planner stores descriptions, not evidence files.
Separate work completed from issues resolved
A review can be completed while its findings still require action. Use notes and next actions to explain unresolved items. Review the exported plan with the people responsible before adding calendar entries. An exported calendar is a file; no reminders are installed automatically.
Keep the record
Use Save a copy to download an editable project file, then Open saved copy to continue later. Use Print / PDF for a review copy, or More for spreadsheet and calendar downloads. Protect those local files under your own handling rules. Closing or refreshing this page can discard work.
Source & applicability
NIST-1300 — Cybersecurity Framework 2.0: Small Business Quick-Start Guide
Provides a starting point for small organizations to organize cybersecurity risk management. Voluntary guidance; no RIA-specific frequency or legal deadline is derived here.
SEC-registered and state-registered firms may have different obligations. Have the appropriate professionals review what applies to your firm. No regulatory determination is made here.