workflow

Cybersecurity Assurance Review

Cybersecurity Assurance Review — a CAE-owned assurance engagement that runs on the EXISTING Audit item opened from the audit plan (audit_type=it_audit, status PLANNED, lead_auditor and scope already set): the workflow instance attaches to that item and enriches it end to end, never creating a duplicate engagement record. It covers the three IIA Cybersecurity Topical Requirement domains (governance, risk management, and control activities) over the cyber estate bounded in the engagement memo (in scope: named legal entities, networks, cloud tenants, and OT/ICS where included; out of scope: areas whose assurance is documented as delivered by other engagements), testing against the NIST 800-53 Rev 5 catalog with CSF 2.0 / ISO 27001 as the aggregation frame. It originates from the audit plan (no upstream workflow) and produces the findings register (one four-Cs Issue per finding), the cyber posture summary carrying the per-domain and overall Standard 14.5 conclusions, and the approved engagement package — which it hands to the downstream Audit Report Drafting workflow.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
audit
department
internal-audit
lineOfDefense
assure

Details

teams
  • internal-audit
  • it
domains
  • audit
standards
  • iia-2024
  • nist-800-53
sourceTemplateId
workflow-library:audit-cybersecurity-assurance-review
releaseId
sha256:b1b1849f755b1bd298e35c5fe4919ba4e021cf217f67943330cb40b47b726828
canonicalUrl
https://workflow-library.com/all/?w=audit-cybersecurity-assurance-review
capabilities
    mappingStatus
    mapped
    lineOfDefense
    assure
    controls
    • UC-AUDIT-12
    • UC-AUDIT-13
    • UC-AUDIT-16
    • UC-AUDIT-23
    • UC-GOV-15
    • UC-VULN-01
    • UC-LOG-04
    • UC-IR-01
    • UC-BCDR-13
    • UC-LOG-01
    • UC-LOG-03
    • UC-LOG-05
    • UC-LOG-08
    • UC-VULN-05
    • UC-AUDIT-14
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings
          • code
            reliance-basis-incomplete
            title
            Reliance basis is incomplete
            message
            Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.
            missing
            • independence
            • competence
            • evidence
            • recency
            • reliance rationale
            nodeIds

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:b1b1849f755b1bd298e35c5fe4919ba4e021cf217f67943330cb40b47b726828

            Connections