workflow
Cybersecurity Assurance Review
Cybersecurity Assurance Review — a CAE-owned assurance engagement that runs on the EXISTING Audit item opened from the audit plan (audit_type=it_audit, status PLANNED, lead_auditor and scope already set): the workflow instance attaches to that item and enriches it end to end, never creating a duplicate engagement record. It covers the three IIA Cybersecurity Topical Requirement domains (governance, risk management, and control activities) over the cyber estate bounded in the engagement memo (in scope: named legal entities, networks, cloud tenants, and OT/ICS where included; out of scope: areas whose assurance is documented as delivered by other engagements), testing against the NIST 800-53 Rev 5 catalog with CSF 2.0 / ISO 27001 as the aggregation frame. It originates from the audit plan (no upstream workflow) and produces the findings register (one four-Cs Issue per finding), the cyber posture summary carrying the per-domain and overall Standard 14.5 conclusions, and the approved engagement package — which it hands to the downstream Audit Report Drafting workflow.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- audit
- department
- internal-audit
- lineOfDefense
- assure
Details
- teams
- internal-audit
- it
- domains
- audit
- standards
- iia-2024
- nist-800-53
- sourceTemplateId
- workflow-library:audit-cybersecurity-assurance-review
- releaseId
- sha256:b1b1849f755b1bd298e35c5fe4919ba4e021cf217f67943330cb40b47b726828
- canonicalUrl
- https://workflow-library.com/all/?w=audit-cybersecurity-assurance-review
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- assure
- controls
- UC-AUDIT-12
- UC-AUDIT-13
- UC-AUDIT-16
- UC-AUDIT-23
- UC-GOV-15
- UC-VULN-01
- UC-LOG-04
- UC-IR-01
- UC-BCDR-13
- UC-LOG-01
- UC-LOG-03
- UC-LOG-05
- UC-LOG-08
- UC-VULN-05
- UC-AUDIT-14
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
- code
- reliance-basis-incomplete
- title
- Reliance basis is incomplete
- message
- Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.
- missing
- independence
- competence
- evidence
- recency
- reliance rationale
- nodeIds
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:b1b1849f755b1bd298e35c5fe4919ba4e021cf217f67943330cb40b47b726828
Connections
- Cybersecurity Assurance Review tests UC-LOG-01 — Log security-relevant events across all systems
- Cybersecurity Assurance Review tests UC-LOG-04 — Continuously monitor systems for anomalous activity
- Cybersecurity Assurance Review tests UC-IR-01 — Maintain an approved incident response plan
- Cybersecurity Assurance Review tests UC-BCDR-13 — Operate continuous security protection services
- Cybersecurity Assurance Review operates UC-AUDIT-13 — Gather and analyze evidence to develop engagement findings
- Cybersecurity Assurance Review tests UC-LOG-05 — Correlate and analyze events centrally with threat intel
- Cybersecurity Assurance Review tests UC-VULN-05 — Block malware, spam, and phishing across all systems
- Cybersecurity Assurance Review tests UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence
- Cybersecurity Assurance Review tests UC-GOV-15 — Operate a management-approved information security program
- Cybersecurity Assurance Review operates UC-AUDIT-23 — Coordinate independent assurance reviews across providers
- Cybersecurity Assurance Review operates UC-AUDIT-16 — Communicate final engagement results to stakeholders
- Cybersecurity Assurance Review operates UC-AUDIT-14 — Evaluate findings and develop recommendations and action plans
- Cybersecurity Assurance Review tests UC-LOG-03 — Protect audit logs and retain them for required periods
- Cybersecurity Assurance Review operates UC-AUDIT-12 — Plan engagements with risk-based objectives, scope, and criteria
- Cybersecurity Assurance Review tests UC-LOG-08 — Secure and monitor networks and network services