workflow
Threat Intelligence & Insider Threat Program
Runs on the existing Process item "Threat Intelligence & Insider Threat Program" (process_type=security_process, process_owner = program lead) — a long-lived program record related to the Control items it operates (UC-RISK-17, UC-BCDR-16, UC-GOV-37); each cycle is one recurring workflow instance attached to that Process, enriching the standing program rather than creating a new one. Decision-aware, covering NIST SP 800-53 PM-12, PM-16, and RA-10 and NIST CSF 2.0 ID.RA and DE.CM. In scope: cyclic intake and curation of threat intelligence into a validated intake register and intel cards, governed internal dissemination and TLP-marked outbound sharing packages, intel-driven threat hunts (producing the hunt summary) and any resulting investigation record, and privacy-guarded review of insider-threat indicators with a governed board disposition and a restricted insider case file, closing with a program-effectiveness report and a reperformable cycle archive. No upstream workflow feeds it; the only cross-run input is the prior cycle's carry-forward package (the carry-forward document from the previous instance's program-effectiveness report step, which closes each cycle), and each cycle emits the next one. Out of scope and handed off only in prose (no terminal handoff node): incident-response execution (the incident-response process, once an incident is declared at open-investigation) and HR/legal employment actions (owned by those functions within an insider case). Each cycle's intel-and-hunt track and its insider-threat track start in parallel from their own inputs.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- operate
Details
- teams
- it
- domains
- controls
- standards
- nist-800-53
- nist-csf-2
- sourceTemplateId
- workflow-library:controls-threat-intelligence-program
- releaseId
- sha256:9e50ff9e802446081a3b33b6195cb72fc672500d02b83389a22727d7e12d9ece
- canonicalUrl
- https://workflow-library.com/all/?w=controls-threat-intelligence-program
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-RISK-17
- UC-BCDR-16
- UC-GOV-37
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:9e50ff9e802446081a3b33b6195cb72fc672500d02b83389a22727d7e12d9ece
Connections
- Threat Intelligence & Insider Threat Program operates UC-GOV-37 — Operate insider-threat and threat-awareness programs
- Threat Intelligence & Insider Threat Program operates UC-RISK-17 — Operate threat intelligence and threat hunting
- Threat Intelligence & Insider Threat Program operates UC-BCDR-16 — Participate in cyber threat intelligence sharing