workflow

System Categorization, Security Planning & Authorization

Operator workflow for the system owner and authorizing official to categorize a system by impact and criticality, maintain the approved system security and privacy plan, authorize internal connections, and grant and track authorization to operate, as a decision-aware flow with categorization-approval and authorization branches. In scope: a single system — its impact and criticality categorization, the system security and privacy plan, internal-connection authorization, and the authorization-to-operate decision with reauthorization tracking. Out of scope: the control assessments and testing that feed the authorization risk view (consumed as an input) and enterprise categorization-policy setting; there is no upstream or downstream workflow, so any cross-workflow dependency is declared as a step input rather than routed.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
operate

Details

teams
  • it
  • compliance-legal
domains
  • controls
standards
  • nist-800-53
sourceTemplateId
workflow-library:controls-system-categorization-planning-authorization
releaseId
sha256:8a94d321110b8bcc3298d0e3c8954403fa30e2ef9c4f66f96c2d4a62effbe3ec
canonicalUrl
https://workflow-library.com/all/?w=controls-system-categorization-planning-authorization
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-RISK-18
    • UC-GOV-18
    • UC-AUDIT-26
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:8a94d321110b8bcc3298d0e3c8954403fa30e2ef9c4f66f96c2d4a62effbe3ec

            Connections