workflow

Information Security Program Governance Review

Standing operator workflow for the CISO's quarterly information security program governance review and its annual leg. Each cycle runs as one workflow instance attached to the existing "Information Security Program Governance" Process item (process_type: security_process, owner CISO), with the four governing Control items UC-GOV-06/09/10/15 linked to it. It is a decision-aware flow that enriches — never recreates — the senior-management-approved information security program plan (held as a Policy item) and the current role assignments every cycle, and branches into the written board report, workforce competency review, and plan reapproval when the annual interval or a significant change requires it. Named deliverables: the reapproved information security program plan (the Policy item, re-versioned and re-signed), the roles-and-authorities register, the annual written board report to the governing body, and the workforce competency review — each retained on the workflow instance. In scope: the program plan, security roles/authorities/reporting lines, the annual board report, and workforce competency for this organization; out of scope: executing the underlying protective controls and enterprise ERM governance, which are owned by their own workflows (coso-erm is referenced here only for oversight-of-design of the governance structure). There is no upstream or downstream workflow handoff — this cycle is genuinely self-contained: it starts from its own cadence trigger, consumes its own prior-cycle governance record, and seeds the next cycle at close.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
operate

Details

teams
  • it
  • executive
domains
  • controls
standards
  • nist-800-53
  • nydfs-500
  • coso-ic
  • coso-erm
sourceTemplateId
workflow-library:controls-information-security-program-governance-review
releaseId
sha256:7bfa6143ae99e0af99e205c327c02861bf5a3a398c178c92b28e94cdf2ce5f82
canonicalUrl
https://workflow-library.com/all/?w=controls-information-security-program-governance-review
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-GOV-06
    • UC-GOV-09
    • UC-GOV-10
    • UC-GOV-15
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:7bfa6143ae99e0af99e205c327c02861bf5a3a398c178c92b28e94cdf2ce5f82

            Connections