workflow
Information Security Program Governance Review
Standing operator workflow for the CISO's quarterly information security program governance review and its annual leg. Each cycle runs as one workflow instance attached to the existing "Information Security Program Governance" Process item (process_type: security_process, owner CISO), with the four governing Control items UC-GOV-06/09/10/15 linked to it. It is a decision-aware flow that enriches — never recreates — the senior-management-approved information security program plan (held as a Policy item) and the current role assignments every cycle, and branches into the written board report, workforce competency review, and plan reapproval when the annual interval or a significant change requires it. Named deliverables: the reapproved information security program plan (the Policy item, re-versioned and re-signed), the roles-and-authorities register, the annual written board report to the governing body, and the workforce competency review — each retained on the workflow instance. In scope: the program plan, security roles/authorities/reporting lines, the annual board report, and workforce competency for this organization; out of scope: executing the underlying protective controls and enterprise ERM governance, which are owned by their own workflows (coso-erm is referenced here only for oversight-of-design of the governance structure). There is no upstream or downstream workflow handoff — this cycle is genuinely self-contained: it starts from its own cadence trigger, consumes its own prior-cycle governance record, and seeds the next cycle at close.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- operate
Details
- teams
- it
- executive
- domains
- controls
- standards
- nist-800-53
- nydfs-500
- coso-ic
- coso-erm
- sourceTemplateId
- workflow-library:controls-information-security-program-governance-review
- releaseId
- sha256:7bfa6143ae99e0af99e205c327c02861bf5a3a398c178c92b28e94cdf2ce5f82
- canonicalUrl
- https://workflow-library.com/all/?w=controls-information-security-program-governance-review
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-GOV-06
- UC-GOV-09
- UC-GOV-10
- UC-GOV-15
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:7bfa6143ae99e0af99e205c327c02861bf5a3a398c178c92b28e94cdf2ce5f82
Connections
- Information Security Program Governance Review operates UC-GOV-06 — Define security roles, responsibilities, and authorities
- Information Security Program Governance Review operates UC-GOV-09 — Appoint accountable security leadership (CISO)
- Information Security Program Governance Review operates UC-GOV-15 — Operate a management-approved information security program
- Information Security Program Governance Review operates UC-GOV-10 — Attract, develop, and retain competent personnel