workflow
Security Policy Suite Review
Standing operator workflow for the security policy owner's annual (and change-triggered) review, redline, reapproval, and dissemination of the full security policy suite -- secure acquisition/development/configuration-management/maintenance, asset/media/physical protection, access/identity/personnel security, communications/cryptography, security awareness and cyber-hygiene, audit-logging/monitoring/system-integrity, contingency planning and disruption mitigation, and incident response. Anchor: each run is a workflow instance attached to the existing "Security Policy Management" Process item (process_type=security_process, process_owner=policy owner, frequency=annual) -- that instance IS the cycle record the tracked review items roll up to; the eight policy families are the existing Policy items the cycle enriches (never recreates). In scope: reviewing each Policy item against current risk and threat inputs, consolidating findings into one suite-level revision disposition, routing redlines to the right stakeholders, reapproving under accountable security leadership (writing Policy.approved_by / version / effective_date / next_review_date back onto each policy), and tracking dissemination and workforce acknowledgment as a single evidence set. Out of scope: authoring net-new policy domains and operating the technical controls the policies govern. The workflow has no upstream feeder workflow -- its inputs are the policy register (the eight Policy items), the prior-cycle workflow instance and its exported operating record, and the annual review calendar carried on Policy.next_review_date -- and no named downstream workflow; open corrective actions (Issue items) carry forward as explicit inputs to the next cycle. The eight domain reviews run in parallel and converge on a single revision-disposition decision.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- operate
Details
- teams
- it
- compliance-legal
- domains
- controls
- standards
- nist-800-53
- nis2
- nydfs-500
- soc2
- sourceTemplateId
- workflow-library:controls-security-policy-suite-review-protection-domains
- releaseId
- sha256:035bb7044a1c5349f8206936ed2e8f6fedb3a7c54c1dafc75a1679e666df9f4c
- canonicalUrl
- https://workflow-library.com/all/?w=controls-security-policy-suite-review-protection-domains
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-GOV-29
- UC-GOV-30
- UC-GOV-31
- UC-GOV-32
- UC-GOV-33
- UC-GOV-34
- UC-GOV-35
- UC-GOV-36
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:035bb7044a1c5349f8206936ed2e8f6fedb3a7c54c1dafc75a1679e666df9f4c
Connections
- Security Policy Suite Review operates UC-GOV-34 — Maintain business continuity and contingency planning policy
- Security Policy Suite Review operates UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies
- Security Policy Suite Review operates UC-GOV-30 — Maintain asset, media, and physical protection policies
- Security Policy Suite Review operates UC-GOV-32 — Maintain security awareness and cyber-hygiene policies
- Security Policy Suite Review operates UC-GOV-36 — Maintain communications security and cryptography policies
- Security Policy Suite Review operates UC-GOV-33 — Maintain logging, monitoring, and system integrity policies
- Security Policy Suite Review operates UC-GOV-31 — Maintain access control, identity, and personnel security policies
- Security Policy Suite Review operates UC-GOV-35 — Maintain incident response policy and procedures