workflow

Security Policy Suite Review

Standing operator workflow for the security policy owner's annual (and change-triggered) review, redline, reapproval, and dissemination of the full security policy suite -- secure acquisition/development/configuration-management/maintenance, asset/media/physical protection, access/identity/personnel security, communications/cryptography, security awareness and cyber-hygiene, audit-logging/monitoring/system-integrity, contingency planning and disruption mitigation, and incident response. Anchor: each run is a workflow instance attached to the existing "Security Policy Management" Process item (process_type=security_process, process_owner=policy owner, frequency=annual) -- that instance IS the cycle record the tracked review items roll up to; the eight policy families are the existing Policy items the cycle enriches (never recreates). In scope: reviewing each Policy item against current risk and threat inputs, consolidating findings into one suite-level revision disposition, routing redlines to the right stakeholders, reapproving under accountable security leadership (writing Policy.approved_by / version / effective_date / next_review_date back onto each policy), and tracking dissemination and workforce acknowledgment as a single evidence set. Out of scope: authoring net-new policy domains and operating the technical controls the policies govern. The workflow has no upstream feeder workflow -- its inputs are the policy register (the eight Policy items), the prior-cycle workflow instance and its exported operating record, and the annual review calendar carried on Policy.next_review_date -- and no named downstream workflow; open corrective actions (Issue items) carry forward as explicit inputs to the next cycle. The eight domain reviews run in parallel and converge on a single revision-disposition decision.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
operate

Details

teams
  • it
  • compliance-legal
domains
  • controls
standards
  • nist-800-53
  • nis2
  • nydfs-500
  • soc2
sourceTemplateId
workflow-library:controls-security-policy-suite-review-protection-domains
releaseId
sha256:035bb7044a1c5349f8206936ed2e8f6fedb3a7c54c1dafc75a1679e666df9f4c
canonicalUrl
https://workflow-library.com/all/?w=controls-security-policy-suite-review-protection-domains
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-GOV-29
    • UC-GOV-30
    • UC-GOV-31
    • UC-GOV-32
    • UC-GOV-33
    • UC-GOV-34
    • UC-GOV-35
    • UC-GOV-36
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:035bb7044a1c5349f8206936ed2e8f6fedb3a7c54c1dafc75a1679e666df9f4c

            Connections