workflow
Authentication Platform & Session Policy Operations
Monthly authentication-platform operating cycle. Anchor: this instance runs on the existing Process item for authentication-platform / session-management operations (process_type: security_process, frequency: monthly) — enrich that standing Process each cycle, never create a duplicate — with the four operated Control items UC-ACCESS-09/11/12/13 (framework tags carrying the standards mapping, domains: access_control_identity) linked to it. In scope: MFA enforcement and enrollment across remote, privileged, and sensitive-data access; secure log-on and federation-trust verification; lockout and anomalous-logon defense; session lifecycle controls (inactivity lock, automatic termination, concurrent-session limits, re-authentication for sensitive operations); and system-use, last-logon, and failed-attempt notices, across the IdP or SSO tenant, VPN or remote-access gateway, PAM tooling, and applications classified as housing sensitive data. Out of scope: identity provisioning and joiner-mover-leaver lifecycle, access certification, and privileged-access request approval, which are operated by their own workflows. There is no upstream workflow dependency: the instance is self-originating on its own initial inputs — the authentication-platform inventory (a document on the anchor Process, refreshed each cycle) and the prior-cycle operating record (the prior Workflow instance on the same Process plus its carried-forward open Issue items). The four operating areas run in parallel and reconverge at the platform-posture disposition. Named deliverables: the MFA enforcement-coverage register, the authentication-posture memo, the lockout-and-anomaly log, the session-policy compliance matrix, the banner-and-notice verification record, the platform-health dashboard and readiness summary, and the corrective-action register — each attached to its step, with every gap raised as a self_assessment Issue linked to the Control it degrades. There is no downstream handoff: this terminal recurring cycle seeds its own successor via carry-forward Issue items at close.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- operate
Details
- teams
- it
- domains
- controls
- standards
- nist-800-53
- nist-csf-2
- iso-27001
- nydfs-500
- sourceTemplateId
- workflow-library:controls-authentication-platform-session-policy-operations
- releaseId
- sha256:a423b169a8e3d6d6864e185744540fef3107b5e5c468eb937fccef9fff160210
- canonicalUrl
- https://workflow-library.com/all/?w=controls-authentication-platform-session-policy-operations
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-ACCESS-09
- UC-ACCESS-11
- UC-ACCESS-12
- UC-ACCESS-13
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:a423b169a8e3d6d6864e185744540fef3107b5e5c468eb937fccef9fff160210
Connections
- Authentication Platform & Session Policy Operations operates UC-ACCESS-13 — Notify users of system terms and previous logon activity
- Authentication Platform & Session Policy Operations operates UC-ACCESS-09 — Authenticate all users with multi-factor authentication
- Authentication Platform & Session Policy Operations operates UC-ACCESS-11 — Defend logons against brute-force and anomalous attempts
- Authentication Platform & Session Policy Operations operates UC-ACCESS-12 — Lock, limit, and terminate user sessions