workflow

Control Design

This instance runs against the Control item it creates: drafted at the objective step and committed to the Risk & Control Matrix (RCM) at record-the-control, so the archived instance is that control's design audit trail. It consumes no upstream workflow — a control is motivated by an existing Risk item or an audit Issue (finding/deficiency), which it links to rather than rebuilds. Design one new control end to end: control objective and attributes, risk mapping to the register, evidence and test-approach design, RCM record creation, disposition, packaging, and archival. The named deliverable is a new, uniquely identified control record in the RCM (a Control item) carrying a design determination statement, plus its test plan. In scope: designing and recording a single new control so it is operable and testable. Out of scope: executing the control's operating-effectiveness tests and remediating deficiencies, which are handed off downstream to the Security Control Assessment & POA&M Remediation workflow.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
operations
lineOfDefense
operate

Details

teams
  • operations
  • risk-management
domains
  • controls
standards
  • nist-800-53
  • iso-27001
sourceTemplateId
workflow-library:controls-design
releaseId
sha256:362c8362a87fd9c6ed9bbc66ac1f6bf55e7701d605a4f7fce99f08d6b1c1206f
canonicalUrl
https://workflow-library.com/all/?w=controls-design
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-ACCESS-15
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:362c8362a87fd9c6ed9bbc66ac1f6bf55e7701d605a4f7fce99f08d6b1c1206f

            Connections