workflow
Deception, Honeytoken & OPSEC Concealment Operations
Standing quarterly operator workflow that runs against the EXISTING deception/OPSEC concealment Control in the control library (control_type: detective, framework: nist-800-53, frequency: quarterly, mapped to UC-NET-10/UC-VULN-11/UC-NET-11) — each quarter's instance enriches that Control's operating history and is archived as its audit trail, never creating a duplicate control. In scope: deploy and reposition honeypot/honeynet decoys and honeyclient sandbox detonation ahead of user delivery, seed/monitor/functionally-test honeytoken/beacon/watermark taint mechanisms across systems and datasets, and run the OPSEC process that identifies critical operational information (Risk items), analyzes adversary collection paths, and deploys concealment and misdirection countermeasures (Control items) on the cycle's designated systems, segments, and datasets. Originates on its own: the four operating streams (OPSEC, decoys, sandbox, taint) are parallel entry points fed by the organization's own asset, threat-intel, and inventory data — no upstream workflow feeds it. Named deliverables: the isolation-verified deception estate (deployment/repositioning plan + isolation-verification record), sandbox pipeline test results, the seeded taint-mechanism placement inventory, the OPSEC critical-information register with countermeasure register, the cycle detections timeline, and the program-health readiness dashboard. Out of scope: incident containment and eradication — confirmed activations are handed to the incident-response workflow with a preserved chain-of-custody evidence package (that handoff fires only on the activations-detected branch), rather than contained here.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- operate
Details
- teams
- it
- domains
- controls
- standards
- nist-800-53
- sourceTemplateId
- workflow-library:controls-deception-honeytoken-opsec-concealment-operations
- releaseId
- sha256:6f0b367a6b42ff061615e403c2c5ce39ef09a5ec054aa932d43c8b74d4d220e6
- canonicalUrl
- https://workflow-library.com/all/?w=controls-deception-honeytoken-opsec-concealment-operations
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-NET-10
- UC-VULN-11
- UC-NET-11
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:6f0b367a6b42ff061615e403c2c5ce39ef09a5ec054aa932d43c8b74d4d220e6
Connections
- Deception, Honeytoken & OPSEC Concealment Operations operates UC-NET-11 — Conceal operational information from adversaries
- Deception, Honeytoken & OPSEC Concealment Operations operates UC-NET-10 — Deploy deception and dynamic detection capabilities
- Deception, Honeytoken & OPSEC Concealment Operations operates UC-VULN-11 — Embed taint mechanisms to detect data exfiltration