workflow
Secure Development & Release Security Gate
Each run attaches as a workflow instance to the existing Control item for the secure-development/release-security-gate control (domains: secure_development_sdlc + vulnerability_patch_management) — enrich that Control, never create a duplicate; release runs and the quarterly checkpoint are separate instances on the same anchor Control. This workflow originates on its own artifacts (the release candidate, design artifacts, and the standing portfolio registers) and receives no upstream handoff package. Decision-aware: it branches on trigger type. In scope — for a release or major upgrade entering development, run security-and-privacy-by-design engineering, security test-plan execution, and runtime-hardening verification as parallel evidence streams, then resolve the release security disposition and assemble the release security evidence package with its acceptance-criteria index; for the quarterly portfolio checkpoint, run the vulnerability, patch, and end-of-life software review, publish the portfolio-health dashboard, and log corrective actions. Out of scope — the final production go/no-go, which the separate SDLC gate review workflow owns using the evidence package this workflow hands off to it. The release track and the quarterly track never force each other's steps.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- operate
Details
- teams
- it
- domains
- controls
- standards
- nist-800-53
- nist-csf-2
- gdpr
- pci-dss
- sourceTemplateId
- workflow-library:controls-secure-development-release-security-gate
- releaseId
- sha256:97dde0cbe2525c8b4665900d4ab33c1d99daacd4ad3a2b8cf27e14ff86954a66
- canonicalUrl
- https://workflow-library.com/all/?w=controls-secure-development-release-security-gate
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-CONFIG-04
- UC-VULN-04
- UC-VULN-07
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:97dde0cbe2525c8b4665900d4ab33c1d99daacd4ad3a2b8cf27e14ff86954a66
Connections
- Secure Development & Release Security Gate operates UC-CONFIG-04 — Build security and privacy into software design and upkeep
- Secure Development & Release Security Gate operates UC-VULN-07 — Harden runtime error handling, output filtering, and memory
- Secure Development & Release Security Gate operates UC-VULN-04 — Test software security during development and acceptance