workflow

Secure Development & Release Security Gate

Each run attaches as a workflow instance to the existing Control item for the secure-development/release-security-gate control (domains: secure_development_sdlc + vulnerability_patch_management) — enrich that Control, never create a duplicate; release runs and the quarterly checkpoint are separate instances on the same anchor Control. This workflow originates on its own artifacts (the release candidate, design artifacts, and the standing portfolio registers) and receives no upstream handoff package. Decision-aware: it branches on trigger type. In scope — for a release or major upgrade entering development, run security-and-privacy-by-design engineering, security test-plan execution, and runtime-hardening verification as parallel evidence streams, then resolve the release security disposition and assemble the release security evidence package with its acceptance-criteria index; for the quarterly portfolio checkpoint, run the vulnerability, patch, and end-of-life software review, publish the portfolio-health dashboard, and log corrective actions. Out of scope — the final production go/no-go, which the separate SDLC gate review workflow owns using the evidence package this workflow hands off to it. The release track and the quarterly track never force each other's steps.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
operate

Details

teams
  • it
domains
  • controls
standards
  • nist-800-53
  • nist-csf-2
  • gdpr
  • pci-dss
sourceTemplateId
workflow-library:controls-secure-development-release-security-gate
releaseId
sha256:97dde0cbe2525c8b4665900d4ab33c1d99daacd4ad3a2b8cf27e14ff86954a66
canonicalUrl
https://workflow-library.com/all/?w=controls-secure-development-release-security-gate
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-CONFIG-04
    • UC-VULN-04
    • UC-VULN-07
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:97dde0cbe2525c8b4665900d4ab33c1d99daacd4ad3a2b8cf27e14ff86954a66

            Connections