workflow
Identity Assurance Review
This review runs on an Audit engagement item created for the review cycle (audit_type: it_audit; scope: the identity assurance boundary) — the workflow instance attaches to that Audit, and the five in-scope UC-ACCESS Control items (UC-ACCESS-07/08/09/11/12) link to it. It is self-originating: no upstream workflow feeds it — it starts from the review trigger, the governing controls, and the collected evidence. Review the IAL, AAL, and FAL assurance requirements against the current identity proofing, authentication, and federation controls for the in-scope systems, then remediate, document, and hand off open gaps. It produces the target-level register, the current-state control inventory, the scored gap register, the per-control assurance determination memo, and the compiled assurance review package; each open gap is recorded as an Issue (POA&M) item linked to its UC-ACCESS Control and the anchor Audit. In scope: NIST SP 800-63 identity assurance levels for the systems named in the locked workplan. Out of scope: broader access provisioning, joiner-mover-leaver lifecycle, and privileged-access certification. Hands off the assurance determination and any open POA&M items to the Security Control Assessment and POA&M Remediation workflow.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- monitor
Details
- teams
- it
- domains
- controls
- standards
- nist-800-53
- sourceTemplateId
- workflow-library:controls-identity-assurance-review
- releaseId
- sha256:356c43deb1a22a13525cc411a881fc72d7a28eff0443a514ded9c6c5444bd201
- canonicalUrl
- https://workflow-library.com/all/?w=controls-identity-assurance-review
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- monitor
- controls
- UC-ACCESS-07
- UC-ACCESS-08
- UC-ACCESS-09
- UC-ACCESS-11
- UC-ACCESS-12
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:356c43deb1a22a13525cc411a881fc72d7a28eff0443a514ded9c6c5444bd201
Connections
- Identity Assurance Review oversees UC-ACCESS-12 — Lock, limit, and terminate user sessions
- Identity Assurance Review oversees UC-ACCESS-09 — Authenticate all users with multi-factor authentication
- Identity Assurance Review oversees UC-ACCESS-11 — Defend logons against brute-force and anomalous attempts
- Identity Assurance Review oversees UC-ACCESS-08 — Manage and protect authenticators across their lifecycle
- Identity Assurance Review oversees UC-ACCESS-07 — Proof identities before binding credentials