workflow

Outsourced & Critical-Component Development Oversight

Quarterly outsourced- and critical-component development oversight, run as a recurring operating cycle against the EXISTING Control item for outsourced/critical-component secure development (UC-SDLC-10 / UC-SDLC-11; domains secure_development_sdlc + third_party_supply_chain_risk; NIST 800-53 SA-20/SA-21/SA-23, ISO 27001 A.8.30) — the workflow enriches that Control, it never creates a duplicate. Each quarter it inventories the active outsourced/third-party development engagements (enriching the Vendor register), verifies contract secure-development / IP-ownership / audit-rights terms, traces deliverables to requirements with security-test evidence on file, screens critical-system developers before access, refreshes the register of components critical to security or mission, and re-tests the specialized-development rationale and assurance evidence. It consumes the prior cycle's carry-forward Issue items (open corrective actions, contract renewals, components due for rationale review) and the archived prior workflow instance's registers; every gap it surfaces becomes an Issue linked to the anchor Control, giving one queryable corrective-action population. In scope: active outsourced and third-party development engagements and the register of components critical to security or mission; out of scope: internal-only development with no third-party contributor and general procurement risk unrelated to development. Self-terminating: no downstream workflow consumes this cycle's output — corrective actions are tracked to closure within this workflow and carried forward to the next quarter.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
controls
department
procurement
lineOfDefense
operate

Details

teams
  • procurement
  • it
domains
  • controls
standards
  • nist-800-53
  • iso-27001
sourceTemplateId
workflow-library:controls-outsourced-critical-component-development-oversight
releaseId
sha256:f420cdf1d70a9a9222512c83f000ea88e6d3b4be6315825595c9cbb43247ea6b
canonicalUrl
https://workflow-library.com/all/?w=controls-outsourced-critical-component-development-oversight
capabilities
    mappingStatus
    mapped
    lineOfDefense
    operate
    controls
    • UC-SDLC-10
    • UC-SDLC-11
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:f420cdf1d70a9a9222512c83f000ea88e6d3b4be6315825595c9cbb43247ea6b

            Connections