workflow
Outsourced & Critical-Component Development Oversight
Quarterly outsourced- and critical-component development oversight, run as a recurring operating cycle against the EXISTING Control item for outsourced/critical-component secure development (UC-SDLC-10 / UC-SDLC-11; domains secure_development_sdlc + third_party_supply_chain_risk; NIST 800-53 SA-20/SA-21/SA-23, ISO 27001 A.8.30) — the workflow enriches that Control, it never creates a duplicate. Each quarter it inventories the active outsourced/third-party development engagements (enriching the Vendor register), verifies contract secure-development / IP-ownership / audit-rights terms, traces deliverables to requirements with security-test evidence on file, screens critical-system developers before access, refreshes the register of components critical to security or mission, and re-tests the specialized-development rationale and assurance evidence. It consumes the prior cycle's carry-forward Issue items (open corrective actions, contract renewals, components due for rationale review) and the archived prior workflow instance's registers; every gap it surfaces becomes an Issue linked to the anchor Control, giving one queryable corrective-action population. In scope: active outsourced and third-party development engagements and the register of components critical to security or mission; out of scope: internal-only development with no third-party contributor and general procurement risk unrelated to development. Self-terminating: no downstream workflow consumes this cycle's output — corrective actions are tracked to closure within this workflow and carried forward to the next quarter.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- procurement
- lineOfDefense
- operate
Details
- teams
- procurement
- it
- domains
- controls
- standards
- nist-800-53
- iso-27001
- sourceTemplateId
- workflow-library:controls-outsourced-critical-component-development-oversight
- releaseId
- sha256:f420cdf1d70a9a9222512c83f000ea88e6d3b4be6315825595c9cbb43247ea6b
- canonicalUrl
- https://workflow-library.com/all/?w=controls-outsourced-critical-component-development-oversight
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-SDLC-10
- UC-SDLC-11
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:f420cdf1d70a9a9222512c83f000ea88e6d3b4be6315825595c9cbb43247ea6b