{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:c1eba4819d732a63c86422514455ba1cffacc57cfca35373d63457d0e5694c14","slug":"controls-continuous-controls-monitoring-iscm","url":"/assets/agent_workflow-controls-continuous-controls-monitoring-iscm-47fa294d.599009e670247033.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"monitor"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-continuous-controls-monitoring-iscm","description":"Run the continuous controls monitoring (ISCM) cycle: pull the current-period control metrics and score them against thresholds, triage degraded and failed controls, update the POA&M, report control health to governance, recalibrate the monitoring strategy, then classify the disposition and prepare, hand off, and archive the cycle package. Each interval runs as one workflow instance attached to the existing Process item that represents the ISCM / continuous-controls-monitoring program (process_type = security_process) — enrich that program record every cycle, never create a duplicate. The monitored control set is the existing Control items (Control.frequency doubles as the monitoring cadence, Control.control_owner as the accountable owner) and the POA&M is the existing Issue register (issue_type = deficiency, source = self_assessment); metric definitions and pass/degraded/fail threshold bands have no native field, so they live in the ISCM strategy document carried on the anchor Process item. The cycle produces the control-health scorecard, the reconciled POA&M, the control-health / security-status report, and the recalibrated ISCM strategy. In scope: the recurring NIST 800-137 monitoring loop — metric collection, threshold comparison, triage, POA&M maintenance, security-status reporting, and monitoring-strategy tuning for the controls under continuous monitoring. Out of scope: formal security control assessment and driving gap remediation to closure, which is owned by the downstream Security Control Assessment & POA&M Remediation workflow that consumes this cycle's handoff package. No upstream workflow feeds this one; it is triggered by the arrival of the monitoring interval.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-continuous-controls-monitoring-iscm","capabilities":[],"controls":["UC-LOG-04","UC-AUDIT-21","UC-RISK-14","UC-RISK-13","UC-GOV-33"],"domains":["controls"],"lineOfDefense":"monitor","mappingStatus":"mapped","releaseId":"sha256:c1eba4819d732a63c86422514455ba1cffacc57cfca35373d63457d0e5694c14","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-continuous-controls-monitoring-iscm","standards":["nist-800-53","nist-csf-2"],"teams":["it","risk-management"]},"id":"wf:C1","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC1","slug":"controls-continuous-controls-monitoring-iscm","sourceIds":["cobit-2019","coso-erm","coso-ic","iso-27001","iso-31000","nist-800-53","nist-csf-2","soc2","sox"],"sourceUrl":null,"title":"Continuous Controls Monitoring (ISCM) Cycle","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0422a46450d702d7dbb0107b22e20d5dc22ffe94bd68dfdd6f27ef557669b882","properties":{},"sourceDetailPath":"/data/v1/records/wf-c1-f9e3db77.json","sourceId":"wf:C1","targetDetailPath":"/data/v1/records/uc-uc-risk-14-a5d6281b.json","targetId":"uc:UC-RISK-14","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0710c2c06139849a73f76fede4ef76ad75bdc3f599b5ba12e2638006dbbe821b","properties":{},"sourceDetailPath":"/data/v1/records/wf-c1-f9e3db77.json","sourceId":"wf:C1","targetDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","targetId":"uc:UC-LOG-04","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:85f0dedff23b18e2cce9cf1901f9b69491cf687e3fa1b14983e6d9e3f59f16db","properties":{},"sourceDetailPath":"/data/v1/records/wf-c1-f9e3db77.json","sourceId":"wf:C1","targetDetailPath":"/data/v1/records/uc-uc-risk-13-75b9f6c7.json","targetId":"uc:UC-RISK-13","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:964ecd8450a1658763c3eff7c1f52e19b196ba077a9a76a51d22a88d447186d6","properties":{},"sourceDetailPath":"/data/v1/records/wf-c1-f9e3db77.json","sourceId":"wf:C1","targetDetailPath":"/data/v1/records/uc-uc-audit-21-6406caa4.json","targetId":"uc:UC-AUDIT-21","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:988741cc23fe104184d595237a3e3a27adf50b582ee6d5b027e2196861d7f9fd","properties":{},"sourceDetailPath":"/data/v1/records/wf-c1-f9e3db77.json","sourceId":"wf:C1","targetDetailPath":"/data/v1/records/uc-uc-gov-33-50bafd1b.json","targetId":"uc:UC-GOV-33","type":"oversees"}],"schemaVersion":1}
