{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:9774074d4b29f254001fafd22efa7e724864084b0d28613d5fb5bbb8791a8dc4","slug":"controls-vulnerability-patch-management","url":"/assets/agent_workflow-controls-vulnerability-patch-management-40149d57.b05575dcb57fe230.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-vulnerability-patch-management","description":"Recurring vulnerability & patch management lifecycle covering NIST SP 800-53 RA-5 (vulnerability scanning) and SI-2 (flaw remediation) and NIST CSF 2.0 ID.RA and PR.PS. Each cycle runs as one recurring instance anchored to the EXISTING vulnerability & patch management Control item (a Control with domains = vulnerability_patch_management — e.g. the UC-VULN-01 scanning control, control_owner = cycle owner); the instance enriches that Control's evidence trail rather than creating a new subject, and the instance itself is the cycle record. In scope: authenticated scanning of the confirmed asset inventory, severity-based triage against the SLA matrix, standard and emergency remediation, rescan verification, time-bound risk acceptance of residuals, metrics reporting, and cycle closure. Named deliverables: the deduplicated, enriched finding register (one vulnerability_scan Issue per finding, linked to the Control), rescan closure evidence, time-bound compensating-control-backed risk-acceptance exceptions (policy_exception Issues), and the cycle KPI & trend report. Consumed as inputs, not produced: the authoritative asset inventory / CMDB and the enterprise change-approval policy (a Policy item). The workflow is self-triggered by its own scheduled scan window (or an actively-exploited advisory) with no upstream or downstream workflow — its carry-forward package feeds the next iteration of this same cycle at intake.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-vulnerability-patch-management","capabilities":[],"controls":["UC-VULN-01","UC-VULN-03","UC-ASSET-10","UC-ASSET-09"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:9774074d4b29f254001fafd22efa7e724864084b0d28613d5fb5bbb8791a8dc4","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-vulnerability-patch-management","standards":["nist-800-53","nist-csf-2"],"teams":["it"]},"id":"wf:C13","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC13","slug":"controls-vulnerability-patch-management","sourceIds":["iso-27001","nist-800-53","nist-csf-2","nydfs-500"],"sourceUrl":null,"title":"Vulnerability & Patch Management Cycle","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:00ddc579a64ca8f05b272db05bb2e820e1c2445c5de372adfcb22b9ce5bab162","properties":{},"sourceDetailPath":"/data/v1/records/wf-c13-1ffe161d.json","sourceId":"wf:C13","targetDetailPath":"/data/v1/records/uc-uc-asset-10-bbda2a79.json","targetId":"uc:UC-ASSET-10","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:aac289b08fe5983f3c59bfa0cda25a4360ae1fa98294e7da01c6dcdb294c9564","properties":{},"sourceDetailPath":"/data/v1/records/wf-c13-1ffe161d.json","sourceId":"wf:C13","targetDetailPath":"/data/v1/records/uc-uc-vuln-01-ec9a46fe.json","targetId":"uc:UC-VULN-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:accb279338b1b6069d45ede587ecdb2ef71585f2f99a56648108fb934cd8ba2a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c13-1ffe161d.json","sourceId":"wf:C13","targetDetailPath":"/data/v1/records/uc-uc-asset-09-911f6a6c.json","targetId":"uc:UC-ASSET-09","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d3852077b3eba8bcf14d8814eb2ca7fb83cad6909b66ab96fad2ba309c288a08","properties":{},"sourceDetailPath":"/data/v1/records/wf-c13-1ffe161d.json","sourceId":"wf:C13","targetDetailPath":"/data/v1/records/uc-uc-vuln-03-cc58f6a7.json","targetId":"uc:UC-VULN-03","type":"operates"}],"schemaVersion":1}
