{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:7bfa6143ae99e0af99e205c327c02861bf5a3a398c178c92b28e94cdf2ce5f82","slug":"controls-information-security-program-governance-review","url":"/assets/agent_workflow-controls-information-security-program-governance-review-289b0c84.1c320bc19a171b9c.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-information-security-program-governance-review","description":"Standing operator workflow for the CISO's quarterly information security program governance review and its annual leg. Each cycle runs as one workflow instance attached to the existing \"Information Security Program Governance\" Process item (process_type: security_process, owner CISO), with the four governing Control items UC-GOV-06/09/10/15 linked to it. It is a decision-aware flow that enriches — never recreates — the senior-management-approved information security program plan (held as a Policy item) and the current role assignments every cycle, and branches into the written board report, workforce competency review, and plan reapproval when the annual interval or a significant change requires it. Named deliverables: the reapproved information security program plan (the Policy item, re-versioned and re-signed), the roles-and-authorities register, the annual written board report to the governing body, and the workforce competency review — each retained on the workflow instance. In scope: the program plan, security roles/authorities/reporting lines, the annual board report, and workforce competency for this organization; out of scope: executing the underlying protective controls and enterprise ERM governance, which are owned by their own workflows (coso-erm is referenced here only for oversight-of-design of the governance structure). There is no upstream or downstream workflow handoff — this cycle is genuinely self-contained: it starts from its own cadence trigger, consumes its own prior-cycle governance record, and seeds the next cycle at close.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-information-security-program-governance-review","capabilities":[],"controls":["UC-GOV-06","UC-GOV-09","UC-GOV-10","UC-GOV-15"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:7bfa6143ae99e0af99e205c327c02861bf5a3a398c178c92b28e94cdf2ce5f82","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-information-security-program-governance-review","standards":["nist-800-53","nydfs-500","coso-ic","coso-erm"],"teams":["it","executive"]},"id":"wf:C25","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC25","slug":"controls-information-security-program-governance-review","sourceIds":["cobit-2019","coso-erm","coso-ic","iso-27001","nist-800-53","nist-csf-2","nydfs-500","soc2"],"sourceUrl":null,"title":"Information Security Program Governance Review","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:515c4dac89a289ac1dcb9ed47119f1a457760286cccd3bfe5aec86b93154431b","properties":{},"sourceDetailPath":"/data/v1/records/wf-c25-a2c9f603.json","sourceId":"wf:C25","targetDetailPath":"/data/v1/records/uc-uc-gov-06-f1eb1346.json","targetId":"uc:UC-GOV-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:73b0dc90806d089f721c75968f1053e74e1fdca5b6289c50953959dd8cf299c9","properties":{},"sourceDetailPath":"/data/v1/records/wf-c25-a2c9f603.json","sourceId":"wf:C25","targetDetailPath":"/data/v1/records/uc-uc-gov-09-3b622881.json","targetId":"uc:UC-GOV-09","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c60e891944141548bf42d6bb9ed8de714c4e01c64d304d2d2b2a9a06bf238385","properties":{},"sourceDetailPath":"/data/v1/records/wf-c25-a2c9f603.json","sourceId":"wf:C25","targetDetailPath":"/data/v1/records/uc-uc-gov-15-828b3eec.json","targetId":"uc:UC-GOV-15","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cfa52634e502458d95de4e5becd02552a38d61eec8bb2c6863a09ab03d54cbf4","properties":{},"sourceDetailPath":"/data/v1/records/wf-c25-a2c9f603.json","sourceId":"wf:C25","targetDetailPath":"/data/v1/records/uc-uc-gov-10-016614d1.json","targetId":"uc:UC-GOV-10","type":"operates"}],"schemaVersion":1}
