{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:f4fe8ecd7ca5d670f071656992621a3ae28d900aec23d4843962eac9e65866ac","slug":"controls-security-privacy-architecture-review-board","url":"/assets/agent_workflow-controls-security-privacy-architecture-review-board-4e5f216d.b44a47d182c80e2d.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-security-privacy-architecture-review-board","description":"Standing operator workflow for the Security & Privacy Architecture Review Board. Each cycle runs as a recurring workflow instance attached to the existing UC-GOV-19 Control item (security & privacy architecture governance; framework nist-800-53 + cobit-2019) in the control library — it enriches that Control and its evidence trail, never creates a duplicate, and the chain of archived instances is that control's execution log (Control has no native execution-log field). The cycle maintains the enterprise, security, and privacy architecture views (across the business, data, application, technology, security, and privacy domains), runs a scheduled annual full-refresh branch, reviews solution designs and acquisition decisions for architectural alignment with a remediation loop, and pushes approved architecture updates into system security plans and acquisition requirements. It consumes: the prior cycle's archived baseline and architecture-view documents plus its open carryover Issue items; the live system/application inventory and mission/strategy statements (uploaded from external systems, no native item type); and the Risk items that form the security (category cyber_security) and privacy (category privacy) risk registers. Named deliverables: the refreshed enterprise architecture baseline package and drift log, the updated security and privacy architecture views with risk-crosswalk gap lists, the alignment assessment register, the pushed-updates package of SSP and acquisition-requirement changes, and the program-health dashboard. In scope: enterprise/security/privacy architecture maintenance, solution-design and acquisition alignment review, and SSP and acquisition-requirement updates. Out of scope: implementing the individual system security controls and running procurement themselves — those execute in the owning system-authorization (ATO) and acquisition/procurement workflows, which are the real downstream consumers of this cycle's SSP and acquisition-requirement updates. No upstream workflow feeds this cadence; it is triggered by the standing quarterly ARB cadence, the annual refresh date, or an ad hoc urgent design or acquisition submission.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-security-privacy-architecture-review-board","capabilities":[],"controls":["UC-GOV-19"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:f4fe8ecd7ca5d670f071656992621a3ae28d900aec23d4843962eac9e65866ac","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-security-privacy-architecture-review-board","standards":["nist-800-53","cobit-2019"],"teams":["it","privacy"]},"id":"wf:C28","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC28","slug":"controls-security-privacy-architecture-review-board","sourceIds":["cobit-2019","nist-800-53"],"sourceUrl":null,"title":"Security & Privacy Architecture Review Board","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:72990f4f4f171507f35400a202b3e2eefbe6143dfafe307117a947e2d1e74e79","properties":{},"sourceDetailPath":"/data/v1/records/wf-c28-1635c493.json","sourceId":"wf:C28","targetDetailPath":"/data/v1/records/uc-uc-gov-19-115302cb.json","targetId":"uc:UC-GOV-19","type":"operates"}],"schemaVersion":1}
