{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:f80ac3091ec1ebb2c841e32384473adbffab3d5b1bc43189934663886e04428b","slug":"controls-identity-authenticator-lifecycle-administration","url":"/assets/agent_workflow-controls-identity-authenticator-lifecycle-administration-d76f0c97.9a6fa58c4951b3d6.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-identity-authenticator-lifecycle-administration","description":"Standing operator workflow for identity issuance and ownership, shared-identifier exception handling, the dormancy and non-reuse sweep, identity proofing and credential binding, and the full authenticator lifecycle from verified issuance through protection, exposure scanning, and scheduled rotation or revocation. Each monthly cycle runs as a new workflow instance attached to the existing identity & authenticator lifecycle Control item (the UC-ACCESS-06/07/08 family; domains=access_control_identity, frequency=monthly) — the run enriches that standing control's evidence trail, never creating a duplicate control. It consumes no upstream workflow: its inputs are the prior cycle's own carry-forward Issue items (open corrective actions, pending shared-ID review dates, deferred rotations, each linked to the anchor Control) plus current request, source, and inventory extracts. Named deliverables: the issuance & ownership register, the dormancy/non-reuse sweep log, the shared-ID exception disposition and its compensating-control Control items, the identity-proofing evidence package with credential-binding records, the authenticator issuance/strength/default-change log, the protection/exposure-scan disposition, the rotation-and-revocation log, and the identity & authenticator lifecycle-health dashboard — all rolled into an archived, immutable operating record. Because no Identifier/Authenticator/Credential item type exists in the schema, per-identifier, per-binding, and per-authenticator records live as rows in these step-attached registers and logs; only exceptions, gaps, and carry-forwards are promoted to Issue items linked to the anchor Control, and approved shared-identifier waivers are recorded as compensating-control Control items plus a policy_exception Issue. In scope: unique-identifier issuance and ownership mapping for users, services, and devices; shared/group-identifier exceptions; the monthly dormancy and non-reuse sweep; identity proofing proportional to assurance level and credential binding; and authenticator issuance, hardening, protection, exposure remediation, rotation, and revocation across passwords, tokens, keys, and certificates. Out of scope: access authorization and entitlement reviews, joiner/mover/leaver approval routing, and privileged-session management, which are operated by their own workflows. There is no downstream handoff workflow — corrective actions and carry-forward items are tracked to closure within this cycle and seed the next monthly instance of the same control.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-identity-authenticator-lifecycle-administration","capabilities":[],"controls":["UC-ACCESS-06","UC-ACCESS-07","UC-ACCESS-08"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:f80ac3091ec1ebb2c841e32384473adbffab3d5b1bc43189934663886e04428b","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-identity-authenticator-lifecycle-administration","standards":["nist-800-53","nist-csf-2","iso-27001"],"teams":["it"]},"id":"wf:C30","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC30","slug":"controls-identity-authenticator-lifecycle-administration","sourceIds":["iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2"],"sourceUrl":null,"title":"Identity & Authenticator Lifecycle Administration","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9b99bdec75ee38f020c8bccb9840c3323a9df3ec783294ee04a98fef22149a07","properties":{},"sourceDetailPath":"/data/v1/records/wf-c30-ece66f45.json","sourceId":"wf:C30","targetDetailPath":"/data/v1/records/uc-uc-access-07-ed06e251.json","targetId":"uc:UC-ACCESS-07","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a57e7562a54f7cb668d0ad49c961b002f2bd53c00cdd6dd489e6bd2283f00b01","properties":{},"sourceDetailPath":"/data/v1/records/wf-c30-ece66f45.json","sourceId":"wf:C30","targetDetailPath":"/data/v1/records/uc-uc-access-06-623f356c.json","targetId":"uc:UC-ACCESS-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a91cb2e5642c24df64ebdcfecc08e94433967724411d896c03234899546e4bbb","properties":{},"sourceDetailPath":"/data/v1/records/wf-c30-ece66f45.json","sourceId":"wf:C30","targetDetailPath":"/data/v1/records/uc-uc-access-08-7c9dc13e.json","targetId":"uc:UC-ACCESS-08","type":"operates"}],"schemaVersion":1}
