{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:a423b169a8e3d6d6864e185744540fef3107b5e5c468eb937fccef9fff160210","slug":"controls-authentication-platform-session-policy-operations","url":"/assets/agent_workflow-controls-authentication-platform-session-policy-operations-c0b42678.4777aea83f0a7a23.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-authentication-platform-session-policy-operations","description":"Monthly authentication-platform operating cycle. Anchor: this instance runs on the existing Process item for authentication-platform / session-management operations (process_type: security_process, frequency: monthly) — enrich that standing Process each cycle, never create a duplicate — with the four operated Control items UC-ACCESS-09/11/12/13 (framework tags carrying the standards mapping, domains: access_control_identity) linked to it. In scope: MFA enforcement and enrollment across remote, privileged, and sensitive-data access; secure log-on and federation-trust verification; lockout and anomalous-logon defense; session lifecycle controls (inactivity lock, automatic termination, concurrent-session limits, re-authentication for sensitive operations); and system-use, last-logon, and failed-attempt notices, across the IdP or SSO tenant, VPN or remote-access gateway, PAM tooling, and applications classified as housing sensitive data. Out of scope: identity provisioning and joiner-mover-leaver lifecycle, access certification, and privileged-access request approval, which are operated by their own workflows. There is no upstream workflow dependency: the instance is self-originating on its own initial inputs — the authentication-platform inventory (a document on the anchor Process, refreshed each cycle) and the prior-cycle operating record (the prior Workflow instance on the same Process plus its carried-forward open Issue items). The four operating areas run in parallel and reconverge at the platform-posture disposition. Named deliverables: the MFA enforcement-coverage register, the authentication-posture memo, the lockout-and-anomaly log, the session-policy compliance matrix, the banner-and-notice verification record, the platform-health dashboard and readiness summary, and the corrective-action register — each attached to its step, with every gap raised as a self_assessment Issue linked to the Control it degrades. There is no downstream handoff: this terminal recurring cycle seeds its own successor via carry-forward Issue items at close.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-authentication-platform-session-policy-operations","capabilities":[],"controls":["UC-ACCESS-09","UC-ACCESS-11","UC-ACCESS-12","UC-ACCESS-13"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:a423b169a8e3d6d6864e185744540fef3107b5e5c468eb937fccef9fff160210","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-authentication-platform-session-policy-operations","standards":["nist-800-53","nist-csf-2","iso-27001","nydfs-500"],"teams":["it"]},"id":"wf:C31","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC31","slug":"controls-authentication-platform-session-policy-operations","sourceIds":["hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss"],"sourceUrl":null,"title":"Authentication Platform & Session Policy Operations","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:16f7ac21edb56841a23f5338179ac780061e437f339c5ecd2b4e11d448770ba9","properties":{},"sourceDetailPath":"/data/v1/records/wf-c31-c58b2f38.json","sourceId":"wf:C31","targetDetailPath":"/data/v1/records/uc-uc-access-13-2ccf2dfa.json","targetId":"uc:UC-ACCESS-13","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1f964b879786f00be6cd7709a8e0782c994b9ce18bfec5e706b01a5d7a06e38b","properties":{},"sourceDetailPath":"/data/v1/records/wf-c31-c58b2f38.json","sourceId":"wf:C31","targetDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","targetId":"uc:UC-ACCESS-09","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2a4dcd459e177327f6c5f3a8c16c0932fdf5faf3a36434791bf6100b08f7b596","properties":{},"sourceDetailPath":"/data/v1/records/wf-c31-c58b2f38.json","sourceId":"wf:C31","targetDetailPath":"/data/v1/records/uc-uc-access-11-d0c7a1b8.json","targetId":"uc:UC-ACCESS-11","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:685b36d14de767557dc4718fdf300957718a727962b517b25617079a3d37bf14","properties":{},"sourceDetailPath":"/data/v1/records/wf-c31-c58b2f38.json","sourceId":"wf:C31","targetDetailPath":"/data/v1/records/uc-uc-access-12-8ef9e477.json","targetId":"uc:UC-ACCESS-12","type":"operates"}],"schemaVersion":1}
