{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:920c97d575af92eedda7f4b4e83b78d86377f2c1f6eba6645f8542651b6ba7c0","slug":"controls-public-content-external-sharing-authorization","url":"/assets/agent_workflow-controls-public-content-external-sharing-authorization-3233bc82.a90acfceaa3f1e0c.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-public-content-external-sharing-authorization","description":"Standing operator workflow for the public-posting and external-sharing authorization queue plus the quarterly permitted-without-authentication register and public-content exposure sweep, run per publication request and each quarter. Each operating cycle runs as one instance that enriches the existing UC-ACCESS-14 Control item in the control library (NIST 800-53 AC-14/AC-21/AC-22, family AC, preventive, quarterly) — it never creates a new control, and the workflow instance itself is the durable audit trail attached to that Control. In scope: public-facing systems (public website, support portal, developer documentation, status page, social channels) and external data shares governed by sharing agreements. Out of scope: authenticated internal content and access provisioning. Consumes each cycle: the living public-content and external-share register, the permitted-without-authentication register, and the active-sharing-agreements register (all pre-existing, refreshed cycle over cycle); the information-classification scheme (a Policy item, policy_type: standard); and the prior cycle's open carry-forward Issues. Named deliverables: the classified intake register, the authorization-verification log, the per-request publication dispositions, the refreshed permitted-without-authentication register, the quarterly exposure-sweep dashboard and findings report, and exposure corrective-action Issues linked to the Control. This control runs standalone — no upstream workflow feeds it and no downstream workflow consumes its output; the per-request authorization path and the quarterly sweep path are independent and both close in this instance.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-public-content-external-sharing-authorization","capabilities":[],"controls":["UC-ACCESS-14"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:920c97d575af92eedda7f4b4e83b78d86377f2c1f6eba6645f8542651b6ba7c0","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-public-content-external-sharing-authorization","standards":["nist-800-53"],"teams":["it","compliance-legal"]},"id":"wf:C32","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC32","slug":"controls-public-content-external-sharing-authorization","sourceIds":["aiuc-1","nist-800-53"],"sourceUrl":null,"title":"Public Content & External Sharing Authorization","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cf6570a2c3cf7f1caef0ab9a761c8dd3b18bd337750b3d0018674a9f77d403a8","properties":{},"sourceDetailPath":"/data/v1/records/wf-c32-53bd0bae.json","sourceId":"wf:C32","targetDetailPath":"/data/v1/records/uc-uc-access-14-99fd72b5.json","targetId":"uc:UC-ACCESS-14","type":"operates"}],"schemaVersion":1}
