{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:2803b29ce9c1d03798d270f0824b32255b3f51d13b0c68c093d012b9ee7c90ae","slug":"controls-data-encryption-in-use-protection-operations","url":"/assets/agent_workflow-controls-data-encryption-in-use-protection-operations-76272c04.993996cbe9eb070f.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-data-encryption-in-use-protection-operations","description":"Standing operator workflow for the quarterly encryption sweep across data at rest, in transit, and in use, including CISO-approved compensating controls where encryption is infeasible, with a dashboarded readiness classification and corrective-action tracking. Each quarterly instance runs against — and enriches — the existing Control item for the data-encryption / in-use-protection control (domains cryptography_key_management + data_protection_privacy, quarterly frequency, control_owner set); it never creates a duplicate control. It consumes the prior cycle's carry-forward — the still-open corrective-action Issue items and the active compensating-control Control items already linked to that anchor Control (there is no upstream handoff package). Named deliverables: the sensitivity-classified inventory register; the at-rest, in-transit, movement-control, and data-in-use findings registers; the CISO-approved compensating-control register; the program-health dashboard; the corrective-action register; and the archived operating record. In scope: every data store, transmission channel, and removable-media pathway that holds or moves sensitive or account data, plus high-sensitivity workloads that process data in use. Out of scope: key and certificate inventory and rotation, which are reviewed under the separate key-management program. Terminal by design: no downstream workflow consumes this cycle's output — open corrective actions and compensating controls carry forward as explicit inputs to the next quarterly cycle.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-data-encryption-in-use-protection-operations","capabilities":[],"controls":["UC-CRYPTO-01","UC-CRYPTO-04"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:2803b29ce9c1d03798d270f0824b32255b3f51d13b0c68c093d012b9ee7c90ae","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-data-encryption-in-use-protection-operations","standards":["nist-csf-2","nist-800-53","pci-dss","soc2"],"teams":["it"]},"id":"wf:C33","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC33","slug":"controls-data-encryption-in-use-protection-operations","sourceIds":["aiuc-1","hipaa","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Data Encryption & In-Use Protection Operations","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:24ab90dfdd49b75d1555acb1f931c03d52bb21b9f2275da9f651b386627e56ce","properties":{},"sourceDetailPath":"/data/v1/records/wf-c33-0d69c278.json","sourceId":"wf:C33","targetDetailPath":"/data/v1/records/uc-uc-crypto-04-097c39b7.json","targetId":"uc:UC-CRYPTO-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:382cfd77994c884aa61fa4aecb0954e212a241cf5c56f9622c28f315fbacd306","properties":{},"sourceDetailPath":"/data/v1/records/wf-c33-0d69c278.json","sourceId":"wf:C33","targetDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","targetId":"uc:UC-CRYPTO-01","type":"operates"}],"schemaVersion":1}
