{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:bff91696eb5798d65dae1ed4785cae7e0def347c88e46ca51aa4faed126fbe9b","slug":"controls-change-release-management-operation","url":"/assets/agent_workflow-controls-change-release-management-operation-f4a540f2.4f68f72a91916445.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-change-release-management-operation","description":"Change & Release Management (CAB) as a decision-aware workflow that runs one recurring weekly instance against the EXISTING change-management ITGC Control item in the control library (domains: secure_configuration_change_management; mapped via Control.framework to nist-800-53, cobit-2019, iso-27001, and soc1, alongside the related UC-CONFIG-02/03, UC-ACCESS-16, and UC-SDLC-06/07/08/09 controls) — it enriches that control's operating evidence each cycle, it does not create the control. Upstream it consumes the open change-request queue and the emergency-change log exported from the ticketing system, plus the prior cycle's closure export as its carry-forward backlog. It covers change intake, security and risk impact analysis, environment segregation and configuration-baseline control, acceptance testing, the single CAB authorization gate, the emergency-change path, and controlled deployment with rollback and post-implementation verification — producing the prioritized CAB agenda and authorization packet, per-change risk-assessment memos, the environment-and-baseline verification memo, acceptance-testing summaries, the deployment-and-verification record, and the archived per-cycle evidence set. In scope: application, database, infrastructure, configuration, and procedure changes across development, test, and production environments. Out of scope: authoring the change itself — this workflow governs authorization and release, not development of the underlying code or configuration. Studio ships no native Change Request item type, so per-change records live as lines in step documents and in the workflow instance rather than as items. This is a terminal workflow with no downstream handoff: closure archives the cycle evidence set in place under retention, and the next cycle's intake reads this instance's closure export as its carry-forward source.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-change-release-management-operation","capabilities":[],"controls":["UC-CONFIG-02","UC-CONFIG-03","UC-ACCESS-16","UC-SDLC-07","UC-SDLC-06","UC-SDLC-08","UC-SDLC-09"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:bff91696eb5798d65dae1ed4785cae7e0def347c88e46ca51aa4faed126fbe9b","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-change-release-management-operation","standards":["nist-800-53","cobit-2019","iso-27001","soc1"],"teams":["it","finance"]},"id":"wf:C41","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC41","slug":"controls-change-release-management-operation","sourceIds":["cobit-2019","iso-27001","nist-800-53","soc1","soc2","sox"],"sourceUrl":null,"title":"Change & Release Management (CAB)","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:31bba5c22a2a5f37c88f8fd9fde19b93fa0dba136c0a76723313abd2158b9621","properties":{},"sourceDetailPath":"/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/data/v1/records/uc-uc-config-02-175d55b0.json","targetId":"uc:UC-CONFIG-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9fcff12028e176d5c2873539c7d60baa0ea46c4326e0725998744121fab21a9c","properties":{},"sourceDetailPath":"/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","targetId":"uc:UC-ACCESS-16","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b022fc233777d25d28095b221559ac0d3cf7e839c8481f82e0d806e22d4686ea","properties":{},"sourceDetailPath":"/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/data/v1/records/uc-uc-config-03-3a08a2b1.json","targetId":"uc:UC-CONFIG-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c2f5ec1ee219dfe5cf1ab92be5980ca23f2065db7827e4a1cec03981a3f7e9b1","properties":{},"sourceDetailPath":"/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/data/v1/records/uc-uc-sdlc-08-29ce69df.json","targetId":"uc:UC-SDLC-08","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c864fa00f5335636be6d821a5f146456add5940d3e01652e7dbc180a471e9624","properties":{},"sourceDetailPath":"/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","targetId":"uc:UC-SDLC-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f2c816489faa7b3d7c854a41723a32f75cb9decb7945ab3b3dde36825745dbd2","properties":{},"sourceDetailPath":"/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","targetId":"uc:UC-SDLC-07","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fb95cde5b0511e45ed39f3328947e9546d9b035cf18a4b708c2f28735b86435f","properties":{},"sourceDetailPath":"/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/data/v1/records/uc-uc-sdlc-09-659d0280.json","targetId":"uc:UC-SDLC-09","type":"operates"}],"schemaVersion":1}
