{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:b53f505729c73529b0c617f56c09fe8bc6d9c256b403c66b164c684e8fed5372","slug":"controls-authorized-software-component-integrity-control","url":"/assets/agent_workflow-controls-authorized-software-component-integrity-control-ccc66fb7.1c3c67966918dc80.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-authorized-software-component-integrity-control","description":"Authorized Software & Component Integrity Control run as a decision-aware monthly cycle that enriches the existing \"Authorized Software & Component Integrity\" Control item in the control library (control_id UC-CONFIG-05/UC-CONFIG-06, frequency monthly, domains secure_configuration_change_management + third_party_supply_chain_risk) — each run is a workflow instance attached to that Control item, never a newly created control. It originates on its own (parallel entry threads consuming the cycle's own software-inventory, catalog/allowlist, install-rights, supplier-intake, and telemetry feeds) and also carries forward the prior cycle's still-open Issue items linked to the same Control. In scope: reconciling installed software across the in-scope endpoints, servers, and system images against the approved catalog and technical allowlist (the discrepancy register), triaging unauthorized installations to catalog-update / removal / escalation, verifying installation rights stay restricted to the authorized-installer roster from trusted sources (the install-rights and trusted-source exception list), tracking usage against license entitlements (the license-position report), and verifying supplier trust and signature integrity for every component acquired this cycle (the component verification register). Named deliverables — the discrepancy register, triage dispositions, catalog/allowlist change record, per-host removal evidence, install-rights and trusted-source exception list, component verification register, blocked-component investigation findings, and license-position report — are archived as the signed monthly cycle record on the workflow instance. Out of scope: incident containment and forensics — any suspected-malicious component is handed off, evidence intact, to the incident-response workflow, which owns that containment; this control cycle does not duplicate it.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-authorized-software-component-integrity-control","capabilities":[],"controls":["UC-CONFIG-05","UC-CONFIG-06"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:b53f505729c73529b0c617f56c09fe8bc6d9c256b403c66b164c684e8fed5372","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-authorized-software-component-integrity-control","standards":["nist-800-53","iso-27001","soc2","nist-csf-2"],"teams":["it"]},"id":"wf:C43","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC43","slug":"controls-authorized-software-component-integrity-control","sourceIds":["iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Authorized Software & Component Integrity Control","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:124988e2cf6b7833f2dd43b8ea888ec4df7e58583484cb675efdd2decb13400d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c43-e401f9da.json","sourceId":"wf:C43","targetDetailPath":"/data/v1/records/uc-uc-config-06-31f293f7.json","targetId":"uc:UC-CONFIG-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4eb2e4328a9f90720b3f93ff75430535c2b9fc365c2b0d75d4ca8ad6723578bb","properties":{},"sourceDetailPath":"/data/v1/records/wf-c43-e401f9da.json","sourceId":"wf:C43","targetDetailPath":"/data/v1/records/uc-uc-config-05-84d5ee43.json","targetId":"uc:UC-CONFIG-05","type":"operates"}],"schemaVersion":1}
