{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:3d55f54b2fcd9c02bbcb99373843a2c850f589f699300583fd65d4ccef633e0e","slug":"controls-malware-email-web-content-defense-operations","url":"/assets/agent_workflow-controls-malware-email-web-content-defense-operations-78d327b4.1156de91dfab999d.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-malware-email-web-content-defense-operations","description":"Standing operator workflow for anti-malware coverage, detection handling, spam and phishing filtering, and mobile-code and website-content control, run on a monthly cadence by the security operations malware defense lead. Each monthly run is a new workflow instance attached to the existing Process item \"Malware, Email & Web Content Defense Operations\" (process_type: security_process, frequency: monthly), with Item relationships to the Control items it operates — UC-VULN-05 (malicious code protection) and UC-NET-13 (mobile code) in the control library (framework: nist-800-53, iso-27001, pci-dss). In scope: every system component commonly affected by malicious software, the email and web filtering entry and exit points, the mobile-code technologies in use, and website category and reputation filtering. Out of scope: endpoint patching and vulnerability remediation, incident response beyond first-line quarantine and alerting, and network firewall rule management. No upstream workflow feeds it: the monthly scope, the in-scope component and channel list, the accountable owners, and the prior-cycle carryover — the previous instance's open Issue items and step documents — are its own initial inputs. It produces the coverage reconciliation report, the detection-and-response log, the mobile-code authorization list, the tuned email/web and website-content filtering packages, a capability-health dashboard, a signed readiness classification, and a corrective-action register. It is terminal by design: rather than hand off to a downstream workflow, the close-and-archive step preserves the signed operating record under retention and loops carry-forward Issue items into the next monthly cycle.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-malware-email-web-content-defense-operations","capabilities":[],"controls":["UC-VULN-05","UC-NET-13"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:3d55f54b2fcd9c02bbcb99373843a2c850f589f699300583fd65d4ccef633e0e","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-malware-email-web-content-defense-operations","standards":["nist-800-53","iso-27001","pci-dss"],"teams":["it"]},"id":"wf:C44","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC44","slug":"controls-malware-email-web-content-defense-operations","sourceIds":["iso-27001","nist-800-53","pci-dss"],"sourceUrl":null,"title":"Malware, Email & Web Content Defense Operations","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:16145adcf912d6562f3fdbd6c8cac63b3df1e8b6cd132754c583b608f8930bc7","properties":{},"sourceDetailPath":"/data/v1/records/wf-c44-c8ff29dd.json","sourceId":"wf:C44","targetDetailPath":"/data/v1/records/uc-uc-vuln-05-5870fcee.json","targetId":"uc:UC-VULN-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:92574c9f6490a9c26946ae9223b5e2a3b0596de54a898d472215cff4ccc42699","properties":{},"sourceDetailPath":"/data/v1/records/wf-c44-c8ff29dd.json","sourceId":"wf:C44","targetDetailPath":"/data/v1/records/uc-uc-net-13-df790edf.json","targetId":"uc:UC-NET-13","type":"operates"}],"schemaVersion":1}
