{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:97dde0cbe2525c8b4665900d4ab33c1d99daacd4ad3a2b8cf27e14ff86954a66","slug":"controls-secure-development-release-security-gate","url":"/assets/agent_workflow-controls-secure-development-release-security-gate-be976196.f9acdb538cbfa8e7.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-secure-development-release-security-gate","description":"Each run attaches as a workflow instance to the existing Control item for the secure-development/release-security-gate control (domains: secure_development_sdlc + vulnerability_patch_management) — enrich that Control, never create a duplicate; release runs and the quarterly checkpoint are separate instances on the same anchor Control. This workflow originates on its own artifacts (the release candidate, design artifacts, and the standing portfolio registers) and receives no upstream handoff package. Decision-aware: it branches on trigger type. In scope — for a release or major upgrade entering development, run security-and-privacy-by-design engineering, security test-plan execution, and runtime-hardening verification as parallel evidence streams, then resolve the release security disposition and assemble the release security evidence package with its acceptance-criteria index; for the quarterly portfolio checkpoint, run the vulnerability, patch, and end-of-life software review, publish the portfolio-health dashboard, and log corrective actions. Out of scope — the final production go/no-go, which the separate SDLC gate review workflow owns using the evidence package this workflow hands off to it. The release track and the quarterly track never force each other's steps.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-secure-development-release-security-gate","capabilities":[],"controls":["UC-CONFIG-04","UC-VULN-04","UC-VULN-07"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:97dde0cbe2525c8b4665900d4ab33c1d99daacd4ad3a2b8cf27e14ff86954a66","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-secure-development-release-security-gate","standards":["nist-800-53","nist-csf-2","gdpr","pci-dss"],"teams":["it"]},"id":"wf:C46","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC46","slug":"controls-secure-development-release-security-gate","sourceIds":["gdpr","iso-27001","nist-800-53","nist-csf-2","pci-dss"],"sourceUrl":null,"title":"Secure Development & Release Security Gate","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5667a3ac9340eae1683ddf8a31450063e6b380fa21e8a090314eb2ccd39e3308","properties":{},"sourceDetailPath":"/data/v1/records/wf-c46-88a88be6.json","sourceId":"wf:C46","targetDetailPath":"/data/v1/records/uc-uc-config-04-ed033b30.json","targetId":"uc:UC-CONFIG-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6909cfdc8692f82582141d1712282b5b685e8c5c6c83e17dc119ee4dd824568c","properties":{},"sourceDetailPath":"/data/v1/records/wf-c46-88a88be6.json","sourceId":"wf:C46","targetDetailPath":"/data/v1/records/uc-uc-vuln-07-abfa5ce7.json","targetId":"uc:UC-VULN-07","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:db63e47ad82fa0aa031f9a94687e09c922a31ab3f5c5bdab1e473e755a2fd221","properties":{},"sourceDetailPath":"/data/v1/records/wf-c46-88a88be6.json","sourceId":"wf:C46","targetDetailPath":"/data/v1/records/uc-uc-vuln-04-d07c87cf.json","targetId":"uc:UC-VULN-04","type":"operates"}],"schemaVersion":1}
