{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:87d7ec847bc369edee212ee417702566be5995820fc364469fa7dab1fbcc5c9a","slug":"controls-platform-isolation-separation-enforcement","url":"/assets/agent_workflow-controls-platform-isolation-separation-enforcement-b069e776.277aec181b9d03df.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-platform-isolation-separation-enforcement","description":"Platform Isolation & Separation Enforcement as a decision-aware operator workflow. Each semiannual run attaches to the existing platform-isolation Control item — UC-NET-04 (framework nist-800-53, family SC, frequency semi_annual, control_owner = security architect), with sibling Controls UC-NET-05 and UC-NET-06 linked — enriching that standing control with a fresh cycle of evidence rather than creating any new anchor; consecutive instances stack on the same Control as its cycle history. Three verification streams run in parallel — user/system-management/security function and sensitivity-domain separation, shared-resource sanitization and covert-channel bandwidth reduction, and hardware- and software-enforced separation-mechanism integrity — and converge into a single posture review and closure. It consumes the prior cycle's still-open findings (Issue items carried forward on the anchor Control) plus live platform telemetry, and produces named deliverables: the function-and-domain separation matrix, the shared-resource sanitization report, the covert-channel analysis report, the hardware/software-mechanism verification report, a consolidated isolation-posture dashboard and evidence summary, and a signed cycle closure record. In scope: the semiannual verification and corrective-action closure of platform isolation across all in-scope platform components. Out of scope: the platform-engineering re-architecture behind a fix (tracked here as corrective-action Issues, executed by platform engineering) and boundary/network-protection controls owned by their own cycle. No upstream workflow feeds this cycle; its only handoff is downstream to its own next run — open corrective actions are left as OPEN Issue items on the anchor Control and arrive as explicit inputs to the next semiannual instance.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-platform-isolation-separation-enforcement","capabilities":[],"controls":["UC-NET-04","UC-NET-05","UC-NET-06"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:87d7ec847bc369edee212ee417702566be5995820fc364469fa7dab1fbcc5c9a","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-platform-isolation-separation-enforcement","standards":["nist-800-53"],"teams":["it"]},"id":"wf:C50","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC50","slug":"controls-platform-isolation-separation-enforcement","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"Platform Isolation & Separation Enforcement","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3f95c9a723e1d23219dbfd9f3deeed28cfa4709548b8dc597d4a95a333ea5b11","properties":{},"sourceDetailPath":"/data/v1/records/wf-c50-4402d67a.json","sourceId":"wf:C50","targetDetailPath":"/data/v1/records/uc-uc-net-05-b8a440f7.json","targetId":"uc:UC-NET-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:635338f7e05b03c1d8773471b3f96f488881db9ff56c9eda531c3710b6f80457","properties":{},"sourceDetailPath":"/data/v1/records/wf-c50-4402d67a.json","sourceId":"wf:C50","targetDetailPath":"/data/v1/records/uc-uc-net-04-d99d6d16.json","targetId":"uc:UC-NET-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:94c26cfd5dead60f6a061a1d76c189d2f8243601d9889b4b066291ae1cc8793d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c50-4402d67a.json","sourceId":"wf:C50","targetDetailPath":"/data/v1/records/uc-uc-net-06-f006626f.json","targetId":"uc:UC-NET-06","type":"operates"}],"schemaVersion":1}
