{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:4b7fee34ffe97fe67233456545758640c8491dfcb20c1331eb266b66f96734b4","slug":"controls-audit-logging-coverage-integrity-operations","url":"/assets/agent_workflow-controls-audit-logging-coverage-integrity-operations-111e9156.9a333df1ddafbcfa.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-audit-logging-coverage-integrity-operations","description":"Monthly operator cycle that verifies audit-logging coverage against the security-relevant event catalog, validates record content-completeness and clock synchronization, and confirms log protection, alerting, and retention, producing the coverage matrix, record content-completeness results, clock-drift report, and retention and capacity attestation evidence pack each cycle. Each instance attaches to the EXISTING audit-logging Control in the control library (control_id UC-LOG-01; framework nist-800-53 / iso-27001 / pci-dss / nydfs-500; domain logging_monitoring_detection; monthly frequency), with UC-LOG-02 / UC-LOG-03 linked by item relationships — enrich that Control's operating history, never create a duplicate control. Every gap, remediation, and carry-forward is logged as an Issue related back to that Control. In scope: every in-scope system, application, and network component, the security-relevant event catalog, and log protection and retention configuration. Out of scope: SIEM detection-rule tuning and incident investigation — surfaced detection gaps hand off to the SOC / SIEM-operations and incident-response workflows, not this cycle. No upstream workflow feeds this cycle; the prior cycle's open corrective-action and carry-forward Issue items (related to the anchor Control) plus the prior cycle's archived workflow instance are its only inputs, and close-and-archive seeds the next monthly run of itself.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-audit-logging-coverage-integrity-operations","capabilities":[],"controls":["UC-LOG-01","UC-LOG-02","UC-LOG-03"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:4b7fee34ffe97fe67233456545758640c8491dfcb20c1331eb266b66f96734b4","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-audit-logging-coverage-integrity-operations","standards":["nist-800-53","iso-27001","pci-dss","nydfs-500"],"teams":["it"]},"id":"wf:C52","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC52","slug":"controls-audit-logging-coverage-integrity-operations","sourceIds":["hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nydfs-500","pci-dss"],"sourceUrl":null,"title":"Audit Logging Coverage & Integrity Operations","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4d39aba6d5c1acc8a05c02a45649495379fa01912dd0c4218b99a86fb607e491","properties":{},"sourceDetailPath":"/data/v1/records/wf-c52-fa969595.json","sourceId":"wf:C52","targetDetailPath":"/data/v1/records/uc-uc-log-03-68ab930e.json","targetId":"uc:UC-LOG-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:70135cfb9795714526f681960c2a2b8a11aee8bffd8500ffb810d12c6a768928","properties":{},"sourceDetailPath":"/data/v1/records/wf-c52-fa969595.json","sourceId":"wf:C52","targetDetailPath":"/data/v1/records/uc-uc-log-02-0d3519a4.json","targetId":"uc:UC-LOG-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d7f433af76c52866d5e295cfe6b0d524560ba7efe642a3ac345a2a95c9485355","properties":{},"sourceDetailPath":"/data/v1/records/wf-c52-fa969595.json","sourceId":"wf:C52","targetDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","targetId":"uc:UC-LOG-01","type":"operates"}],"schemaVersion":1}
