{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:2264ccb2a62c35b5cd25519eb830d768654f8034602856c3d593927ef0ebf28c","slug":"controls-security-monitoring-detection-operations","url":"/assets/agent_workflow-controls-security-monitoring-detection-operations-f46a70dc.6408a8ac24d36eb5.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-security-monitoring-detection-operations","description":"Each weekly cycle is a recurring instance attached to the existing continuous security-monitoring Control item (domains: logging_monitoring_detection, control_type: detective, frequency: weekly) — the cycle enriches that standing Control with its operating record, never creating a duplicate control. It consumes the prior cycle's carry-forward (unresolved queue Issues, open watchlist entries, open corrective actions) and the documented continuous-monitoring strategy (a Policy item linked to the Control), and produces named deliverables: the deployment coverage-and-effectiveness assessment, the enriched central SIEM analysis queue, the maintained detection watchlist, and the signed cycle security-status report. In scope: verifying monitoring deployment and effectiveness, working the central SIEM threat-intel analysis queue, triaging flagged anomalies, maintaining the detection watchlist, reporting security status to the defined roles, and verifying continuous protection-service health and tuning across hosts, networks, and applications at both the perimeter and the interior. Out of scope: incident containment, eradication, and recovery — confirmed security events are handed off mid-cycle to the Security Incident Response workflow rather than duplicated here.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-security-monitoring-detection-operations","capabilities":[],"controls":["UC-LOG-04","UC-LOG-05","UC-BCDR-13"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:2264ccb2a62c35b5cd25519eb830d768654f8034602856c3d593927ef0ebf28c","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-security-monitoring-detection-operations","standards":["nist-csf-2","nist-800-53","iso-27001","soc2"],"teams":["it"]},"id":"wf:C53","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC53","slug":"controls-security-monitoring-detection-operations","sourceIds":["cobit-2019","iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Security Monitoring & Detection Operations","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:39f18e04d3d5f4f20aebb3067d2197f33a603fe34b15f0c52a85e73ad998d214","properties":{},"sourceDetailPath":"/data/v1/records/wf-c53-cbf08eb0.json","sourceId":"wf:C53","targetDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","targetId":"uc:UC-LOG-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:983a9be40f6813a4d7d516887840738a76058c5de2b25f4daae96ef7fef2886d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c53-cbf08eb0.json","sourceId":"wf:C53","targetDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","targetId":"uc:UC-LOG-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d11c5a590a6921ffae253d315bf99e37f47b67b5d281af9679a02896f997f162","properties":{},"sourceDetailPath":"/data/v1/records/wf-c53-cbf08eb0.json","sourceId":"wf:C53","targetDetailPath":"/data/v1/records/uc-uc-bcdr-13-aa7feb8e.json","targetId":"uc:UC-BCDR-13","type":"operates"}],"schemaVersion":1}
