{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:507a4a5bfc78815b47c68f319b5e08063e17570820c2df86cc5c083de3191bce","slug":"controls-user-activity-external-exposure-monitoring","url":"/assets/agent_workflow-controls-user-activity-external-exposure-monitoring-0f49c101.6f313232fb55e12b.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-user-activity-external-exposure-monitoring","description":"Monthly operator cycle for the standing user-activity and external-exposure monitoring control (UC-LOG-07/UC-LOG-11) — a detective, monthly-frequency Control that already exists in the control library. Each cycle runs as one workflow instance attached to that existing Control (enrich it — never create a duplicate control); the accountable owner and cadence come from Control.control_owner and Control.frequency=monthly. The instance runs the restricted privileged/remote session and acceptable-use review alongside the external open-source and dark-web exposure sweep, then converges every confirmed finding from both halves — each recorded as an Issue item linked to the anchor Control — into one consolidated restricted case log (XLSX) for security-event evaluation. Consumes upstream: no workflow feeds it — session capture and the exposure sweep are the two parallel entry points; each cycle draws on the standing monitoring program's authorized-reviewer roster, the acceptable-use policy and employee-monitoring disclosure notice (Policy items), the external search-set markers, and the prior cycle's carry-forward Issues. Named deliverables: the personnel-activity and exposure disposition decisions, the HR/legal referral and takedown Issues, the cycle-health dashboard, and the consolidated restricted case log. Downstream handoff: confirmed findings hand into the security-event evaluation queue — an informal handoff recorded as a reference on each case-log entry and in each Issue.description, since the graph has no terminal handoff node. In scope: privileged/remote session review, personnel acceptable-use monitoring, and the external open-source/dark-web exposure sweep for one monthly cycle. Out of scope: the automated SIEM alerting pipeline and the downstream security-event evaluation itself.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-user-activity-external-exposure-monitoring","capabilities":[],"controls":["UC-LOG-07","UC-LOG-11"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:507a4a5bfc78815b47c68f319b5e08063e17570820c2df86cc5c083de3191bce","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-user-activity-external-exposure-monitoring","standards":["nist-800-53","nist-csf-2"],"teams":["it","hr"]},"id":"wf:C54","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC54","slug":"controls-user-activity-external-exposure-monitoring","sourceIds":["nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"User Activity & External Exposure Monitoring","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:55cace1152d9b265e132b49e47bccedee687bf7e072e52d90bab1bd86b3566a4","properties":{},"sourceDetailPath":"/data/v1/records/wf-c54-ed6c01d8.json","sourceId":"wf:C54","targetDetailPath":"/data/v1/records/uc-uc-log-07-659fa92d.json","targetId":"uc:UC-LOG-07","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f7e877f82eeb1e464a3cb529e8f19caacad2bf7ad5046fc73f0c8e55b2832cb0","properties":{},"sourceDetailPath":"/data/v1/records/wf-c54-ed6c01d8.json","sourceId":"wf:C54","targetDetailPath":"/data/v1/records/uc-uc-log-11-abdbb946.json","targetId":"uc:UC-LOG-11","type":"operates"}],"schemaVersion":1}
