{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:61fcfac851cd742968ad73ecf3783140c0be3de3489b3de2ac17e3c00cba230d","slug":"controls-incident-response-readiness-program","url":"/assets/agent_workflow-controls-incident-response-readiness-program-a8e458f4.5e9134e88b80729c.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-incident-response-readiness-program","description":"Standing operator workflow that runs against the EXISTING incident-response Control item — UC-IR-01 (domains=incident_management_response, frequency=annual) — with the training-and-testing Control UC-IR-02 linked to the same instance; both carry framework=[nist-800-53, iso-27001], and those governing standards drive the plan's required elements. It maintains and approves the written IR plan (a Policy item, policy_type=procedure, framework=[nist-800-53, iso-27001], review_frequency=annual, whose governed redline attaches to the item), distributes and protects it to named responders, delivers role-based training, runs the scheduled capability test (an Audit item, audit_type=readiness, linked back to the two Controls), and feeds exercise and training gaps back into the plan and training program as corrective-action Issue items (source=self_assessment). Named deliverables: the redlined IR plan on its Policy item, the exercise after-action report, the IR readiness dashboard, and the routed corrective-action register (Issue items). In scope: the IR plan's required elements (mission and scope, incident definitions and severity structure, roles and responsibilities, communication paths, and business-continuity/third-party coordination), the named-responder and leadership training population, and the scheduled capability test. Out of scope: live incident handling itself — this workflow builds and tests readiness, it does not run the response to an active incident. It runs on an annual cadence and off-cycle whenever a significant incident or a material organizational/system change occurs; no upstream workflow feeds it and it hands off to no downstream workflow — identified gaps re-enter this same workflow as corrective-action Issues.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-incident-response-readiness-program","capabilities":[],"controls":["UC-IR-01","UC-IR-02"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:61fcfac851cd742968ad73ecf3783140c0be3de3489b3de2ac17e3c00cba230d","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-incident-response-readiness-program","standards":["nist-800-53","iso-27001"],"teams":["it"]},"id":"wf:C57","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC57","slug":"controls-incident-response-readiness-program","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"Incident Response Readiness Program","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5d1da3bbabfdfb12ae952827d1eef946882f92760f56ed958b8c61fb6019953f","properties":{},"sourceDetailPath":"/data/v1/records/wf-c57-d3460b57.json","sourceId":"wf:C57","targetDetailPath":"/data/v1/records/uc-uc-ir-02-70e2bdb3.json","targetId":"uc:UC-IR-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9cf2658fbf30d3fb1affa64301fe9cb19514879ebc6204bdb55c4c7280dfeb06","properties":{},"sourceDetailPath":"/data/v1/records/wf-c57-d3460b57.json","sourceId":"wf:C57","targetDetailPath":"/data/v1/records/uc-uc-ir-01-e7711d29.json","targetId":"uc:UC-IR-01","type":"operates"}],"schemaVersion":1}
