{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:6accc3950adde35373ca06d8c364cbd98d3206abe88ce5a64ae5d541ac074b30","slug":"controls-supply-chain-integrity-opsec-operations","url":"/assets/agent_workflow-controls-supply-chain-integrity-opsec-operations-e6b78df4.3bedf8e1b0cf0a94.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-supply-chain-integrity-opsec-operations","description":"Standing monthly operator workflow run against the existing supply-chain integrity Control item (UC-TPRM-07, frequency=monthly, domains=third_party_supply_chain_risk), with the OPSEC need-to-know Control (UC-TPRM-09) linked as the second in-scope control — enrich these existing Control items, never recreate them; the workflow instance attaches to the anchor Control as the durable operating record. Two concurrent workstreams. In scope: receipt-time tamper-evidence and authenticity inspection of critical systems and components, provenance and chain-of-custody upkeep, suspected-counterfeit disposition (each raised as a finding Issue linked to the anchor Control and the implicated Vendor) with inspector-training refresh where a lapse is found, and the OPSEC need-to-know review of the sensitive supply-chain information register with remediation of any overexposure. Named deliverables: the authenticated provenance and chain-of-custody register, the counterfeit-disposition cases, the OPSEC exposure-review worksheet, and the confirmed need-to-know-restricted disclosure footprint. No upstream workflow feeds this cycle — its inputs are the period's own receiving log and the sensitive supply-chain information register. This is a terminal standing control: procurement and vendor onboarding, contract-level third-party risk assessment, and facility physical security are out of scope, each handled by its own workflow; a substantiated counterfeit or compromised supplier is escalated to the third-party/vendor risk workflow rather than resolved here.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-supply-chain-integrity-opsec-operations","capabilities":[],"controls":["UC-TPRM-07","UC-TPRM-09"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:6accc3950adde35373ca06d8c364cbd98d3206abe88ce5a64ae5d541ac074b30","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-supply-chain-integrity-opsec-operations","standards":["nist-800-53","iso-27001"],"teams":["it","procurement"]},"id":"wf:C60","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC60","slug":"controls-supply-chain-integrity-opsec-operations","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"Supply-Chain Integrity & OPSEC Operations","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:24502ff03a69d28f5d40639734c82e5611e8dafee3afefd29b103fcf579cc256","properties":{},"sourceDetailPath":"/data/v1/records/wf-c60-62941eb6.json","sourceId":"wf:C60","targetDetailPath":"/data/v1/records/uc-uc-tprm-09-eb9772d0.json","targetId":"uc:UC-TPRM-09","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e9bcf6f06bb517f3f7d07073bf3502c0bb1a581b41df0fd29e61f632524f7f8a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c60-62941eb6.json","sourceId":"wf:C60","targetDetailPath":"/data/v1/records/uc-uc-tprm-07-c98d7242.json","targetId":"uc:UC-TPRM-07","type":"operates"}],"schemaVersion":1}
