{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:f420cdf1d70a9a9222512c83f000ea88e6d3b4be6315825595c9cbb43247ea6b","slug":"controls-outsourced-critical-component-development-oversight","url":"/assets/agent_workflow-controls-outsourced-critical-component-development-oversight-167a010e.a8653cfb141b9bda.json"},"kind":"record","record":{"attributes":{"department":"procurement","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-outsourced-critical-component-development-oversight","description":"Quarterly outsourced- and critical-component development oversight, run as a recurring operating cycle against the EXISTING Control item for outsourced/critical-component secure development (UC-SDLC-10 / UC-SDLC-11; domains secure_development_sdlc + third_party_supply_chain_risk; NIST 800-53 SA-20/SA-21/SA-23, ISO 27001 A.8.30) — the workflow enriches that Control, it never creates a duplicate. Each quarter it inventories the active outsourced/third-party development engagements (enriching the Vendor register), verifies contract secure-development / IP-ownership / audit-rights terms, traces deliverables to requirements with security-test evidence on file, screens critical-system developers before access, refreshes the register of components critical to security or mission, and re-tests the specialized-development rationale and assurance evidence. It consumes the prior cycle's carry-forward Issue items (open corrective actions, contract renewals, components due for rationale review) and the archived prior workflow instance's registers; every gap it surfaces becomes an Issue linked to the anchor Control, giving one queryable corrective-action population. In scope: active outsourced and third-party development engagements and the register of components critical to security or mission; out of scope: internal-only development with no third-party contributor and general procurement risk unrelated to development. Self-terminating: no downstream workflow consumes this cycle's output — corrective actions are tracked to closure within this workflow and carried forward to the next quarter.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-outsourced-critical-component-development-oversight","capabilities":[],"controls":["UC-SDLC-10","UC-SDLC-11"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:f420cdf1d70a9a9222512c83f000ea88e6d3b4be6315825595c9cbb43247ea6b","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-outsourced-critical-component-development-oversight","standards":["nist-800-53","iso-27001"],"teams":["procurement","it"]},"id":"wf:C63","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC63","slug":"controls-outsourced-critical-component-development-oversight","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"Outsourced & Critical-Component Development Oversight","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:76fa21c8e34eebc4ed16fd823134d811433d1d66dabd8679327463fb74fcc068","properties":{},"sourceDetailPath":"/data/v1/records/wf-c63-6a1e26cb.json","sourceId":"wf:C63","targetDetailPath":"/data/v1/records/uc-uc-sdlc-11-153d74aa.json","targetId":"uc:UC-SDLC-11","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bd0ef5399d4edb6148e25a04bb1f1ca8c4c3319db7a67afa05455666b2c9a29b","properties":{},"sourceDetailPath":"/data/v1/records/wf-c63-6a1e26cb.json","sourceId":"wf:C63","targetDetailPath":"/data/v1/records/uc-uc-sdlc-10-3ac58852.json","targetId":"uc:UC-SDLC-10","type":"operates"}],"schemaVersion":1}
