{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:2c5564bd2edf274e1a4337ed6524ca7a882fedcab9c7b1f2d5715bae74dfca70","slug":"grc-data-governance-council-operations","url":"/assets/agent_workflow-grc-data-governance-council-operations-e6218050.01865be8618a167d.json"},"kind":"record","record":{"attributes":{"department":"operations","domain":"grc","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-data-governance-council-operations","description":"Data Governance Council Operations as a decision-aware workflow. Each quarterly cycle runs as one workflow instance attached to the existing UC-GOV-20 Control item (data governance council oversight; domains=governance_policy_oversight, frequency=quarterly) — it enriches that Control as its execution record and never creates a governing body. It validates the chartered council's charter and membership, runs the annual policy and lifecycle-standards review when due, compiles data-quality and integrity metrics, reviews and approves data-sharing and matching agreements, convenes the council with recorded minutes, and reports data governance status at the defined interval. Upstream, it consumes the prior cycle's archived governance record — the council and data-integrity-board charters (Policy items, policy_type: charter) and membership rosters, the current data-governance policy and data-lifecycle standards library (Policy items), the prior minutes and status report, and the open action-item register (Issue items linked to the Control). Named deliverables: the data-quality and integrity dashboard, the data-management oversight summary, the chair-approved council (and integrity board) minutes, the per-agreement dispositions, and the data-governance status report; the annual branch adds the refreshed policy and standards redlines and the charter and roster amendments. In scope each quarterly cycle: the named business units and data domains, the data governance council (always), and the data integrity board wherever data-matching (Privacy Act computer matching) or new data-sharing requires its review; a metrics-only cycle need not convene the integrity board. Out of scope: bodies and data domains not named in the cycle's scope. Downstream the workflow is self-contained — no separate workflow depends on it — but it chains cycle to cycle: this cycle's archived governance record, filed with the status report, is the next quarterly instance's primary input.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-data-governance-council-operations","capabilities":[],"controls":["UC-GOV-20"],"domains":["grc"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:2c5564bd2edf274e1a4337ed6524ca7a882fedcab9c7b1f2d5715bae74dfca70","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:grc-data-governance-council-operations","standards":["cobit-2019","nist-800-53"],"teams":["operations","privacy","it"]},"id":"wf:G21","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AG21","slug":"grc-data-governance-council-operations","sourceIds":["cobit-2019","nist-800-53"],"sourceUrl":null,"title":"Data Governance Council Operations","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a95775424e6bb9efd2d860397c677e086315572ac9172c381ef30456afbd8a0f","properties":{},"sourceDetailPath":"/data/v1/records/wf-g21-6aec79d1.json","sourceId":"wf:G21","targetDetailPath":"/data/v1/records/uc-uc-gov-20-4a468c1a.json","targetId":"uc:UC-GOV-20","type":"operates"}],"schemaVersion":1}
