{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","download":{"releaseId":"sha256:68ba255991c944b50697cf043f9bc7fbde7ecf065f42ccb12f684c5a448b351c","slug":"grc-vendor-offboarding-secure-termination","url":"/assets/agent_workflow-grc-vendor-offboarding-secure-termination-015e96d2.8ba033cfa78df66c.json"},"kind":"record","record":{"attributes":{"department":"procurement","domain":"grc","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-vendor-offboarding-secure-termination","description":"Vendor Offboarding & Secure Termination as a decision-aware workflow triggered on a relationship termination. It runs on the vendor's existing Vendor register item - the offboarding enriches that record, it never creates a duplicate: the run marks the Vendor `monitoring_status: exited` and stamps `contract_end_date`, and where the vendor's risk is registered it links to the existing third-party Risk item (`category: third_party`). In scope: executing one vendor's contractual exit end to end - inventorying the vendor's access, data, and dedicated components; containing access immediately on for-cause exits; transitioning each service to its successor; revoking every credential; verifying data return or destruction; disposing of internal-side components using defined techniques; and retaining the post-relationship evidence. Out of scope: the underlying contract-termination or renewal business decision and any separately-governed affiliate contracts. Initial inputs are the termination trigger and effective date, the vendor's contractual exit provisions (master agreement, data processing addendum, exit plan) - which also carry the data-disposition and evidence-retention clauses consumed downstream - and the existing Vendor register item with its risk tier; there is no upstream workflow. The named deliverable is the retained, audit-standing termination evidence package assembled at compile-termination-evidence-and-retain; the workflow is terminal - close-and-archive exports the run and hands off nothing downstream.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-vendor-offboarding-secure-termination","capabilities":[],"controls":["UC-TPRM-06"],"domains":["grc"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:68ba255991c944b50697cf043f9bc7fbde7ecf065f42ccb12f684c5a448b351c","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:grc-vendor-offboarding-secure-termination","standards":["nist-800-53","nist-csf-2"],"teams":["procurement","it"]},"id":"wf:G30","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AG30","slug":"grc-vendor-offboarding-secure-termination","sourceIds":["nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"Vendor Offboarding & Secure Termination","type":"workflow"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e551307721f1b290d8a4ef02e0f7113f58963d184d26519bcec63fbc88e7e009","properties":{},"sourceDetailPath":"/data/v1/records/wf-g30-ab069982.json","sourceId":"wf:G30","targetDetailPath":"/data/v1/records/uc-uc-tprm-06-0d2c1b90.json","targetId":"uc:UC-TPRM-06","type":"operates"}],"schemaVersion":1}
