{"description":"Monthly operator cycle that verifies audit-logging coverage against the security-relevant event catalog, validates record content-completeness and clock synchronization, and confirms log protection, alerting, and retention, producing the coverage matrix, record content-completeness results, clock-drift report, and retention and capacity attestation evidence pack each cycle. Each instance attaches to the EXISTING audit-logging Control in the control library (control_id UC-LOG-01; framework nist-800-53 / iso-27001 / pci-dss / nydfs-500; domain logging_monitoring_detection; monthly frequency), with UC-LOG-02 / UC-LOG-03 linked by item relationships — enrich that Control's operating history, never create a duplicate control. Every gap, remediation, and carry-forward is logged as an Issue related back to that Control. In scope: every in-scope system, application, and network component, the security-relevant event catalog, and log protection and retention configuration. Out of scope: SIEM detection-rule tuning and incident investigation — surfaced detection gaps hand off to the SOC / SIEM-operations and incident-response workflows, not this cycle. No upstream workflow feeds this cycle; the prior cycle's open corrective-action and carry-forward Issue items (related to the anchor Control) plus the prior cycle's archived workflow instance are its only inputs, and close-and-archive seeds the next monthly run of itself.","edges":[{"id":"e-verify-logging-coverage-across-systems-remediate-coverage-gaps","label":"Gaps found","source":"verify-logging-coverage-across-systems","target":"remediate-coverage-gaps","whenValue":"gaps_found"},{"id":"e-verify-logging-coverage-across-systems-classify-logging-program-readiness","label":"Full coverage","source":"verify-logging-coverage-across-systems","target":"classify-logging-program-readiness","whenValue":"full_coverage"},{"id":"e-remediate-coverage-gaps-classify-logging-program-readiness","source":"remediate-coverage-gaps","target":"classify-logging-program-readiness"},{"id":"e-classify-logging-program-readiness-log-corrective-actions","label":"Gaps","source":"classify-logging-program-readiness","target":"log-corrective-actions","whenValue":"gaps_identified"},{"id":"e-classify-logging-program-readiness-close-and-archive","label":"Healthy","source":"classify-logging-program-readiness","target":"close-and-archive","whenValue":"healthy"},{"id":"e-log-corrective-actions-close-and-archive","source":"log-corrective-actions","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-LOG-01","UC-LOG-02","UC-LOG-03"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-audit-logging-coverage-integrity-operations","contentDigest":"sha256:4b7fee34ffe97fe67233456545758640c8491dfcb20c1331eb266b66f96734b4","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:4b7fee34ffe97fe67233456545758640c8491dfcb20c1331eb266b66f96734b4","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-audit-logging-coverage-integrity-operations"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-audit-logging-coverage-integrity-operations","source":"coworkcanvas-gallery","standards":["nist-800-53","iso-27001","pci-dss","nydfs-500"],"teams":["it"]},"name":"Audit Logging Coverage & Integrity Operations","nodes":[{"data":{"decisionField":"coverage_disposition","description":"Resolve catalog-category disputes and classify actual logging coverage against the owner-reviewed event catalog.","formData":{"fields":[{"key":"coverage_disposition","label":"Coverage Disposition","options":[{"label":"Full coverage","value":"full_coverage"},{"label":"Gaps found","value":"gaps_found"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Resolve catalog-category disputes and classify actual logging coverage against the owner-reviewed event catalog.\n\n**Inputs**\n- The operating anchor: the EXISTING audit-logging Control item in the control library (control_id UC-LOG-01), with UC-LOG-02 / UC-LOG-03 linked — this monthly instance attaches to it and every gap and corrective action created this cycle relates back to it.\n- Prior-cycle event catalog — the finalized catalog document (XLSX/DOCX) attached to the prior cycle instance's verify-logging-coverage-across-systems step; it is the living baseline you re-finalize this cycle.\n- Current system / application / network-component inventory — queried from the external CMDB / asset inventory (no native Studio item type) and attached here as a CSV evidence document.\n- The prior cycle's open corrective-action and carry-forward Issue items (related to the anchor Control) and the prior cycle's archived workflow instance — the only handoff into this cycle; no upstream workflow feeds it.\n- New deployments, decommissions, and security incidents since the last review — queried from external change-management / incident tooling (no native Incident type; the items that drove catalog changes are cited in the change-log document on this step).\n- Governing control clauses this catalog serves — Control items in the library with framework = nist-800-53 / iso-27001 / pci-dss / nydfs-500 and domain = logging_monitoring_detection, related to the anchor Control: NIST 800-53 AU-2 / AU-3 / AU-12, ISO 27001 A.8.15, PCI DSS Req 10.2, NYDFS 500.6.\n\n**Procedure**\n_This checkpoint absorbs “Review and update event catalog”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Review and update event catalog: Pull the current event catalog with coach-query-data. Confirm it covers each required category: successful and failed authentication, access to sensitive or regulated data, privileged and administrative actions, account-lifecycle changes, configuration and security-setting changes, and security-tool events (AV / EDR / IDS).\n2. Reconcile the catalog against change since the last review: every newly deployed system or application is mapped to the categories it can emit; every decommission is removed; every incident in the period is checked for an event type that would have detected it, adding one where missing.\n3. Draft catalog changes — additions, removals, category clarifications — each with a one-line rationale tied to a standard clause or to a specific incident or prior finding.\n4. Create a per-owner catalog sign-off item with coach-item-create and link each to the anchor Control and to the draft catalog with coach-items-link so sign-off ownership is explicit and traceable.\n5. Compile owner responses into the finalized catalog, resolving any category dispute with the logging platform owner as tie-breaker.\n6. Verify logging coverage across systems: Agent preparation before the human picks: (1) query logging-configuration state for every in-scope system, application, and network component with coach-query-data and cross-reference each against the finalized event catalog, category by category; (2) identify components deployed since the last cycle and verify each has audit logging enabled by default, flagging any that shipped without it; (3) build the coverage matrix — system by event category by enabled or disabled — with coach-dashboard-create, compute the coverage percentage, and list every gap with its responsible system owner; (4) attach the matrix and gap list with coach-document-upload.\n\n**Decision criteria**\n- full_coverage — every in-scope system, application, and network component logs every catalog event type, including every component deployed since the last cycle; coverage is 100% and the gap list is empty (NIST 800-53 AU-2 / AU-12; PCI DSS Req 10.2).\n- gaps_found — any component is missing one or more required event categories, or any newly deployed component shipped without default logging. A single confirmed gap selects this branch.\n\n**Record in AssureSwarm**\n- Per-owner catalog sign-off task — one Issue per system owner (coach-item-create), issue_type: observation, source: self_assessment, issue_owner = the system owner; link each to the anchor Control and to the draft catalog with coach-items-link. Studio has no lightweight Task type, so a low-severity Issue is the honest home for a sign-off task.\n- Finalized event catalog and its change log — step documents (XLSX catalog + DOCX/XLSX change log) attached with coach-document-upload.\n- Step form — submit the coverage_disposition SELECT field; record the step result citing the coverage percentage and the specific gaps and evidence references, and the step's approver record (the approver).\n- Coverage matrix (system x event category x enabled/disabled, with gap list) — step document (XLSX) attached via coach-document-upload, plus a coverage Dashboard built with coach-dashboard-create for the coverage percentage and per-system gap view.\n\n**Exit criteria**\n- Every system owner has reviewed; the finalized catalog reflects current systems and event types; each change carries a rationale; the catalog document is attached and ready for coverage to be verified against it.\n- coverage_disposition submitted with rationale and owner; the coverage matrix is attached; the unused branch is prunable (gaps_found routes to remediation, full_coverage routes straight to readiness classification).","kind":"decision","label":"Verify logging coverage across systems","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-items-link","coach-document-upload","coach-dashboard-create"]}},"id":"verify-logging-coverage-across-systems"},{"data":{"description":"Agent opens and tracks remediation tasks for every coverage gap and re-verifies closure; human confirms no gap remains untracked","instructions":"**Objective** — Close every logging-coverage gap surfaced by the coverage matrix so no system, application, or network component keeps operating without its required audit logging before readiness is judged.\n\n**Inputs**\n- The coverage matrix and gap list attached to the coverage decision, each gap naming the missing event categories and responsible system owner.\n- System owners' target dates and change windows.\n\n**Procedure**\n1. Parse the gap list. For each gap create a remediation task with coach-item-create capturing the missing event categories, the responsible system owner, a target date, and any interim compensating control.\n2. Link each remediation task to the coverage matrix with coach-items-link and route it to the named system owner.\n3. When an owner reports a change complete, re-query logging-configuration state for that system with coach-query-data and confirm the previously missing categories now emit records; do not accept an owner's assertion of closure without the re-query.\n4. Update the coverage matrix to reflect each closure and recompute the coverage percentage.\n5. For any gap that cannot close this cycle, ensure it has an owned, dated task and a documented interim mitigation so it carries forward rather than silently persisting.\n\n**Record in AssureSwarm**\n- Remediation task per gap — one Issue (coach-item-create), issue_type: deficiency, source: compliance_review, issue_owner = responsible system owner, target_remediation_date, with actual_remediation_date set on re-verified closure; link each to the anchor Control and the coverage matrix with coach-items-link.\n- Updated coverage matrix and remediation log — step documents (XLSX) attached with coach-document-upload.\n\n**Exit criteria** — Every gap is closed and re-verified by query, or has an owned, dated remediation task with a documented interim mitigation; the updated matrix is attached.","label":"Remediate coverage gaps","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-query-data","coach-document-upload"]}},"id":"remediate-coverage-gaps"},{"data":{"decisionField":"readiness_disposition","description":"Judge whether coverage, record completeness, clock drift, log access, tested alerts and retention collectively meet the cycle tolerances.","formData":{"fields":[{"key":"readiness_disposition","label":"Readiness Disposition","options":[{"label":"Healthy, within tolerance","value":"healthy"},{"label":"Gaps identified","value":"gaps_identified"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Judge whether coverage, record completeness, clock drift, log access, tested alerts and retention collectively meet the cycle tolerances.\n\n**Inputs**\n- The documented retention schedule and the longest applicable legal or regulatory retention period — the log-retention Policy item (coach-query-data; policy_type: standard, domains: logging_monitoring_detection, framework: nist-800-53 / pci-dss, policy_owner = logging platform owner) in the policy library, related to the anchor Control; the retention schedule document attaches to that Policy (for example PCI DSS Req 10.7: one year retained with three months readily available; five years where transaction-reconstruction rules apply).\n- Current log-storage capacity and forecast growth.\n- Alerting configuration for logging-failure and capacity-threshold conditions.\n- The finalized event catalog (used to stratify the record sample by event category), read access to audit records on each in-scope system, and the centrally managed list of any additional fields defined for investigation support.\n- The inventory of logging systems with their configured time source and last-sync status, plus the approved authoritative time source and drift tolerance threshold — the time-synchronization Policy item (coach-query-data; policy_type: standard, domains: logging_monitoring_detection, framework: nist-800-53 / pci-dss, policy_owner = logging platform owner) in the policy library, related to the anchor Control; the governing standard document attaches to that Policy.\n- Log-forwarding configuration for every in-scope system, access-control lists for the central log store and the logging tools, and tamper-alert rule configuration with its last-test date and detection history.\n- The upstream cycle evidence arriving at this join: the coverage matrix and gap list, the remediation log, and the retention and capacity attestation.\n\n**Procedure**\n_This checkpoint absorbs “Test alerting and attest retention”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Test alerting and attest retention: Trigger or simulate a logging-failure condition and a capacity-threshold condition in a controlled manner with coach-query-data, and confirm the designated personnel were alerted and the defined action was taken for each (NIST 800-53 AU-5).\n2. Pull current storage capacity against forecast growth with coach-query-data and confirm allocated capacity is consistent with the retention requirement and that headroom exists before the next cycle.\n3. Compare the configured retention period for every log source against the documented schedule and the longest applicable legal period, and confirm recent security logs remain readily available for analysis.\n4. Draft the retention and capacity attestation and build the alert-test evidence dashboard with coach-dashboard-create.\n5. Classify logging program readiness: Pull a sample of audit records from each in-scope system and event category with coach-query-data, stratified so every catalog category is represented (do not let one high-volume category dominate the sample).\n6. Check each sampled record for the required content fields — event type, timestamp, location or system, source (address / process / user), outcome (success or failure), and associated user or subject identity, with NIST 800-53 AU-3 as the reference set — and for any centrally managed additional fields (for example session id or request id) defined for investigation support.\n7. Compile record pass and fail counts per system and per field; flag any system whose record format structurally omits a required field — a format defect, distinct from a one-off sampling miss — note the omitted AU-3 field, and open a tracked fix owned by the system owner.\n8. Query the configured time source and last-sync status for every logging system with coach-query-data and compare each against the approved authoritative source (NIST 800-53 AU-8; PCI DSS Req 10.6).\n9. Compute measured drift per system and flag any system beyond the tolerance threshold.\n10. Confirm each system's timestamp format is internally consistent and mappable to UTC at the required granularity, recording whether offsets and DST are handled.\n11. For each drifting or misconfigured system, create a correction task with coach-item-create, link it to the drift finding with coach-items-link, and re-check the clock once the owner reports the correction applied — do not accept an unverified correction.\n12. Compile the clock-drift report: system, drift measured, correction applied, re-check result.\n13. Query the log-forwarding configuration for every in-scope system with coach-query-data and confirm each forwards to central storage where source-system users hold no modify or delete rights (NIST 800-53 AU-9; PCI DSS Req 10.5).\n14. Pull the access-control list for the central log store and the logging tools; verify access is restricted to a need-to-know set, flagging every excess or stale grant against current role and employment, and record any account holding modify or delete rights on central storage that should not have it, routing removal to the owner.\n15. Test tamper alerting: confirm a recent genuine detection event, or where none occurred this cycle, validate the alert-rule configuration and record the date of its last successful test — a rule never tested is itself a finding.\n16. Compute the cycle metrics with coach-query-data — coverage percentage and outstanding gaps, catalog-review completion, content-completeness pass rate, clock-drift instances and correction status, access-restriction exceptions, tamper-alert test result, failure and capacity alert test result, and retention-schedule exceptions — and list every breach with its owner and the evidence behind it.\n17. Build the program-health dashboard with coach-dashboard-create showing each metric against its threshold and the trend against prior cycles, and attach the readiness summary with coach-document-upload.\n18. The logging platform owner reviews the dashboard and the open-breach list and classifies the cycle's readiness.\n\n**Decision criteria**\n- healthy — every metric is within tolerance: coverage at 100% or all gaps closed; catalog reviewed by all owners; sampled records complete against the AU-3 fields, or every incomplete-format system carries a tracked fix; no uncorrected clock drift and timestamps UTC-mappable; forwarding unalterable by source-system users, central-store and tool access need-to-know with no open access exception; tamper and failure/capacity alerts tested and passing; and no retention-schedule exception.\n- gaps_identified — any coverage, content, clock-sync, access, alerting, or retention exception remains open at review time.\n\n**Record in AssureSwarm**\n- Retention and capacity attestation (the cycle deliverable) — step document (PDF/DOCX) attached with coach-document-upload.\n- Alert-test evidence dashboard — built with coach-dashboard-create showing the failure and capacity alert-test results.\n- Step form — submit the readiness_disposition SELECT field; record the step result citing the metric dashboard and the specific open breaches, and the step's approver record (the approver).\n- Record content-completeness results (pass / fail per system and field, plus the fix list; XLSX), the clock-drift report (system, drift measured, correction applied, re-check result; XLSX/PDF), log-protection evidence (forwarding verification, access-review results, tamper-alert test evidence), and the readiness summary — step documents attached with coach-document-upload. The content-completeness results and the clock-drift report are named monthly deliverables of this cycle.\n- Format-defect fix per incomplete-format system — one Issue (coach-item-create), issue_type: deficiency, source: compliance_review, issue_owner = system owner, target_remediation_date, noting the omitted AU-3 field. Correction task per drifting or misconfigured system — one Issue (coach-item-create), issue_type: exception, source: compliance_review, issue_owner = system owner, target_remediation_date. Link each to the anchor Control, and each correction task to its drift finding, with coach-items-link.\n- Any excess or stale access grant that must be removed is routed to the owner here; where it cannot be cleared this cycle it is logged as a corrective-action Issue (related to the anchor Control) at the log-corrective-actions step so it carries forward rather than persisting silently.\n- Program-health dashboard — built with coach-dashboard-create (a recurring monthly metrics publication) showing each metric against its threshold and the trend versus prior cycles.\n\n**Exit criteria**\n- Failure and capacity alerts fired and were actioned; storage capacity is adequate; every log source meets the documented schedule and legal minimum; the attestation is attached.\n- Sampled records are complete against the AU-3 fields or every incomplete-format system has a tracked fix; every logging system is within tolerance or has a verified correction and timestamps are UTC-mappable; forwarding is unalterable, log access is need-to-know with every exception routed, and tamper alerting is proven functional; all supporting evidence is attached; readiness_disposition is submitted with rationale and owner alongside the program-health dashboard; the unused branch is prunable (gaps_identified routes to corrective-action logging, healthy routes straight to close).","kind":"decision","label":"Classify logging program readiness","performedBy":{"primitives":["coach-query-data","coach-dashboard-create","coach-document-upload","coach-item-create","coach-items-link"]}},"id":"classify-logging-program-readiness"},{"data":{"description":"Agent converts each identified gap into an owned corrective action; human confirms every gap is owned, dated, and escalated where required","instructions":"**Objective** — Convert every gap identified at the readiness review into an owned, dated, tracked corrective action, and escalate systemic or legal-period exceptions, so nothing degrading audit-logging coverage or integrity goes unaddressed.\n\n**Inputs**\n- The readiness summary and program-health dashboard listing each open gap with its driving metric or finding.\n- Accountable owners for systemic improvements and for legal / retention escalations.\n\n**Procedure**\n1. Parse the readiness summary to list each gap with its root cause and the metric or finding that surfaced it.\n2. Create a corrective-action item per gap with coach-item-create capturing root cause, owner, due date, and interim mitigation; link it to the driving metric or finding with coach-items-link.\n3. Raise program-level improvement items for systemic gaps — a chronically under-capacity log store, a stale event catalog, a recurring clock-sync failure — rather than only per-instance fixes.\n4. Escalate any retention or legal-period exception to the accountable owner and record the escalation.\n\n**Record in AssureSwarm**\n- Corrective-action item per gap — one Issue (coach-item-create), issue_type: deficiency (or the driving finding's type), source: compliance_review, root_cause, issue_owner, target_remediation_date, remediation_plan capturing the interim mitigation; link each to the anchor Control and to any driving Issue or metric finding with coach-items-link. Escalate a retention or legal-period exception to the accountable owner and record the escalation in the item.\n- Corrective-action register — step document (XLSX) attached with coach-document-upload.\n\n**Exit criteria** — Every gap has a named owner and due date; systemic improvement items are raised; escalations are routed; nothing is left untracked before closure.","label":"Log corrective actions","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"log-corrective-actions"},{"data":{"description":"Automatically archive the authorized cycle record and carry open actions into the next cycle.","instructions":"**Objective** — Automatically preserve the authorized cycle record and its carry-forward actions after the preceding decision.\n\n**Inputs**\n- The full cycle evidence pack: coverage matrix, content-completeness results, clock-drift report, log-protection evidence, retention and capacity attestation, readiness summary, and any corrective-action register.\n- The designated evidence repository and its retention policy.\n\n**Procedure**\n1. Export the full operating record with coach-workflow-export and archive the coverage matrix, clock-drift report, and retention and capacity attestation in the designated evidence repository under retention controls, recording the archive location and reference.\n2. Create carry-forward items with coach-item-create for open corrective actions, the next event-catalog review, and the next clock-sync check; link each to its source with coach-items-link so it lands as an explicit input to the next cycle.\n3. Update the control execution log with the cycle result and key metrics, and confirm the next monthly review is scheduled.\n4. Verify the archived pack is immutable and retrievable before completing automatic archival.\n\n**Record in AssureSwarm**\n- Workflow instance — export the operating record with coach-workflow-export; the closed instance (attached to the anchor Control) is the durable, cycle-over-cycle audit trail on that Control.\n- Carry-forward items — one Issue per open corrective action, the next event-catalog review, and the next clock-sync check (coach-item-create), linked to the anchor Control and their source findings with coach-items-link so each lands as an explicit existing-item input to the next monthly instance.\n- Closure record noting the external evidence-repository archive location — step document attached with coach-document-upload.\n\n**Exit criteria** — The evidence pack is archived immutably and is retrievable; carry-forward items are created and linked; the next cycle is scheduled; nothing remains open without a tracked owner; the cycle record is complete.","label":"Close and archive","performedBy":{"primitives":["coach-workflow-export","coach-item-create","coach-items-link","coach-document-upload"]},"requiredApprovals":0},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:controls-audit-logging-coverage-integrity-operations"}
