{"description":"Standing operator workflow for the quarterly encryption sweep across data at rest, in transit, and in use, including CISO-approved compensating controls where encryption is infeasible, with a dashboarded readiness classification and corrective-action tracking. Each quarterly instance runs against — and enriches — the existing Control item for the data-encryption / in-use-protection control (domains cryptography_key_management + data_protection_privacy, quarterly frequency, control_owner set); it never creates a duplicate control. It consumes the prior cycle's carry-forward — the still-open corrective-action Issue items and the active compensating-control Control items already linked to that anchor Control (there is no upstream handoff package). Named deliverables: the sensitivity-classified inventory register; the at-rest, in-transit, movement-control, and data-in-use findings registers; the CISO-approved compensating-control register; the program-health dashboard; the corrective-action register; and the archived operating record. In scope: every data store, transmission channel, and removable-media pathway that holds or moves sensitive or account data, plus high-sensitivity workloads that process data in use. Out of scope: key and certificate inventory and rotation, which are reviewed under the separate key-management program. Terminal by design: no downstream workflow consumes this cycle's output — open corrective actions and compensating controls carry forward as explicit inputs to the next quarterly cycle.","edges":[{"id":"e-classify-encryption-gaps-document-and-approve-compensating-controls","label":"Compensating control","source":"classify-encryption-gaps","target":"document-and-approve-compensating-controls","whenValue":"compensating_control_required"},{"id":"e-classify-encryption-gaps-classify-program-readiness","label":"No gaps","source":"classify-encryption-gaps","target":"classify-program-readiness","whenValue":"no_gaps_identified"},{"id":"e-document-and-approve-compensating-controls-classify-program-readiness","source":"document-and-approve-compensating-controls","target":"classify-program-readiness"},{"id":"e-classify-program-readiness-log-corrective-actions","label":"Gaps","source":"classify-program-readiness","target":"log-corrective-actions","whenValue":"gaps_identified"},{"id":"e-classify-program-readiness-close-and-archive","label":"Healthy","source":"classify-program-readiness","target":"close-and-archive","whenValue":"healthy"},{"id":"e-log-corrective-actions-close-and-archive","source":"log-corrective-actions","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-CRYPTO-01","UC-CRYPTO-04"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-data-encryption-in-use-protection-operations","contentDigest":"sha256:2803b29ce9c1d03798d270f0824b32255b3f51d13b0c68c093d012b9ee7c90ae","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:2803b29ce9c1d03798d270f0824b32255b3f51d13b0c68c093d012b9ee7c90ae","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-data-encryption-in-use-protection-operations"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-data-encryption-in-use-protection-operations","source":"coworkcanvas-gallery","standards":["nist-csf-2","nist-800-53","pci-dss","soc2"],"teams":["it"]},"name":"Data Encryption & In-Use Protection Operations","nodes":[{"data":{"decisionField":"encryption_gap_disposition","description":"Judge encryption, retention, trusted transport and authorized data movement across the complete classified inventory, and decide whether an infeasible-encryption exception requires CISO authorization.","formData":{"fields":[{"key":"encryption_gap_disposition","label":"Encryption Gap Disposition","options":[{"label":"No gaps, standard met","value":"no_gaps_identified"},{"label":"Compensating control required","value":"compensating_control_required"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Judge encryption, retention, trusted transport and authorized data movement across the complete classified inventory, and decide whether an infeasible-encryption exception requires CISO authorization.\n\n**Inputs**\n- The anchor Control item — the existing data-encryption / in-use-protection control this instance runs against (`control_owner`, `frequency`, and `framework` already set). Enrich it; do not create a new control.\n- The asset and data-classification registers (data stores, channels, removable-media pathways, and workloads with sensitivity) — these live in external inventory systems (CMDB / cloud inventory); there is no native Asset item type, so the AssureSwarm copy is the prior-cycle inventory register document (below). Pull the anchor Control and its linked items with `coach-query-data`.\n- The prior cycle's inventory register — the XLSX document attached to this same step on the previous quarter's archived instance — to diff additions and removals.\n- The open compensating-control register — the active compensating-control **Control items** linked to the anchor Control (each linked to the Issue finding it covers), queried with `coach-query-data`.\n- The prior-cycle carry-forward — still-open corrective-action **Issue items** (created last cycle, linked to the anchor Control) plus the prior archived instance's operating-record export — to know what carried forward.\n- The governing encryption / cryptography standard and per-store business-need retention limits — the standard rides on the anchor Control (`Control.description` states approved algorithms and key strengths, `control_id` names it) or, where the tenant maintains one, a linked **Policy item** (`policy_type: standard`); retention limits per store live in the inventory register document.\n- The cycle trigger: routine quarterly cadence, an annual compensating-control re-approval falling due, or a newly onboarded store/channel/workload needing first-time coverage. Key and certificate inventory and rotation are out of scope here — they are reviewed under the separate key-management program.\n- The inventory register from the Inventory data stores and channels step: the data-store population (databases, file shares, buckets, backup/replica sets) with sensitivity classification and business-need retention limit; the open, public, and external channel population; the removable-media pathway population; and the authorized-users-and-processes list.\n- The at-rest encryption configuration of each store (algorithm, key strength, tokenization/truncation status) and its backup/replica topology; the transport-layer configuration of each channel (protocol version, cipher suite, certificate chain and expiry); access-control and DLP logs for the cycle and endpoint removable-media policy configuration (device allow-listing, encryption-at-write, blocking). All are read from the external storage, cloud, TLS-scanner, DLP, EDR and IAM systems; the evidence snapshots land as step documents here.\n- The governing standard on the anchor Control (`Control.description`, `control_id`) and the applicable frameworks carried on `Control.framework` (nist-csf-2, nist-800-53, pci-dss, soc2), pulled with `coach-query-data`. Mapped requirements: NIST SC-28, PR.DS-01, PCI DSS Req 3, SOC 2 CC6.1 (at rest); NIST SC-8, PR.DS-02, PCI DSS Req 4, SOC 2 CC6.7 (in transit).\n- Active compensating-control Control items and open corrective-action Issue items carried forward from the prior cycle.\n\n**Procedure**\n_This checkpoint absorbs “Inventory data stores and channels”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Inventory data stores and channels: Query the asset and data-classification registers to list every database, file share, object-storage bucket, and backup or replica set holding sensitive or account data.\n2. Enumerate every API, network segment, and external interface carrying that data in transit, flagging which are open, public, or external-facing — these are the channels the in-transit check must cover.\n3. Enumerate removable-media pathways and the processes authorized to move data off managed systems.\n4. Enumerate the high-sensitivity workloads that process data in memory or active sessions — this is the population for the data-in-use check.\n5. Tag each store, channel, and workload with its sensitivity classification, and tag each store with its defined business-need retention limit.\n6. Diff against the prior-cycle inventory to flag additions and removals, and flag any newly discovered store, channel, or workload lacking an accountable owner.\n7. Classify encryption gaps: For each in-scope store, read the at-rest encryption configuration: algorithm and key strength (e.g., AES-256), and whether tokenization or truncation is applied to stored account data in lieu of full encryption.\n8. Flag any store using no encryption, a weak or deprecated algorithm or key length, or storing full account data (e.g., unmasked PAN) without tokenization or truncation.\n9. Compare each store's actual retention against its business-need retention limit and flag any store retaining data beyond the approved window.\n10. Cross-check backup and replica copies to confirm encryption and retention apply consistently to every copy, not only the primary.\n11. Consolidate every unencrypted, weakly encrypted, or over-retained store into the at-rest findings register with the evidence reference for each.\n12. For each open and external channel, read the negotiated protocol version and cipher suite; flag anything below TLS 1.2 or using weak or deprecated ciphers.\n13. Validate the certificate trust chain and expiry; flag any expired, self-signed, or untrusted certificate.\n14. Test fallback behavior by attempting a legacy or insecure protocol or cipher and confirming it is rejected rather than silently accepted.\n15. Confirm integrity-protection mechanisms such as message authentication and signed payloads are active on each channel.\n16. Consolidate every channel with weak cryptography, an untrusted certificate, permitted insecure fallback, or missing integrity protection into the in-transit findings register with evidence.\n17. From access-control and DLP logs, list every user and process that moved in-scope data or wrote to removable media during the cycle.\n18. Reconcile each mover against the authorized-users-and-processes list and flag any transmission or removable-media write performed by an unauthorized identity.\n19. Verify removable-media controls — device allow-listing, encryption-at-write, and blocking policies — are active on every endpoint handling in-scope data.\n20. For each flagged movement, capture whether it is an authorized-but-unlisted path (the list needs updating) or a genuine unauthorized movement (remediation needed).\n21. Consolidate the movement-control findings with the evidence reference for each flagged item.\n22. Merge the at-rest, in-transit, and movement-control findings into a single gap list, each entry marked remediable immediately, requiring a compensating control, or already covered by an active compensating control whose annual CISO review is current.\n\n**Decision criteria**\n- Choose **no_gaps_identified** (\"No gaps, standard met\") when every store and channel meets the standard, OR when the only exceptions are already covered by an active compensating control whose annual CISO review is current — nothing new to authorize.\n- Choose **compensating_control_required** (\"Compensating control required\") when at least one gap where encryption is technically infeasible (legacy system, vendor constraint) has no current compensating control, or an existing compensating control is past or nearing its annual re-approval and must be re-authorized.\n- A gap closable by immediate configuration remediation does not by itself force the compensating-control branch — it is logged as a corrective action later; this branch turns on whether a compensating control must be documented and authorized.\n\n**Record in AssureSwarm**\n- **Step document** — attach the consolidated inventory register (stores, channels, removable-media pathways, workloads — each with classification, owner, and retention limit) as the XLSX file on this step via `coach-document-upload`. There is no native Asset/DataStore item type, so this register lives as a per-cycle step document rather than as queryable items — say so, and diff it against the prior cycle's document.\n- Note the cycle trigger and scope boundary on the step.\n- **Step form** — submit the SELECT field `encryption_gap_disposition`; record the consolidated gap-list rationale and evidence references in the step result, and the deciding approver in the step's approver record.\n- **Step document** — attach the at-rest, in-transit, and movement-control findings registers and the consolidated gap-classification summary (XLSX) on this step via `coach-document-upload`.\n\n**Exit criteria**\n- Every store, channel, pathway, and workload is listed with a sensitivity classification and named owner; the diff against last cycle is documented; no in-scope item is missing an owner; and the control owner has verified completeness against known systems.\n- Every in-scope store is confirmed encrypted, tokenized, or truncated per standard with retention minimized and backups and replicas covered; every open and external channel enforces strong cryptography, trusted certificates, rejected insecure fallback, and integrity protection; every mover reconciles to an authorized identity or carries a disposition and removable-media controls are enforced on all in-scope endpoints; all findings are evidenced in their registers; and the routing selector is submitted and the step result contains a rationale that cites the consolidated gap list, leaving the unused branch prunable.","kind":"decision","label":"Classify encryption gaps","performedBy":{"primitives":["coach-query-data","coach-document-upload"]}},"id":"classify-encryption-gaps"},{"data":{"description":"Agent drafts compensating-control documentation and routes it for CISO approval; human confirms approval and currency of the annual review","instructions":"**Objective** — Document every compensating control standing in for infeasible encryption, secure CISO approval, and confirm each control's annual review clock is current, so the exception is authorized rather than merely noted.\n\n**Inputs**\n- The gap list from Classify encryption gaps, filtered to entries marked \"requires a compensating control.\"\n- The running compensating-control register — the compensating-control **Control items** linked to the anchor Control, queried with `coach-query-data`; each carries its next annual review date on its linked policy_exception Issue (`exception_expiry_date`).\n- The CISO as approver.\n\n**Procedure**\n1. For each gap requiring a compensating control, create or update a compensating-control **Control item** with `coach-item-create` — set `control_id`, `description` (the compensating measure plus the risk it mitigates), `control_type` (preventive/detective/corrective per the measure), `control_category` (technical/administrative/physical), `domains` (cryptography_key_management, data_protection_privacy), `framework`, `control_owner` (the CISO-accountable owner), and `key_control: true` where it stands in for a key control.\n2. Link each compensating-control Control to its source-finding Issue and to the anchor Control with `coach-items-link`.\n3. Authorize the encryption exception itself as a **policy_exception Issue** with `coach-item-create` — `issue_type: policy_exception`, `source: self_assessment`, `exception_approver: CISO`, `exception_expiry_date` = the next annual review date, `description` = the technical or business reason encryption is infeasible — and link it (`coach-items-link`) to the compensating Control, the anchor Control, and the source finding. This is what makes the annual re-approval clock queryable (`exception_expiry_date` is the filterable expiry index); Control has no native approval-date field. Where a Risk item captures the accepted residual risk, set `treatment: accept` on it.\n4. Prepare the CISO native approval request, with the proposed conditions and next annual review date for each control recorded in the step result and linked policy_exception Issue.\n5. Route new and re-approval-due exceptions to the CISO; query the policy_exception Issues by `exception_expiry_date` to confirm none is past its annual review, flagging any that are.\n6. Consolidate the approved compensating-control register.\n\n**Record in AssureSwarm**\n- **Item create/update** — compensating-control **Control items** (`coach-item-create`; `control_type`, `control_category`, `domains`, `control_owner`, `key_control`) and, for each, a **policy_exception Issue** (`issue_type: policy_exception`, `exception_approver`, `exception_expiry_date`).\n- **Item relationships** — compensating Control ↔ source-finding Issue ↔ anchor Control, and the policy_exception Issue ↔ each of those, via `coach-items-link`; set `treatment: accept` on any linked Risk that is a granted residual-risk acceptance.\n- **Native approval** — the CISO decision; conditions and next annual review date remain in the step result and linked policy_exception Issue.\n- **Step document** — the approved compensating-control register (XLSX) via `coach-document-upload`.\n\n**Exit criteria** — Every compensating control is documented as a Control item, risk-justified, CISO-approved via a policy_exception Issue with a next-review `exception_expiry_date`, and no exception is past its annual review; the CISO and control owner have confirmed.","label":"Document and approve compensating controls","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-form-create","coach-query-data","coach-document-upload"]}},"id":"document-and-approve-compensating-controls"},{"data":{"decisionField":"readiness_disposition","description":"Judge data-in-use masking, isolation/enclave, processing-identity access and memory clearing together with the encryption and compensating-control results.","formData":{"fields":[{"key":"readiness_disposition","label":"Readiness Disposition","options":[{"label":"Healthy, within tolerance","value":"healthy"},{"label":"Gaps identified","value":"gaps_identified"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Judge data-in-use masking, isolation/enclave, processing-identity access and memory clearing together with the encryption and compensating-control results.\n\n**Inputs**\n- The high-sensitivity workload population from the inventory register (Inventory data stores and channels).\n- Per-workload configuration for masking, process isolation, enclave or confidential-computing, processing-identity access, and memory clearing — read from the external workload / platform config; the evidence snapshot lands as the step document here.\n- The governing standard on the anchor Control, pulled with `coach-query-data`. Mapped requirement: PR.DS-10 (data-in-use protection).\n\n**Procedure**\n_This checkpoint absorbs “Verify data-in-use protections”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Verify data-in-use protections: For each high-sensitivity workload, check the display or output layer masks sensitive fields where required, confirming raw values are not rendered where masking is mandated.\n2. Verify process isolation and memory-protection configuration; for the highest-sensitivity workloads confirm confidential-computing or an equivalent enclave technology is configured and active.\n3. Confirm access to data in use is limited to the processing identity itself, with no shared or standing human access to live process memory.\n4. Test that residual data is cleared from memory and temporary storage after each processing session completes.\n5. Consolidate any workload missing masking, isolation, enclave configuration, identity-scoped access, or memory clearing into a data-in-use findings register with evidence.\n\n**Decision criteria**\n- First compute the cycle metrics: at-rest and in-transit coverage percentage, unauthorized-movement events, open or overdue compensating-control approvals, and data-in-use findings by workload, and render them against thresholds on a health dashboard.\n- Choose **healthy** (\"Healthy, within tolerance\") when every store, channel, and workload meets standard and all compensating controls are current — no open unencrypted store, insecure channel, unauthorized movement, overdue approval, or data-in-use finding.\n- Choose **gaps_identified** (\"Gaps identified\") when any unencrypted or weakly encrypted store, insecure channel, unauthorized movement, overdue compensating-control approval, or data-in-use finding remains open at review.\n\n**Record in AssureSwarm**\n- **Step document** — attach the data-in-use findings register (XLSX) on this step via `coach-document-upload`.\n- **Step form** — submit the SELECT field `readiness_disposition`; record the metric and evidence references in the step result and the deciding owner in the step's approver record.\n- **Dashboard** — build (or refresh) the program-health dashboard with `coach-dashboard-create`; it persists across cycles rather than being rebuilt each quarter.\n- **Step document** — attach the readiness summary (XLSX) on this step via `coach-document-upload`.\n\n**Exit criteria**\n- Every high-sensitivity workload is confirmed to enforce masking, isolation or enclave protection, processing-identity-scoped access, and post-use memory clearing; findings are evidenced; and the control owner has verified.\n- The routing selector is submitted and the step result contains a rationale that cites the metrics and dashboard, and the unused branch is prunable.","kind":"decision","label":"Classify program readiness","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-dashboard-create"]}},"id":"classify-program-readiness"},{"data":{"description":"Agent converts each identified gap into an owned corrective action; human confirms every gap is owned, dated, and escalated where required","instructions":"**Objective** — Convert every gap identified at the readiness review into an owned, dated, tracked corrective action so no encryption or data-in-use weakness persists unaddressed.\n\n**Inputs**\n- The readiness summary and gap list from Classify program readiness, each gap tied to the store, channel, or workload that surfaced it.\n- The four findings registers (at-rest, in-transit, movement, data-in-use) and the compensating-control register, for root-cause and evidence linkage.\n\n**Procedure**\n1. Parse the readiness summary to list each open gap with its root cause and the store, channel, or workload that surfaced it.\n2. Create a corrective-action **Issue item** per gap with `coach-item-create` — `issue_type: deficiency` (or `observation` for a lower-severity gap), `source: self_assessment`, `severity`, `root_cause`, `issue_owner`, `identified_date`, `target_remediation_date`, and the interim mitigation in `remediation_plan`.\n3. Link each corrective-action Issue to the anchor Control — and to the relevant compensating-control Control where one applies — with `coach-items-link`; the driving finding itself lives in the step-document findings register, referenced in the Issue's `root_cause`.\n4. Raise program-level improvement **Issue items** for systemic gaps such as a chronically over-retained data store or a recurring unauthorized removable-media pathway.\n5. Escalate any regulatory-relevant gap (PCI DSS Req 3 and 4, NYDFS 500.15) to the accountable owner.\n\n**Record in AssureSwarm**\n- **Item create** — corrective-action **Issue items** (`issue_type: deficiency/observation`, `source: self_assessment`, `severity`, `root_cause`, `issue_owner`, `identified_date`, `target_remediation_date`, `remediation_plan`) plus program-level improvement Issues for systemic gaps.\n- **Item relationships** — each corrective-action Issue ↔ the anchor Control (and ↔ the relevant compensating Control) via `coach-items-link`.\n- **Step document** — attach the corrective-action register (XLSX) via `coach-document-upload`.\n\n**Exit criteria** — Every open gap has a named owner and due date, escalations are routed, and nothing is left untracked; the control owner has confirmed.","label":"Log corrective actions","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"log-corrective-actions"},{"data":{"description":"Automatically archive the authorized cycle record and carry open actions into the next cycle.","instructions":"**Objective** — Automatically preserve the authorized cycle record and its carry-forward actions after the preceding decision.\n\n**Inputs**\n- The full operating record for the cycle (all four findings registers, both decision forms, the compensating-control register, and the corrective-action register), exported with `coach-workflow-export`.\n- The open corrective-action Issue items, the compensating-control Control items whose policy_exception `exception_expiry_date` falls in the next cycle, and any pending remediation — for carry-forward.\n\n**Procedure**\n1. Export the full operating record with `coach-workflow-export` and archive it against the anchor Control in the designated evidence repository under retention controls, recording the archive location and reference.\n2. Confirm the still-open corrective-action **Issue items** and the compensating-control **Control items** (with any policy_exception Issue due for re-approval) remain open and linked to the anchor Control — they ARE the next cycle's inputs; record the carry-forward list in the closure document. Create a new tracking Issue only for pending remediation not already captured (`coach-item-create`), linking it to the anchor Control with `coach-items-link`.\n3. Update the control execution log with the cycle result and key metrics.\n4. Confirm the next quarterly review — and the annual compensating-control re-approval where applicable — is scheduled.\n\n**Record in AssureSwarm**\n- **Workflow instance** — export the operating record (`coach-workflow-export`) and archive it against the anchor Control as the durable audit trail.\n- **Item relationships** — keep the open corrective-action Issues and compensating-control Controls linked to the anchor Control as the next cycle's carry-forward inputs (`coach-items-link`); create a tracking Issue only for otherwise-uncaptured pending remediation (`coach-item-create`).\n- **Step document** — attach the closure record (naming the carry-forward list and archive reference) via `coach-document-upload`.\n\n**Exit criteria** — The archived record is immutable and retrievable; the next review and any annual re-approval are scheduled; no item remains open without a tracked owner; the authorized cycle record is complete.","label":"Close and archive","performedBy":{"primitives":["coach-workflow-export","coach-item-create","coach-items-link","coach-document-upload"]},"requiredApprovals":0},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:controls-data-encryption-in-use-protection-operations"}
