{"description":"Evaluate GCP assurance-report scope, physical and environmental controls, exceptions and user responsibilities; record a bounded reliance decision rather than claiming to operate provider facilities.\n\nThis customer-side review relies on relevant independent reports, disclosed provider information and customer implementation evidence. It does not operate or certify GCP facility access or environmental safeguards. Preserve each report's permitted-use restrictions.","edges":[{"id":"e-investigate-anomalies-and-violations-escalate-and-remediate-anomaly","label":"Anomaly","source":"investigate-anomalies-and-violations","target":"escalate-and-remediate-anomaly","whenValue":"anomaly_or_violation_confirmed"},{"id":"e-investigate-anomalies-and-violations-classify-capability-readiness","label":"Clean","source":"investigate-anomalies-and-violations","target":"classify-capability-readiness","whenValue":"no_anomalies_detected"},{"id":"e-escalate-and-remediate-anomaly-classify-capability-readiness","source":"escalate-and-remediate-anomaly","target":"classify-capability-readiness"},{"id":"e-classify-capability-readiness-log-corrective-actions","label":"Gaps","source":"classify-capability-readiness","target":"log-corrective-actions","whenValue":"gaps_identified"},{"id":"e-classify-capability-readiness-close-and-archive","label":"Healthy","source":"classify-capability-readiness","target":"close-and-archive","whenValue":"healthy"},{"id":"e-log-corrective-actions-close-and-archive","source":"log-corrective-actions","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-ACCESS-21","UC-TPRM-04","UC-TPRM-08","UC-RISK-14"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-gcp-physical-environmental-subservice-reliance","contentDigest":"sha256:5af35ab842eb7c5b52ca2e9bcd4fd14f41d4c89299b5264a6dfb7250fcd2600c","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:5af35ab842eb7c5b52ca2e9bcd4fd14f41d4c89299b5264a6dfb7250fcd2600c","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-gcp-physical-environmental-subservice-reliance"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"controls-gcp-physical-environmental-subservice-reliance","source":"coworkcanvas-gallery","standards":["iso-27001","nist-800-53","soc1","soc2"],"teams":["it","risk-management"]},"name":"GCP Physical and Environmental Subservice Reliance","nodes":[{"data":{"decisionField":"monitoring_disposition","description":"Accept a bounded assessment scope and judge tested physical-security evidence, report periods, bridge limitations and material exceptions.","formData":{"fields":[{"key":"monitoring_disposition","label":"Monitoring Disposition","options":[{"label":"No anomalies detected","value":"no_anomalies_detected"},{"label":"Anomaly or violation confirmed","value":"anomaly_or_violation_confirmed"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Accept a bounded assessment scope and judge tested physical-security evidence, report periods, bridge limitations and material exceptions.\n\n**Inputs**\nThe cloud service inventory, contracts, applicable assurance reports and prior reliance review.\nThe in-scope report sections describing facility entry, visitors, personnel authorization, termination and monitoring.\nThe assurance package, available provider security notices, bridge information, prior exceptions and customer incident records.\n\n**Procedure**\n_This checkpoint absorbs “Establish the GCP assurance scope”, “Review physical-entry and visitor-control assurance”, “Review provider monitoring and current changes”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Establish the GCP assurance scope: Identify the GCP services and regions actually used, the customer system boundary, the review period and the accountable reliance owner. Obtain the current relevant independent assurance report through an authorized channel; public certification summaries alone are insufficient.\n2. Record the report issuer, type, period, opinion, exclusions and subservice treatment. Compare covered services and locations to the inventory, and list uncovered services or periods.\n3. Ask the qualified reviewer to decide whether the source package is relevant and sufficiently complete to assess reliance. Seek the missing report or alternative evidence where necessary; do not infer a clean result from unavailable evidence.\n4. Review physical-entry and visitor-control assurance: Extract the provider controls and examiner results for physical authorization, visitor identification and escort, entry logging, surveillance and revocation. Cite each relevant section and the period tested.\n5. Distinguish management descriptions, tested operating results, exceptions and information unavailable to customers. Do not request direct access to provider badge systems, staff rosters or surveillance feeds as though the customer operates those systems.\n6. Ask the security reviewer to challenge whether the described and tested controls address the customer's reliance risks; record scope limitations and evidence needed to resolve uncertainty.\n7. Review provider monitoring and current changes: Review report results for surveillance, entry-log review, access revocation and anomaly handling. Use authorized provider disclosures and assurance evidence; the customer does not operate the provider's monitoring systems.\n8. Reconcile the reporting period to the current review date. Assess any bridge letter for scope, issuer and limitations; it does not extend independent testing. Review disclosed material changes, incidents and unresolved prior findings.\n9. Prepare one evidence-referenced exception list separating substantiated findings, explained matters and unresolved information gaps for the decision owner.\n\n**Decision criteria**\n- Choose **no_anomalies_detected** only when the scoped evidence contains no unexplained material exception and no unresolved evidence gap that prevents a conclusion. Record explained matters and the limits of the reviewed period. This means no unresolved exception in the evidence reviewed, not proof that no provider incident occurred.\n- Choose **anomaly_or_violation_confirmed** when there is a material provider exception, a customer exposure requiring action or an unresolved evidence gap that prevents reliance. An information gap is not itself proof of a physical breach; state which condition caused this path.\n\n**Record in AssureSwarm**\nThe reviewed scope, source report references and dates, exclusions and unresolved evidence requests.\nA physical-security reliance table linking customer risks, provider controls, examiner results and limitations.\nThe monitoring-assurance review, date coverage, relevant notices and per-exception analysis.\nSubmit the `monitoring_disposition` SELECT. Record the cited evidence and actual human rationale in the step result and the decision owner in the native approval record.\n\n**Exit criteria**\n- A qualified reviewer accepts a bounded assessment scope and identifies any limitations before the assessment continues.\n- The reviewer has judged the relevance of the provider evidence and recorded all exceptions and missing coverage.\n- The reviewer can distinguish covered evidence from current-period uncertainty and choose the appropriate exception path.\n- The reviewer has selected the evidence-supported branch and material issues remain visible for response.","kind":"decision","label":"Classify subservice exceptions","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-items-link","coach-document-upload"]}},"id":"investigate-anomalies-and-violations"},{"data":{"instructions":"**Objective** — Track subservice exceptions as Issues.\n\n**Inputs** — The exception decision, affected service and control evidence, customer exposure and escalation criteria.\n\n**Procedure**\n1. Create or update an Issue for each material provider exception or unresolved reliance gap, with scope, evidence, owner and due date. Do not duplicate an existing case.\n2. Decide with the authorized service/risk owner whether to request provider clarification, operate customer-side safeguards, restrict use, consider alternatives or accept bounded residual risk. Customer actions must stay within the customer's authority.\n3. Route suspected customer compromise to the incident-response process and record the actual handoff. Track provider corrective action separately from customer mitigation; neither is complete without evidence.\n\n**Record in AssureSwarm** — Issue relationships to the service and relevant controls, approved response, provider correspondence and incident handoffs.\n\n**Exit criteria** — Every material exception has an authorized response, owner and next review date; no provider fix is claimed merely because it was requested.","kind":"task","label":"Track subservice exceptions as Issues","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"escalate-and-remediate-anomaly"},{"data":{"decisionField":"capability_readiness","description":"Approve the responsibility boundary and judge provider physical/environmental assurance alongside actual customer CUEC implementation.","formData":{"fields":[{"key":"capability_readiness","label":"Capability Readiness","options":[{"label":"Healthy, within tolerance","value":"healthy"},{"label":"Gaps identified","value":"gaps_identified"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Approve the responsibility boundary and judge provider physical/environmental assurance alongside actual customer CUEC implementation.\n\n**Inputs**\nThe assurance report, service contract, GCP shared-responsibility documentation and applicable complementary user-entity controls.\n\n**Procedure**\n_This checkpoint absorbs “Document the shared-responsibility boundary”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Document the shared-responsibility boundary: List the physical and environmental safeguards operated by the provider and distinguish customer-controlled premises, devices, cloud IAM and configuration. A customer's cloud administrator role does not grant physical data-center authority.\n2. Extract applicable complementary user-entity controls and assign each to a customer owner. Inspect the customer's actual implementation evidence; a report's list of responsibilities is not proof they operate.\n3. Ask the service owner and security reviewer to approve the responsibility allocation and identify gaps, including any customer premises that need their own facility-access workflow.\n\n**Decision criteria**\n1. Review the provider report's power resilience, fire protection, water and environmental safeguards, maintenance and testing results. Evaluate current report coverage and bridge limitations; do not query provider facilities systems directly.\n2. Reconcile provider exceptions, environmental or security notices, customer CUEC implementation and unresolved evidence requests. Ask the security reviewer to challenge the effect on the services actually used.\n- Choose **healthy** only when relevant evidence is current for the scoped conclusion, no material unresolved provider exception prevents reliance, applicable customer responsibilities are evidenced and any residual limitations are within the owner's authority and tolerance.\n- Choose **gaps_identified** when relevant evidence is missing or stale, a material provider exception remains unresolved, customer obligations are not demonstrated or the proposed reliance exceeds tolerance or authority.\n\n**Record in AssureSwarm**\nA responsibility matrix, applicable CUECs, customer implementation evidence and owned gaps.\nSubmit the `capability_readiness` SELECT. Attach the physical/environmental assurance and CUEC assessment with evidence dates, limitations and the actual human rationale. Record the owner natively.\n\n**Exit criteria**\n- The authorized owners accept the boundary; customer obligations and provider limitations are explicit and any gap is tracked.\n- The authorized owner has selected the supported branch; gaps pass to corrective-action decisions before the final reliance conclusion.","kind":"decision","label":"Classify subservice reliance readiness","performedBy":{"primitives":["coach-query-data","coach-document-upload"]}},"id":"classify-capability-readiness"},{"data":{"instructions":"**Objective** — Approve reliance corrective actions.\n\n**Inputs** — The readiness decision and its evidence gaps, provider exceptions, customer CUEC deficiencies and open Issues.\n\n**Procedure**\n1. Reconcile each readiness gap to an existing Issue or create an owned action with root cause, expected closure evidence, target date and interim safeguards.\n2. Separate provider remediation, customer implementation and contractual/alternative-service decisions so the responsible party can act. Retain original due dates when targets change.\n3. The authorized risk owner chooses the treatment and prioritization, escalates matters outside their authority and approves any time-bound risk acceptance. Missing evidence remains a limitation until resolved; it is not automatically an accepted risk.\n\n**Record in AssureSwarm** — The reviewed action register, treatment decisions, acceptance authority and expiry, and links to provider and customer evidence.\n\n**Exit criteria** — Every gap has an authorized treatment and accountable owner; the package is ready for a bounded reliance decision.","kind":"task","label":"Approve reliance corrective actions","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"log-corrective-actions"},{"data":{"instructions":"**Objective** — Approve the reliance conclusion and next review.\n\n**Inputs** — The scope, provider evidence, exception and readiness decisions, responsibility matrix and corrective-action register.\n\n**Procedure**\n1. The authorized service/risk owner decides whether to continue reliance, continue subject to explicit conditions, restrict use or defer the conclusion. State the services and evidence period covered and remaining uncertainty; this is a customer reliance decision, not an audit opinion on GCP.\n2. Record the actual approval and any conditions, then export and retain the reviewed package under the configured evidence-retention policy. Preserve access restrictions on confidential assurance reports.\n3. Carry forward unresolved actions without marking them complete, and set the next review date and triggers for report renewal, material service changes, incidents or provider exceptions.\n\n**Record in AssureSwarm** — The authorized reliance conclusion, conditions, evidence references, retention location, open actions and next review trigger.\n\n**Exit criteria** — The owner has made a bounded reliance decision and assigned the conditions and next review; the retained record does not claim operation of provider facilities.","kind":"task","label":"Approve the reliance conclusion and next review","performedBy":{"primitives":["coach-workflow-export","coach-item-create","coach-items-link","coach-document-upload"]}},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:controls-gcp-physical-environmental-subservice-reliance"}
