{"description":"Standing operator workflow that runs against the EXISTING incident-response Control item — UC-IR-01 (domains=incident_management_response, frequency=annual) — with the training-and-testing Control UC-IR-02 linked to the same instance; both carry framework=[nist-800-53, iso-27001], and those governing standards drive the plan's required elements. It maintains and approves the written IR plan (a Policy item, policy_type=procedure, framework=[nist-800-53, iso-27001], review_frequency=annual, whose governed redline attaches to the item), distributes and protects it to named responders, delivers role-based training, runs the scheduled capability test (an Audit item, audit_type=readiness, linked back to the two Controls), and feeds exercise and training gaps back into the plan and training program as corrective-action Issue items (source=self_assessment). Named deliverables: the redlined IR plan on its Policy item, the exercise after-action report, the IR readiness dashboard, and the routed corrective-action register (Issue items). In scope: the IR plan's required elements (mission and scope, incident definitions and severity structure, roles and responsibilities, communication paths, and business-continuity/third-party coordination), the named-responder and leadership training population, and the scheduled capability test. Out of scope: live incident handling itself — this workflow builds and tests readiness, it does not run the response to an active incident. It runs on an annual cadence and off-cycle whenever a significant incident or a material organizational/system change occurs; no upstream workflow feeds it and it hands off to no downstream workflow — identified gaps re-enter this same workflow as corrective-action Issues.","edges":[{"id":"e-route-plan-for-approval-incorporate-feedback-and-resubmit","label":"Revise","source":"route-plan-for-approval","target":"incorporate-feedback-and-resubmit","whenValue":"revise_and_resubmit"},{"id":"e-route-plan-for-approval-deliver-role-based-training","label":"Approved","source":"route-plan-for-approval","target":"deliver-role-based-training","whenValue":"approved"},{"id":"e-incorporate-feedback-and-resubmit-deliver-role-based-training","source":"incorporate-feedback-and-resubmit","target":"deliver-role-based-training"},{"id":"e-deliver-role-based-training-close-and-archive","source":"deliver-role-based-training","target":"close-and-archive"},{"id":"e-deliver-role-based-training-classify-readiness-and-route-gaps","source":"deliver-role-based-training","target":"classify-readiness-and-route-gaps"},{"id":"e-classify-readiness-and-route-gaps-log-corrective-actions-and-feed-back","label":"Gaps","source":"classify-readiness-and-route-gaps","target":"log-corrective-actions-and-feed-back","whenValue":"gaps_feed_plan_and_training"},{"id":"e-classify-readiness-and-route-gaps-close-and-archive","label":"Ready","source":"classify-readiness-and-route-gaps","target":"close-and-archive","whenValue":"ready_no_gaps"},{"id":"e-log-corrective-actions-and-feed-back-close-and-archive","source":"log-corrective-actions-and-feed-back","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-IR-01","UC-IR-02"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-incident-response-readiness-program","contentDigest":"sha256:61fcfac851cd742968ad73ecf3783140c0be3de3489b3de2ac17e3c00cba230d","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:61fcfac851cd742968ad73ecf3783140c0be3de3489b3de2ac17e3c00cba230d","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-incident-response-readiness-program"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-incident-response-readiness-program","source":"coworkcanvas-gallery","standards":["nist-800-53","iso-27001"],"teams":["it"]},"name":"Incident Response Readiness Program","nodes":[{"data":{"decisionField":"plan_approval_disposition","description":"Agent redlines the IR plan against its required elements, packages the change summary, and verifies the plan repository protections; human designated-management approver approves or sends it back for revision","formData":{"fields":[{"key":"plan_approval_disposition","label":"Plan Approval Disposition","options":[{"label":"Approved by designated management","value":"approved"},{"label":"Revise and resubmit","value":"revise_and_resubmit"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Redline the incident response plan so every required element stays current — mission and scope, incident definitions and severity structure, roles and responsibilities, communication paths, and business-continuity/third-party coordination — and obtain the designated management approver's decision on it together with the plan repository's protection controls (UC-IR-01). The designated management approver owns this decision.\n\n**Inputs**\n- The current approved IR plan — the IR plan Policy item (policy_type=procedure), whose currently-approved governed document is the baseline redline; its Policy.version, Policy.approved_by and Policy.next_review_date carry the last-review/approval history.\n- The governing standards that drive the required elements: Control.framework=[nist-800-53, iso-27001] on the anchor Controls UC-IR-01 and UC-IR-02 — the plan's mission, definitions, and coordination elements trace to these.\n- The reason this cycle is running: the annual review cadence, a significant incident since the last cycle, or a material organizational/system change. This workflow can start on any of the three triggers — note which applies, because it scopes the edits.\n- Open carryover corrective actions from the prior cycle's readiness close-out — still-open Issue items (issue_type=observation, source=self_assessment) linked to the anchor Controls that were routed back to the plan.\n- The current business-continuity plan — the business-continuity Policy item — and the named third-party/vendor IR-coordination obligations, held as Vendor items (Vendor.business_owner, Vendor.category); related Risk items (category=business_continuity / third_party) give the risk context to coordinate against.\n- Named owners: the IR Program Manager (accountable) — Control.control_owner on the anchor Control — and the designated management approver, captured in the step's approver record field.\n\n**Procedure**\n_Items 1–9 are agent-run (items 1–6 folded from the former \"Review and update the IR plan\" step); the human moment is the approver's decision in item 10._\n1. Pull the current approved plan and its version history with coach-query-data; confirm the baseline you are editing is the latest approved version, not a stray draft. Record the baseline version id on the step.\n2. Enumerate the five required elements and test each against reality this cycle: (a) mission and scope of the response capability; (b) incident definitions and the severity/classification structure; (c) roles and responsibilities; (d) internal and external communication paths; (e) coordination with business continuity and named third parties.\n3. For each element, draft the specific edit needed to reflect the incidents, organizational changes, or system changes that prompted this cycle. Worked example: if a new SaaS system entered scope, add its data-breach severity mapping under (b) and its vendor escalation contact under (e).\n4. Reconcile carryover corrective actions: for each prior-cycle lesson routed to the plan, confirm the edit lands in this redline or record why it is deferred.\n5. Link the draft plan to the business-continuity plan and third-party coordination records it references with coach-items-link, so the cross-references stay traceable and a reviewer can follow them.\n6. Compile a redline summary — a change table listing each edited element, old vs new text, and the trigger/rationale. Flag any required element you did NOT change as \"reviewed, no change\" so completeness is explicit rather than assumed.\n7. Package the redlined plan, the change summary, and the per-change rationale for the approver with coach-document-upload.\n8. Verify repository protection controls with coach-query-data: confirm access is restricted to authorized roles, version control is active, and edit permissions prevent unauthorized modification. Record the verification result — it is a first-class input to the decision, not a formality.\n9. Compile the approval history (prior review cycles and any outstanding conditions) so the approver decides with full context.\n10. Present to the designated management approver and capture the decision, its rationale, and the decision owner.\n\n**Decision criteria**\n- **approved** — Every required element is present and accurate (each marked edited-with-rationale or reviewed-no-change), the change summary is complete with per-change rationale, and repository protection controls (access restriction, version control, edit permissions) are verified. The plan is ready to distribute to named responders and to base training on.\n- **revise_and_resubmit** — One or more required elements are missing or inaccurate, the change rationale is insufficient, or protection controls are inadequate. An unprotected repository is grounds for this branch even when the content is correct. The plan returns for rework before any distribution or training.\n\n**Record in AssureSwarm**\n- Attach the redlined IR plan (DOCX) and the change-summary (XLSX) table to this step with coach-document-upload — the redline becomes the governed document on the IR plan Policy item — together with the approval package.\n- Update the IR plan Policy item with coach-item-update: bump Policy.version for this cycle and confirm Policy.review_frequency=annual and Policy.framework=[nist-800-53, iso-27001]; record the baseline Policy.version and this cycle's trigger on the step.\n- Link the IR plan Policy item to the business-continuity Policy item and to the named third-party Vendor items with coach-items-link so the cross-references stay traceable.\n- Submit the `plan_approval_disposition` SELECT field (approved | revise_and_resubmit); record the decision rationale and evidence references in the step result, and the approver in the native approval record.\n\n**Exit criteria** — Every one of the five required elements is marked either edited (with rationale) or reviewed-no-change and the redline summary is attached; cross-references to the business-continuity Policy item and third-party Vendor items are linked; the protection-control verification is recorded; the `plan_approval_disposition` routing selector is submitted and the step result contains a rationale and a named approver, exactly one branch is taken, and the unused branch is prunable.","kind":"decision","label":"Route plan for management approval","performedBy":{"primitives":["coach-document-upload","coach-query-data","coach-item-update","coach-items-link"]}},"id":"route-plan-for-approval"},{"data":{"description":"Agent applies the approver's requested changes and rebuilds the package; human confirms the resubmission addresses every comment","instructions":"**Objective** — Apply every comment from a revise_and_resubmit decision to the plan and finalize it, so the plan reaches an approved, distributable state with no dropped feedback (UC-IR-01).\n\n**Inputs**\n- The approver's comments and requested changes from the approval decision (the step result note plus any linked review record).\n- The IR plan Policy item's governed redline document and its change summary being revised.\n- The original approval request record, to keep the review trail intact.\n\n**Procedure**\n1. Pull the approver's comments with coach-query-data and map each comment to the specific plan element it affects (mission/scope, incident definition/severity, roles/communication, or business-continuity/third-party coordination). Build a comment-disposition table: comment -> element -> edit made.\n2. Revise each affected element as directed and update the redline and change summary so the new version cleanly supersedes the rejected one.\n3. If a comment cannot be actioned exactly as requested, record the reason and the alternative resolution rather than silently dropping it.\n4. Link the revision to the original approval request with coach-items-link so the full trail (request -> comments -> resubmission) stays connected.\n5. Correct any protection-control deficiency the approver flagged and confirm the fix.\n\n**Record in AssureSwarm**\n- Attach the revised IR plan (DOCX) and updated change summary with coach-document-upload — it supersedes the prior governed document on the IR plan Policy item; bump Policy.version with coach-item-update.\n- Link the revision to the original approval request with coach-items-link.\n- Record the comment-disposition table on the step.\n\n**Exit criteria** — Every approver comment has a recorded disposition (actioned or a reasoned alternative); the revised redline is attached; the IR Program Manager confirms all feedback is addressed, which finalizes approval on the revise path so the plan can proceed to distribution and training scoping.","label":"Incorporate feedback and resubmit","performedBy":{"primitives":["coach-query-data","coach-item-update","coach-items-link","coach-document-upload"]}},"id":"incorporate-feedback-and-resubmit"},{"data":{"description":"Accept current-plan acknowledgments and passed role-based training for every required person before the exercise.","instructions":"**Objective** — Accept current-plan acknowledgments and passed role-based training for every required person before the exercise.\n\n**Inputs**\n- The approved plan — the IR plan Policy item's governed document, from the approval decision's approved branch or the finalized resubmission.\n- The named-holder population: responders, leadership, and the named business-continuity and third-party contacts (the latter held as Vendor items).\n- The repository access-control configuration and the plan's review cadence (Policy.review_frequency, at minimum annual).\n- The approved IR plan Policy item and its change set this cycle (drives who must be trained on changed content), plus the current plan's roles, severity structure, and communication paths as the training content source.\n- The personnel roster with role-assignment dates and the prior training-completion register — both uploaded to this step (PBC from HR / the prior archived cycle); there is no native Person/Training item type.\n- The role-to-curriculum mapping (general user / responder / leadership) — a section of the approved plan, attached with the population schedule.\n- Escalation contacts (managers) for chasing overdue assignments.\n\n**Procedure**\n_This checkpoint absorbs “Distribute plan and restrict access”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Distribute plan and restrict access: Compile the distribution-and-acknowledgment log — one row per named holder (responders, leadership, and the named business-continuity and third-party Vendor contacts), each requiring a positive acknowledgment. There is no native Acknowledgment/Attestation item type, so these acknowledgments live as rows in this log document on the step, not as items.\n2. Link the approved plan document (the IR plan Policy item's governed document) to the log with coach-document-link so every recipient opens the authoritative version, never a stray copy.\n3. Verify and, where needed, tighten repository access restrictions and edit permissions with coach-query-data so only authorized roles can view or modify the plan; record the before/after permission state.\n4. Set Policy.approved_by, Policy.effective_date, and Policy.next_review_date on the IR plan Policy item with coach-item-update per the plan's cadence, so the next annual cycle is scheduled now.\n5. Compile the distribution-and-acknowledgment log showing each holder's acknowledgment status, and chase any outstanding acknowledgments to closure.\n6. Deliver role-based training: Query the roster and role-assignment dates with coach-query-data. Flag anyone who assumed a response, user, or leadership role within the defined period and owes INITIAL training, and anyone past roughly twelve months since last completion who owes the annual REFRESHER.\n7. Cross-reference this cycle's approved plan changes: flag personnel who must be trained on the specific changed content (for example a new severity tier or a changed communication path), even when their periodic training is not yet due.\n8. Build the training population-and-schedule register — one row per person, tagged to their role-based curriculum and marked initial, refresher, or change-driven. There is no native Person/TrainingAssignment item type, so assignments are rows in this register document on the step, not items.\n9. Record in each register row the plan change or role event that triggered the assignment (cross-referenced to the source Issue or the IR plan Policy.version) so the reason for each assignment is auditable.\n10. Compile the population and schedule with per-person due dates aligned to the defined training windows, and confirm every in-scope person is present and correctly role-tagged before deployment.\n11. Prepare role-based training, knowledge checks and acknowledgment activities through the approved training channel — one curriculum for general users, one for responders, one for leadership — each covering the current plan's roles, severity structure, and communication paths, with a knowledge check appropriate to the role.\n12. Deploy each assignment to its recipient from the population register; log every completion (pass/fail plus acknowledgment) as a row in the completion register as it arrives — there is no native TrainingAssignment item type, so completions are register rows, not items.\n13. Scan open assignments with coach-workflow-scan to find anyone approaching or past their due date; escalate overdue completions to the person's manager and record the escalation.\n14. For failed knowledge checks, re-assign the training and track re-completion — a fail is not a completion.\n15. Compile the completion register (per person, curriculum, pass/fail, acknowledgment status, and completion date against the due date) and have the IR Program Manager verify full completion — every in-scope person passed inside the window, with no overdue backlog — before the capability test proceeds.\n\n**Record in AssureSwarm**\n- Attach the distribution-and-acknowledgment log (XLSX) with coach-document-upload — per-holder acknowledgment rows live here, as there is no native Acknowledgment item type; link the IR plan Policy item's governed document to the log with coach-document-link.\n- Set Policy.approved_by, Policy.effective_date, and Policy.next_review_date on the IR plan Policy item with coach-item-update.\n- Record the verified before/after access-control state on the step (coach-query-data output).\n- Attach the training population-and-schedule register (XLSX) with coach-document-upload — per-person, role-tagged assignments are rows here, with the triggering plan change or role event recorded in each row (cross-referenced to the source Issue or the Policy version) — and attach the role-to-curriculum mapping alongside it.\n- Use the approved training channel for role-based knowledge checks and acknowledgments; preserve passed/failed results and completion evidence in the registers.\n- Attach the completion register with coach-document-upload — per-person completions (curriculum, pass/fail, acknowledgment, completion vs due date) are rows here, as there is no native TrainingAssignment item type.\n- Record escalations for overdue assignments on the step (coach-workflow-scan output).\n\n**Exit criteria**\n- Every named responder has acknowledged the current plan; access protections are verified and recorded; Policy.next_review_date is set; the IR Program Manager confirms all three before this stream feeds cycle close-out.\n- Every in-scope person has a role-tagged assignment row with a recorded trigger and a due date inside the defined window; every required person completed (passed) training within the defined period with no overdue backlog remaining; both registers are attached; the IR Program Manager has verified full completion before the capability test proceeds.","label":"Deliver role-based training","performedBy":{"primitives":["coach-item-create","coach-item-update","coach-document-upload","coach-query-data","coach-form-create","coach-workflow-scan","coach-items-link"]}},"id":"deliver-role-based-training"},{"data":{"decisionField":"readiness_disposition","description":"Run the realistic capability exercise and judge measured objective results, repeat lessons and training evidence to classify readiness.","formData":{"fields":[{"key":"readiness_disposition","label":"Readiness Disposition","options":[{"label":"Ready, no gaps","value":"ready_no_gaps"},{"label":"Gaps identified, feed back to plan and training","value":"gaps_feed_plan_and_training"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Run the realistic capability exercise and judge measured objective results, repeat lessons and training evidence to classify readiness.\n\n**Inputs**\n- The test schedule/cadence and the prior exercise's after-action report (to avoid re-testing only what already passed and to re-exercise prior gaps).\n- The current plan's severity structure, roles, and communication paths (the scenario source).\n- The trained responder and leadership roster from the training stream (the participants).\n- The raw observation timeline, participant feedback, and the measurable exercise objectives from the capability test (documents on the classify-readiness-and-route-gaps step).\n- The IR plan Policy item's sections and the training curricula (the targets each lesson maps to — plan gaps to the anchor Control, training gaps noted by curriculum).\n- The training completion register and any overdue items carried from the prior cycle.\n\n**Procedure**\n_This checkpoint absorbs “Plan and execute capability test”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Plan and execute capability test: Pull the test schedule, the prior after-action report, and the current plan's severity structure and roles with coach-query-data; identify which objectives were weak last time and must be re-exercised.\n2. Draft the exercise scenario and injects — a tabletop simulation or equivalent — sized to exercise the plan's incident definitions, severity escalation, and internal/external communication paths, and to include coordination with business continuity and named third parties.\n3. Define explicit, measurable exercise objectives (for example \"responders classify severity within N minutes\" or \"the leadership notification path reaches the named contact\"). These become the pass/fail yardstick in the after-action report.\n4. Create the capability-test exercise record as an Audit item with coach-item-create — audit_type=readiness, scope=the exercise scenario, lead_auditor=the facilitator, fieldwork_start/fieldwork_end=the exercise date — and link it to the anchor Controls UC-IR-01/UC-IR-02 and to the responder/leadership participants with coach-items-link.\n5. Facilitate or coordinate execution, capturing a raw observation timeline — who did what, when, and where the plan or a communication path broke down.\n6. Classify readiness and route gaps: Pull the observation timeline, participant feedback, and objective-by-objective performance with coach-query-data.\n7. Draft the after-action report: for each objective, met or missed, with timing against the defined response objective, plus any plan or communication-path breakdown observed. Distinguish a plan gap (the plan itself is wrong or incomplete) from a training gap (people failed to execute a correct plan) — they route to different fixes.\n8. Create a lesson-learned Issue item for each finding with coach-item-create — issue_type=observation (or finding for a serious gap), severity set, source=self_assessment, root_cause captured, identified_date set.\n9. Relate each lesson Issue to the readiness Audit item and, for a plan gap, to the anchor Control UC-IR-01 (mission/scope, definitions/severity, roles/communication, business-continuity/third-party coordination) with coach-items-link; for a training gap, name the affected curriculum in the Issue.description (there is no native training-curriculum item to link) — this mapping is what lets this decision and the corrective-action step route the gap.\n10. Reconcile against prior-cycle lessons: mark any recurring finding as a repeat, which raises its priority.\n11. Compute the cycle metrics with coach-query-data: training completion rate against the defined period, test objectives met versus missed, count of lessons requiring a plan or training change, and any overdue items carried from the prior cycle.\n12. Build the IR readiness dashboard with coach-dashboard-create showing each metric against its threshold and the trend against prior cycles.\n13. List every gap with the lesson or metric that surfaced it, so the branch choice rests on evidence rather than impression.\n14. Apply the criteria below and select the branch.\n\n**Decision criteria**\n- **ready_no_gaps** — Training completed on time (completion rate meets the defined threshold with no overdue backlog), the test met all of its measurable objectives, and no lesson-learned requires a plan or training change. The cycle can close.\n- **gaps_feed_plan_and_training** — Any of the following holds: training completion missed the threshold or carried overdue backlog; the test missed one or more objectives; or at least one lesson-learned requires a plan update or a training-content update. A single unmet objective or plan-affecting lesson is enough to force this branch.\n\n**Record in AssureSwarm**\n- Create the exercise record as an Audit item (audit_type=readiness; scope, lead_auditor, fieldwork_start/fieldwork_end set) with coach-item-create; relate Audit ↔ anchor Controls UC-IR-01/UC-IR-02 and Audit ↔ participants with coach-items-link.\n- Attach the scenario package, the measurable objectives, and the raw observation timeline as documents on this step with coach-document-upload.\n- Create lesson-learned Issue items with coach-item-create (issue_type=observation/finding, severity, source=self_assessment, root_cause, identified_date); relate each to the readiness Audit item and — for a plan gap — to the anchor Control with coach-items-link; name training-curriculum-mapped gaps in Issue.description (no native curriculum item to link).\n- Attach the after-action report (DOCX/PDF) and the readiness summary with coach-document-upload, and build the IR readiness dashboard with coach-dashboard-create.\n- Submit the `readiness_disposition` SELECT field (ready_no_gaps | gaps_feed_plan_and_training); record the rationale and evidence references in the step result and the decision owner in the native approval record.\n\n**Exit criteria**\n- The test executed as scripted with adequate responder and leadership participation; measurable objectives were defined up front; the observation timeline is captured; the exercise facilitator confirms all of this before the results are documented.\n- Every objective has a met/missed result and each finding is a lesson item linked to the plan section or curriculum it affects, with repeats flagged; the dashboard is built; the `readiness_disposition` routing selector is submitted and the step result contains a rationale and owner; exactly one branch is taken and the unused branch is prunable.","kind":"decision","label":"Classify readiness and route gaps","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-items-link","coach-document-upload","coach-dashboard-create"]}},"id":"classify-readiness-and-route-gaps"},{"data":{"description":"Agent converts each gap into an owned corrective action and routes it to the plan or training program; human confirms every gap is owned and routed","instructions":"**Objective** — Convert each identified exercise and training gap into an owned, dated corrective action routed to either the plan or the training program, closing the loop the readiness program exists to run (UC-IR-01, UC-IR-02).\n\n**Inputs**\n- The readiness summary and the list of gaps with their source lessons/metrics.\n- The lesson-learned items and their plan-section/curriculum links, created with the after-action report at the readiness classification decision.\n\n**Procedure**\n1. Parse the readiness summary to list each gap with its root cause and the lesson or metric that surfaced it.\n2. Create a corrective-action Issue item for each gap with coach-item-create — issue_type=deficiency (or observation), root_cause, issue_owner, target_remediation_date, and remediation_plan carrying the plan-vs-training routing.\n3. Route each corrective action explicitly to one destination: a plan update — queued for the next plan review-and-approval pass, or an off-cycle run if the gap is material enough to warrant one now — or a training-content update, queued for the next training deployment. A gap that touches both gets one action per destination.\n4. Relate each corrective-action Issue to its source lesson Issue and to the anchor Control with coach-items-link so the trail from observation to lesson to action stays intact.\n5. Apply the material-gap threshold: if any gap could leave the organization unable to respond to a live incident, flag it for immediate off-cycle handling rather than next-cycle queuing.\n\n**Record in AssureSwarm**\n- Create corrective-action Issue items with coach-item-create (issue_type=deficiency/observation, issue_owner, target_remediation_date, root_cause, remediation_plan carrying the plan-vs-training routing).\n- Relate each action to its source lesson Issue and to the anchor Control with coach-items-link.\n- Attach the corrective-action register (XLSX) with coach-document-upload.\n\n**Exit criteria** — Every gap has a corrective action with a named owner, a due date, and the correct plan-versus-training destination; material gaps are flagged for off-cycle handling; the IR Program Manager confirms all routing before the cycle closes.","label":"Log corrective actions and feed back","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"log-corrective-actions-and-feed-back"},{"data":{"description":"Automatically archive the authorized cycle record and carry open actions into the next cycle.","instructions":"**Objective** — Automatically preserve the authorized cycle record and its carry-forward actions after the preceding decision.\n\n**Inputs**\n- The full cycle record: the approved IR plan Policy item and its approval evidence, the distribution-and-acknowledgment log, the training-completion register, the exercise after-action report, and — when gaps were found — the corrective-action register (all documents on their originating steps).\n- The readiness disposition from the classification decision (this arrives on the slower stream and gates the join).\n- The IR plan Policy.next_review_date and the standing off-cycle triggers (post-incident, material organizational/system change).\n\n**Procedure**\n1. Confirm both incoming streams have completed — the short distribution stream and the readiness stream — before proceeding; the readiness disposition being recorded is the gate.\n2. Export the full cycle record with coach-workflow-export and archive it in the designated evidence repository under retention controls; confirm the archive is immutable and retrievable.\n3. Carry work forward as native item state: the open corrective-action Issue items stay OPEN with their target_remediation_date intact (Issue state is the carryover between annual cycles — no new items are created for them); confirm the next annual review is set on the IR plan Policy.next_review_date and record the next training and test dates in the closure record.\n4. Update the control execution log with the cycle result, the readiness disposition, and the key metrics.\n5. Confirm the standing post-incident and material-change triggers remain active, so an off-cycle run can start automatically when one fires.\n6. Attach the closure record.\n\n**Record in AssureSwarm**\n- Archive the run as the audit trail: export the full cycle record with coach-workflow-export — the workflow instance, anchored to Control UC-IR-01, is the cycle's record — and store it under retention.\n- Carry forward open corrective-action Issue items as native open item state (target_remediation_date intact); confirm the next annual review on the IR plan Policy.next_review_date; record next training/test dates in the closure record.\n- Attach the closure record with coach-document-upload; update the control execution log.\n\n**Exit criteria** — The archived record is immutable and retrievable; the next annual review and any off-cycle triggers are scheduled and active; every open item has a tracked owner; the authorized cycle record is complete.","label":"Close and archive","performedBy":{"primitives":["coach-workflow-export","coach-item-create","coach-items-link","coach-document-upload"]},"requiredApprovals":0},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:controls-incident-response-readiness-program"}
