{"description":"Standing operator workflow for the CISO's quarterly information security program governance review and its annual leg. Each cycle runs as one workflow instance attached to the existing \"Information Security Program Governance\" Process item (process_type: security_process, owner CISO), with the four governing Control items UC-GOV-06/09/10/15 linked to it. It is a decision-aware flow that enriches — never recreates — the senior-management-approved information security program plan (held as a Policy item) and the current role assignments every cycle, and branches into the written board report, workforce competency review, and plan reapproval when the annual interval or a significant change requires it. Named deliverables: the reapproved information security program plan (the Policy item, re-versioned and re-signed), the roles-and-authorities register, the annual written board report to the governing body, and the workforce competency review — each retained on the workflow instance. In scope: the program plan, security roles/authorities/reporting lines, the annual board report, and workforce competency for this organization; out of scope: executing the underlying protective controls and enterprise ERM governance, which are owned by their own workflows (coso-erm is referenced here only for oversight-of-design of the governance structure). There is no upstream or downstream workflow handoff — this cycle is genuinely self-contained: it starts from its own cadence trigger, consumes its own prior-cycle governance record, and seeds the next cycle at close.","edges":[{"id":"e-classify-cycle-scope-assess-governance-readiness","label":"Routine quarterly","source":"classify-cycle-scope","target":"assess-governance-readiness","whenValue":"routine_quarterly"},{"id":"e-classify-cycle-scope-deliver-board-report-and-confirm-mandate","label":"Annual","source":"classify-cycle-scope","target":"deliver-board-report-and-confirm-mandate","whenValue":"annual_review"},{"id":"e-classify-cycle-scope-update-and-reapprove-program-plan","label":"Significant change","source":"classify-cycle-scope","target":"update-and-reapprove-program-plan","whenValue":"significant_change"},{"id":"e-deliver-board-report-and-confirm-mandate-update-and-reapprove-program-plan","source":"deliver-board-report-and-confirm-mandate","target":"update-and-reapprove-program-plan"},{"id":"e-update-and-reapprove-program-plan-assess-governance-readiness","source":"update-and-reapprove-program-plan","target":"assess-governance-readiness"},{"id":"e-assess-governance-readiness-log-corrective-actions","label":"Gaps","source":"assess-governance-readiness","target":"log-corrective-actions","whenValue":"gaps_identified"},{"id":"e-assess-governance-readiness-close-and-archive","label":"Healthy","source":"assess-governance-readiness","target":"close-and-archive","whenValue":"healthy"},{"id":"e-log-corrective-actions-close-and-archive","source":"log-corrective-actions","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-GOV-06","UC-GOV-09","UC-GOV-10","UC-GOV-15"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-information-security-program-governance-review","contentDigest":"sha256:7bfa6143ae99e0af99e205c327c02861bf5a3a398c178c92b28e94cdf2ce5f82","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:7bfa6143ae99e0af99e205c327c02861bf5a3a398c178c92b28e94cdf2ce5f82","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-information-security-program-governance-review"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-information-security-program-governance-review","source":"coworkcanvas-gallery","standards":["nist-800-53","nydfs-500","coso-ic","coso-erm"],"teams":["it","executive"]},"name":"Information Security Program Governance Review","nodes":[{"data":{"decisionField":"cycle_disposition","description":"Judge plan currency and current role authority against risk and organizational change, then select quarterly, annual or significant-change scope.","formData":{"fields":[{"key":"cycle_disposition","label":"Cycle Disposition","options":[{"label":"Routine quarterly maintenance","value":"routine_quarterly"},{"label":"Annual review with board report and reapproval","value":"annual_review"},{"label":"Significant-change plan update and reapproval","value":"significant_change"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Judge plan currency and current role authority against risk and organizational change, then select quarterly, annual or significant-change scope.\n\n**Inputs**\n- The current information security program plan, held as a Policy item (policy_type: charter, policy_owner: CISO, approved_by, version, effective_date, next_review_date, review_frequency, framework containing nist-800-53 | nydfs-500, domains: governance_policy_oversight) — the plan document attaches to that Policy item and its fields carry the queryable senior-management approval state.\n- The latest enterprise risk assessment the program is aligned to — the enterprise risk register, held as Risk items (category, inherent_rating, residual_rating, treatment, risk_owner); the assessment narrative, if a file, is an upload on this step.\n- The significant-change register since the last cycle — a PBC upload on this step (CSV/XLSX); there is no native Change item type, so it lives as a step document.\n- The prior-cycle governance record (the prior workflow instance on the anchor Process) and the cadence calendar. These are this workflow's own initial inputs; no upstream workflow feeds this step.\n- Documented security, risk-management, and internal-control roles, responsibilities, authorities, reporting lines, and organizational structures — a PBC upload on this step (roles-and-authorities register XLSX); there is no native Role/RACI item type, so the register lives as a step document.\n- The current organization chart and the personnel- and role-change log since the last cycle — PBC uploads on this step (org chart + HR change log). These are this workflow's initial inputs, not another step's output.\n- The four governing Control items UC-GOV-06/09/10/15 (existing) in the control library, so each obligation traces to its control.\n\n**Procedure**\n_This checkpoint absorbs “Review program plan currency”, “Reconcile roles, authorities, and reporting lines”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Review program plan currency: Pull the program plan's Policy item and its approval fields with coach-query-data, and link the plan document to this cycle instance with coach-document-link so the review is traceable.\n2. Retrieve the latest enterprise risk assessment and the significant-change register the program must stay aligned to.\n3. Check each program element against current state: (a) scope, (b) security objectives, (c) the five protective functions — identify, protect, detect, respond, recover, (d) supporting management processes, and (e) coordination among organizational entities. Flag every element that has drifted from the risk assessment or a logged significant change.\n4. For each drifted element draft a redline stating the change, the reason, and the risk-assessment basis; mark whether the drift is material enough to require senior-management reapproval (material = a change to scope, objectives, or a protective function; immaterial = editorial or contact updates).\n5. Compile the plan-currency assessment listing every element, its status (current / drifted), the redline, and the reapproval flag.\n6. Reconcile roles, authorities, and reporting lines: Pull the four UC-GOV Control items with coach-query-data, alongside the uploaded roles-and-authorities register, the live org chart, and the change log.\n7. Reconcile documented ownership against the live organization. Flag every security obligation that is now orphaned (owner departed), duplicated (two owners), held by a reassigned individual, or lacking a defined authority.\n8. Draft the RACI and reporting-line updates that restore a single, current, authorized owner for each obligation, including the board/committee oversight note on the design of the structure.\n9. Record each reconciled change as a row in the roles-and-authorities register (no native Role type). Where an obligation is left orphaned, duplicated, or without a defined authority, create an Issue with coach-item-create (issue_type: observation, source: self_assessment, issue_owner) and link it to the affected UC-GOV Control item with coach-items-link so the gap is tracked.\n10. Compile the updated roles-and-authorities register.\n\n**Decision criteria**\n- `routine_quarterly` — Routine quarterly maintenance only. Pick when the plan-currency assessment shows the plan is current and management-approved, roles remain current, and no annual board-report/workforce-review interval and no significant change is due. No plan reapproval is required.\n- `annual_review` — Annual review with board report and reapproval. Pick when the annual interval for the written board report and the workforce competency review is due (NYDFS 500.04 annual reporting; NIST 800-53 PM-1 annual plan review). This leg also updates and reapproves the plan.\n- `significant_change` — Significant-change plan update and reapproval. Pick when the plan-currency assessment or the significant-change register shows a change to the enterprise, its risk profile, or its structure forces an off-cycle plan update and senior-management reapproval, without the full annual leg (no board report or workforce review due).\n\n**Record in AssureSwarm**\n- Item relationship / query — pull the program plan's Policy item and link its plan document to this cycle instance (coach-query-data, coach-document-link).\n- Step document — attach the plan-currency assessment with the redline table and per-element reapproval flags as an XLSX/DOCX on this step (coach-document-upload). The redlines stay a step document here; the Policy item's fields are only re-versioned later, at update-and-reapprove-program-plan.\n- Step document — attach the updated roles-and-authorities register with the board-oversight note as an XLSX on this step; there is no native Role/RACI item type, so the register and its per-change rows live as this document (coach-document-upload).\n- Item create + relationship — for each obligation left orphaned, duplicated, or unauthorized, create an Issue (issue_type: observation, source: self_assessment, issue_owner) and link it to the affected UC-GOV Control item (coach-item-create, coach-items-link; Issue ↔ Control).\nSubmit the `cycle_disposition` SELECT. Record the driving evidence (interval dates, change-register entries, drifted plan elements) in the step result and the approver in the step's approver record. Compile the drivers with coach-query-data and attach the cycle-scope recommendation with coach-document-upload.\n\n**Exit criteria**\n- Every program element is marked current or drifted with a documented basis; each drifted element carries a redline and a reapproval flag; the CISO has confirmed whether the plan still reflects current scope, objectives, protective functions, and risk assessment.\n- Every security obligation maps to exactly one current, authorized owner; reporting lines and board oversight of the design are documented; the CISO has confirmed the register is ready to communicate.\n- The form is submitted with one disposition and a documented rationale; the two unused branches are prunable.","kind":"decision","label":"Classify cycle scope","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-item-create","coach-items-link"]}},"id":"classify-cycle-scope"},{"data":{"description":"Judge risk-driven workforce competence and succession, report material cyber risk and remediation to the board, and confirm mandate and resources.","instructions":"**Objective** — Judge risk-driven workforce competence and succession, report material cyber risk and remediation to the board, and confirm mandate and resources.\n\n**Inputs**\n- The defined security competencies and current staffing against required roles — a PBC upload on this step (competency framework + staffing roster); there is no native Role/Position item type, so the roster lives as a step document.\n- The current threat landscape and the organization's risk-driven staffing need.\n- Prior workforce-review results and any open training/succession Issue items.\n- The plan-currency assessment (step document from classify-cycle-scope) and the enterprise risk register — Risk items (category, inherent_rating, residual_rating, risk_owner) — for the state of the program and material risks.\n- The remediation plans and their status — Issue items (remediation_plan, issue_owner, target_remediation_date, status); the board-reporting calendar and the governing body of record.\n- The current CISO designation, budget, and staffing-authority record — a PBC upload on this step (annual leg only).\n\n**Procedure**\n_This checkpoint absorbs “Run workforce competency review”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Run workforce competency review: Pull the defined competencies, current staffing, and threat landscape with coach-query-data; compare qualified headcount to the organization's risk-driven need.\n2. Evaluate each key role’s competencies against the framework and available training, performance and assessment evidence; request only genuinely missing competency evidence from the named role holder; identify competency gaps, single points of failure, and roles without a successor.\n3. Create a training, development, hiring, or succession-planning action for each gap as an Issue with coach-item-create (issue_type: opportunity, source: self_assessment, issue_owner, target_remediation_date) and link each to the UC-GOV-10 Control item and the anchor Process with coach-items-link, since roles are not items.\n4. Verify that key security personnel maintain current knowledge of evolving threats and countermeasures, tracking completion with coach-workflow-scan.\n5. Compile the workforce-review summary with the competency and succession evidence.\n6. Deliver board report and confirm mandate: Compile the report content with coach-query-data: the state of the information security program, the material cybersecurity risks (Risk items), and the remediation plans and their status (Issue items).\n7. Draft the written board report covering program, material cyber risks, and remediation as a step document; record the board-submission metadata — governing body, delivery date, reporting owner — in the report cover, since there is no native Report/board-submission item type.\n8. Confirm the CISO designation and that the senior leader holds organization-wide responsibility, accountability, authority, and the resources (budget and staffing) to develop, implement, and enforce the program, and that accountable leadership for the risk-management program is designated.\n9. Record any mandate, authority, or resource gap as an Issue with coach-item-create (issue_type: deficiency, source: self_assessment, severity: high, issue_owner: accountable executive) and link it to the anchor Process with coach-items-link for escalation.\n\n**Record in AssureSwarm**\n- Step result — record the competency assessment and evidence; request only missing evidence from the named role holder.\n- Item create + relationship — create each training/development/hiring/succession action as an Issue (issue_type: opportunity, source: self_assessment, issue_owner, target_remediation_date) linked to the UC-GOV-10 Control item and the anchor Process (coach-item-create, coach-items-link; Issue ↔ Control).\n- Step document — attach the workforce-review summary and competency/succession evidence (XLSX/DOCX) on this step; the staffing roster has no native Role item, so it lives here (coach-document-upload).\n- Step document — attach the written board report (DOCX/PDF) and the mandate-and-resources confirmation memo on this step; the board-submission metadata (governing body, delivery date, owner) lives in the report cover, as there is no native Report item type (coach-document-upload).\n- Item create + relationship — record any mandate, authority, or resource gap as an Issue (issue_type: deficiency, source: self_assessment, severity: high, issue_owner: accountable executive) linked to the anchor Process (coach-item-create, coach-items-link; Issue ↔ Process).\n\n**Exit criteria**\n- Competencies were evaluated for every key role; each gap has an owned training, development, or succession action; key security personnel are verified current on evolving threats.\n- The written report is complete and accurate, scheduled for delivery to the governing body at least annually; the CISO mandate, authority, and resources are confirmed or the gap is escalated to the accountable executive.","label":"Deliver board report and confirm mandate","performedBy":{"primitives":["coach-query-data","coach-form-create","coach-item-create","coach-items-link","coach-workflow-scan","coach-document-upload"]}},"id":"deliver-board-report-and-confirm-mandate"},{"data":{"description":"Agent applies the redlines and annual-leg outputs to the program plan and routes it for senior-management reapproval; human confirms the plan is updated and carries a current approval","instructions":"**Objective** — Apply the required updates to the program plan and obtain senior-management reapproval so the program stays authoritative and management-approved (UC-GOV-15).\n\n**Inputs**\n- The plan-currency redlines (step document from classify-cycle-scope) and the significant-change register entries.\n- Where the annual leg ran: the board-report remediation commitments and the workforce actions — the Issue items created on those steps.\n- The program plan's Policy item and the senior-management approval authority and sign-off record.\n\n**Procedure**\n1. Apply the redlines from the plan-currency assessment and the significant-change register to the plan document — scope, objectives, protective functions, supporting processes, and coordination among entities — drawing the source items with coach-query-data. The plan is an existing Policy item; enrich it in place with coach-item-update — do not create a duplicate. (Where a tenant versions plans as discrete records, mint the successor Policy version with coach-item-create and link it to the prior with coach-items-link.)\n2. Where an annual leg ran, fold in the board-report remediation commitments and the workforce actions, linking each such Issue to the plan's Policy item with coach-items-link.\n3. Route the revised plan for senior-management reapproval; with coach-item-update bump the Policy item's version and record the reapproval in its approved_by, effective_date, and next_review_date fields so approval state stays queryable.\n4. Compile the reapproved plan and the approval record.\n\n**Record in AssureSwarm**\n- Item field update — enrich the existing program-plan Policy item: bump version and set the reapproval fields (coach-item-update; Policy.version, Policy.approved_by, Policy.effective_date, Policy.next_review_date, Policy.review_frequency). Where plans are versioned as discrete records, create the successor Policy version instead (coach-item-create).\n- Item relationship — link the folded-in board-report and workforce Issue items to the Policy item (coach-items-link; Issue ↔ Policy).\n- Step document — attach the reapproved program plan (DOCX/PDF) and the approval record to the Policy item / this step (coach-document-upload).\n\n**Exit criteria** — The plan reflects all required updates and its Policy item carries a current, dated senior-management approval (approved_by, effective_date); the Policy item links every folded-in commitment.","label":"Update and reapprove program plan","performedBy":{"primitives":["coach-query-data","coach-item-update","coach-item-create","coach-items-link","coach-document-upload"]}},"id":"update-and-reapprove-program-plan"},{"data":{"decisionField":"readiness_disposition","description":"Agent communicates the updated role assignments for acknowledgment, verifies they are exercised in the operating workflows, and computes governance-health metrics and a dashboard; the CISO classifies the cycle as healthy or gaps-identified","formData":{"fields":[{"key":"readiness_disposition","label":"Readiness Disposition","options":[{"label":"Healthy, within tolerance","value":"healthy"},{"label":"Gaps identified","value":"gaps_identified"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Communicate and enforce the reviewed role and authority assignments (UC-GOV-06), then judge whether program governance operated within tolerance this cycle or carries gaps that need tracked action, so only the relevant closure path continues; the disposition is owned by the CISO.\n\n**Inputs**\n- The updated roles-and-authorities register (step document) and the per-change rows and Issue items raised at the classify-cycle-scope step.\n- The operating workflows and control assignments where the obligations are exercised.\n- This cycle's other outputs where the branch ran: the plan's Policy item with its version and senior-management approval status, the board-report delivery record, and the workforce competency and succession Issues.\n\n**Procedure**\n_Items 1–5 are agent-run (folded from the former \"Communicate and enforce assignments\" step); the human moment is the CISO's disposition call below._\n1. Communicate each assignment to the affected role owner and team, stating the responsibility, authority and reporting line. Record their acceptance through native acknowledgement or approval in the existing assignment record.\n2. Record the acknowledgment log as a step document — who acknowledged, when, and which obligations they accepted.\n3. Verify enforcement by scanning the operating workflows and control assignments with coach-workflow-scan to confirm the named owners are performing the obligations; list any assignment that is communicated but not yet exercised in practice.\n4. For each communicated-but-unexercised assignment, create an Issue with coach-item-create (issue_type: observation, source: self_assessment, issue_owner) and link it to the affected UC-GOV Control item with coach-items-link so the enforcement gap is tracked with a follow-up owner.\n5. Compile the communication-and-enforcement log covering who acknowledged, when, and which obligations are confirmed active, then compute the cycle metrics with coach-query-data (plan currency and senior-management approval status from the plan's Policy item, orphaned or unacknowledged role assignments, board-report delivery status, workforce competency and succession gaps from the open Issue items, and any confirmed mandate/authority/resource gap) and build the \"InfoSec Program Governance Health\" dashboard with coach-dashboard-create showing each metric against its threshold and the trend against prior cycles.\n\n**Decision criteria**\n- `healthy` — Within tolerance. Pick when the plan is current and management-approved, every role obligation is owned, acknowledged and enforced in practice (no orphaned, unacknowledged or communicated-but-unexercised assignments), any due board report was delivered, no competency or succession gap is open, and no mandate/authority/resource gap exists.\n- `gaps_identified` — Pick when any metric breaches its threshold: a stale or unapproved plan, an unowned, unacknowledged or unexercised obligation, an undelivered board report, an open competency or succession gap, or a confirmed mandate/authority/resource shortfall.\n\n**Record in AssureSwarm**\n- Assignment record — retain native acknowledgement of each responsibility, authority and reporting line.\n- Step documents — the communication-and-enforcement (acknowledgment) log as an XLSX (acknowledgments have no native Role item, so the log lives here) and the readiness summary (coach-document-upload).\n- Item create + relationship — for each assignment communicated but not exercised, an Issue linked to the affected UC-GOV Control item (coach-item-create, coach-items-link; Issue ↔ Control).\n- Dashboard — the \"InfoSec Program Governance Health\" dashboard with each metric against its threshold and the prior-cycle trend (coach-dashboard-create).\n- Submit the `readiness_disposition` SELECT; record which metrics breached and their evidence in the step result, and the approver in the step's approver record.\n\n**Exit criteria** — Every updated assignment was communicated and acknowledged, enforcement is verified in the operating workflows, and any communicated-but-unexercised assignment is listed with a follow-up owner; the dashboard shows each metric against its threshold; the form is submitted with a documented rationale by the CISO, whose disposition confirms ownership is real in practice; the unused branch is prunable.","kind":"decision","label":"Assess governance readiness","performedBy":{"primitives":["coach-query-data","coach-dashboard-create","coach-document-upload","coach-form-create","coach-item-create","coach-items-link","coach-workflow-scan"]}},"id":"assess-governance-readiness"},{"data":{"description":"Agent converts each identified gap into an owned corrective action; human confirms every gap is owned, dated, and escalated where required","instructions":"**Objective** — Convert every gap identified at the readiness review into an owned, tracked, dated corrective action so nothing degrades program governance unaddressed.\n\n**Inputs**\n- The readiness summary and the governance-health dashboard listing each breached metric.\n- The role, plan element, or review that surfaced each gap.\n\n**Procedure**\n1. Parse the readiness summary to list each gap with its root cause and the metric or review that surfaced it.\n2. Create a corrective-action Issue for each gap with coach-item-create (issue_type: deficiency or observation, source: self_assessment, root_cause, issue_owner, target_remediation_date) capturing interim mitigation; link it to the anchor Process and the UC-GOV Control item it traces to with coach-items-link.\n3. Raise program-level improvement Issues for systemic gaps — a chronic resource shortfall, an unstaffed key security role, or a repeatedly stale plan.\n4. Escalate any mandate, authority, or board-reporting breach to the accountable executive.\n5. Compile the corrective-action register.\n\n**Record in AssureSwarm**\n- Item create + relationship — create one corrective-action Issue per gap (issue_type: deficiency or observation, source: self_assessment, root_cause, issue_owner, target_remediation_date) linked to the anchor Process and the relevant UC-GOV Control item (coach-item-create, coach-items-link; Issue ↔ Process, Issue ↔ Control).\n- Step document — attach the corrective-action register (XLSX) on this step (coach-document-upload).\n\n**Exit criteria** — Every gap has a named owner and due date; systemic gaps have program-level items; escalations are routed; nothing is left untracked.","label":"Log corrective actions","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"log-corrective-actions"},{"data":{"description":"Automatically archive the authorized cycle record and carry open actions into the next cycle.","instructions":"**Objective** — Automatically preserve the authorized cycle record and its carry-forward actions after the preceding decision.\n\n**Inputs**\n- The full governance record for this cycle: the plan-currency assessment, the roles-and-authorities register, the communication-and-enforcement log, any board report, workforce review, and plan reapproval, the readiness summary, and the corrective-action register.\n- The cadence calendar for the next quarterly and annual reviews.\n\n**Procedure**\n1. Export the full governance record with coach-workflow-export and archive it in the designated evidence repository under retention controls; record the archive location and reference.\n2. Create carry-forward items with coach-item-create for open corrective actions, the next quarterly review, the next annual board report and workforce review, and any outstanding reapproval; link them to their source with coach-items-link so they arrive as explicit inputs to the next cycle.\n3. Update the control execution log with the cycle result and key metrics; confirm the next cadence review is scheduled.\n4. Compile the closure record.\n\n**Record in AssureSwarm**\n- Workflow instance — export the full governance record with coach-workflow-export; this run on the anchor Process is the archived audit trail.\n- Item create + relationship — create carry-forward Issue items (open corrective actions, outstanding reapproval, next quarterly/annual review reminders) linked to the anchor Process so the next instance consumes them (coach-item-create, coach-items-link; Issue ↔ Process).\n- Step document — attach the closure record and the export bundle on this step (coach-document-upload).\n\n**Exit criteria** — The archived record is immutable and retrievable under retention; the next quarterly and annual reviews are scheduled; nothing remains open without a tracked owner; the authorized cycle record is complete.","label":"Close and archive","performedBy":{"primitives":["coach-workflow-export","coach-item-create","coach-items-link","coach-document-upload"]},"requiredApprovals":0},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:controls-information-security-program-governance-review"}
