{"description":"Standing operator workflow for the monthly physical-environment monitoring review across facilities hosting systems and data — badge and entry logs, camera surveillance coverage and footage, and environmental sensor alerts. Each cycle runs as a recurring workflow instance attached to the existing UC-LOG-10 Control item (control_type=detective, control_category=physical, frequency=monthly, framework=nist-csf-2, domains include physical_environmental_security and logging_monitoring_detection) — it enriches that Control's execution history and never creates a duplicate control. In scope: physical-access, surveillance, and environmental monitoring of the in-scope facilities and the systems and data they host. Out of scope: logical-access review and the downstream analysis and remediation of confirmed events, which are handed off to the security-event analysis workflow. Runs on a routine monthly cadence (or out-of-cycle after a triggering incident) with no upstream workflow feeding it — it originates from the anchor Control, its prior-cycle instance, and the prior cycle's still-open Issue items. Consolidates findings into a de-duplicated physical-event register, packages every confirmed adverse physical event as a security-event case handed off to the security-event analysis workflow, and tracks monitoring coverage gaps to closure as owned corrective-action Issues. Implements NIST CSF 2.0 continuous detection monitoring (control UC-LOG-10).","edges":[{"id":"e-review-camera-surveillance-coverage-triage-physical-anomalies","source":"review-camera-surveillance-coverage","target":"triage-physical-anomalies"},{"id":"e-review-camera-surveillance-coverage-assess-monitoring-coverage-gaps","source":"review-camera-surveillance-coverage","target":"assess-monitoring-coverage-gaps"},{"id":"e-triage-physical-anomalies-feed-anomalies-to-security-event-analysis","label":"Confirmed","source":"triage-physical-anomalies","target":"feed-anomalies-to-security-event-analysis","whenValue":"anomalies_confirmed"},{"id":"e-triage-physical-anomalies-close-and-archive","label":"No anomalies","source":"triage-physical-anomalies","target":"close-and-archive","whenValue":"no_anomalies_confirmed"},{"id":"e-feed-anomalies-to-security-event-analysis-close-and-archive","source":"feed-anomalies-to-security-event-analysis","target":"close-and-archive"},{"id":"e-assess-monitoring-coverage-gaps-log-corrective-actions","label":"Gaps","source":"assess-monitoring-coverage-gaps","target":"log-corrective-actions","whenValue":"coverage_gaps_identified"},{"id":"e-assess-monitoring-coverage-gaps-close-and-archive","label":"Adequate","source":"assess-monitoring-coverage-gaps","target":"close-and-archive","whenValue":"coverage_adequate"},{"id":"e-log-corrective-actions-close-and-archive","source":"log-corrective-actions","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-LOG-10"],"department":"facilities","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-physical-environment-monitoring-review","contentDigest":"sha256:4b89a8b465f2b6a9ee4a463d60e2f2df35290fe8f9422bf73f3bb5d3f69e4b29","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:4b89a8b465f2b6a9ee4a463d60e2f2df35290fe8f9422bf73f3bb5d3f69e4b29","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-physical-environment-monitoring-review"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-physical-environment-monitoring-review","source":"coworkcanvas-gallery","standards":["nist-csf-2"],"teams":["facilities"]},"name":"Physical Environment Monitoring Review","nodes":[{"data":{"description":"Judge corroborated badge/footage anomalies, environmental breaches, false positives and coverage blind spots from one physical-monitoring package.","instructions":"**Objective** — Judge corroborated badge/footage anomalies, environmental breaches, false positives and coverage blind spots from one physical-monitoring package.\n\n**Inputs**\n- The anchor Control item (existing) — the UC-LOG-10 physical-environment monitoring control (Control.control_id, Control.description, Control.framework=nist-csf-2, Control.control_type=detective, Control.control_category=physical, Control.frequency=monthly, Control.control_owner = the accountable physical security manager). This workflow has no upstream workflow — the cycle instance originates from this Control.\n- Cycle scope and trigger: the in-scope facility inventory and the systems and data each facility hosts (facility inventory document attached to the prior cycle's closure record and re-referenced here — there is no native Facility/Asset item type, so it lives as a document), plus the review trigger (routine monthly, or an out-of-cycle trigger such as an alert backlog or a specific incident, noted on this workflow instance).\n- The prior-cycle review record (the prior workflow instance archived at its close-and-archive, attached to the same anchor Control) and any carried-forward corrective actions or unresolved anomalies (open Issue items from the prior cycle, linked to the anchor Control).\n- Badge and access-control system export: every entry event for each in-scope facility across the full cycle period, with badge holder, timestamp, door or zone, and access level — a PBC upload at this step (CSV/XLSX from the badge system).\n- The current approved-access roster: active employees and contractors with their assigned access levels, plus terminated or transferred staff whose badges should already be deactivated — a PBC upload at this step; the source of truth is the external HR/badge system and the AssureSwarm copy is evidence.\n- The required camera coverage map per facility and zone, and the camera health and uptime log for the cycle — both PBC uploads at this step (there is no native asset/coverage item type).\n- Any period already flagged for footage review by a standing security request or a prior-cycle sensor alert — open Issue items (issue_type=exception) carried from the prior cycle and linked to the anchor Control.\n- Cycle scope: the in-scope facilities and the systems and data each hosts (facility inventory document referenced from the prior cycle's closure record — no native Facility/Asset item type). This node is a parallel intake off the anchor Control; no upstream workflow feeds it.\n- Environmental sensor telemetry and threshold-breach alerts for the cycle covering temperature, humidity, water-leak, smoke-and-fire, and power sensors, each sensor's heartbeat and health status across the period, and the defined alert thresholds per sensor type and facility — all PBC uploads at this step.\n\n**Procedure**\n_This checkpoint absorbs “Review environmental sensor alerts”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Review camera surveillance coverage and footage: Produce the cycle's reviewed physical-access picture for every in-scope facility: the anomaly list drawn from badge and entry logs, the camera coverage assessment against the required map, and the footage finding for every flagged period, so unauthorized, out-of-schedule, or stale-badge entries are corroborated by visual evidence and any coverage blind spot is caught.\n2. Pull badge and entry logs for every in-scope facility for the full cycle period; confirm there is no gap in the log stream — a missing day or a missing facility voids coverage, so reconcile with the badge-system owner before proceeding.\n3. Pull the current approved-access roster and each holder's access-level assignment.\n4. Cross-reference each entry against the roster and its access level, flagging: after-hours entries outside approved schedules; entries by badges belonging to terminated or transferred personnel; access-level mismatches (entry into a zone the holder is not authorized for); and repeated failed-badge or tailgating flags at a single door.\n5. For each flagged entry, capture facility, badge holder, timestamp, door or zone, and the specific flag reason; distinguish clearly explained entries (for example approved after-hours maintenance) from genuinely unexplained ones.\n6. Assemble the badge and entry log review with the full anomaly list and the coverage confirmation.\n7. Compare the camera health and uptime log against the required coverage map for each facility and zone; identify every camera outage, obstruction, or persistent blind spot against what the map requires.\n8. Compile the set of periods requiring footage review: every badge anomaly timestamp from items 4–5, plus any period already flagged by a standing security request or a prior-cycle sensor alert.\n9. Review footage for each flagged period and record whether it corroborates, explains, or contradicts the driving flag — for example a badge after-hours flag resolved by footage showing an authorized escort, versus one showing an unaccompanied unknown person. Reference the relevant footage segments by link rather than duplicating raw video into the record.\n10. Assemble the coverage assessment and footage-review log alongside the badge review.\n11. Physical security manager: judge whether each flagged entry is genuinely anomalous or explained by the footage, and whether the coverage assessment is sound, before consolidation and coverage scoring in the following decision checkpoints.\n12. Review environmental sensor alerts: Produce a reviewed list of confirmed environmental threshold breaches and sensor outages across all in-scope facilities, so environmental threats to hosted systems are caught on cadence rather than after damage.\n13. Pull sensor telemetry and threshold-breach alerts for the full cycle across every in-scope facility.\n14. Pull each sensor's heartbeat and health status; flag any sensor that went offline or missed heartbeats — a silent sensor is itself a finding, not a clean reading.\n15. For each threshold breach, use surrounding readings to distinguish a confirmed environmental event from a likely false positive — for example a single-sample humidity spike that immediately recovers versus a sustained temperature climb in a room hosting production systems.\n16. Capture facility, sensor, reading, threshold, and duration for each confirmed breach or sensor outage.\n17. Assemble the sensor alert review with the confirmed alert list and the offline-sensor list.\n\n**Record in AssureSwarm**\n- Create an Issue for each flagged entry — `issue_type: exception`, `source: management_identified`, `severity` set to the flag's seriousness, `identified_date` = the review date; put facility, badge holder, timestamp, door/zone, and the specific flag reason in `Issue.description` (there is no Facility/Asset or Employee item type, so the facility and badge-holder identity live in the description text, not a relationship). Link each badge-anomaly Issue to the anchor Control (Issue ↔ Control) so the anomaly is queryable per control.\n- Create an Issue for each camera outage or blind spot — `issue_type: exception`, `source: management_identified`, `severity`, `identified_date`, with the affected facility/zone and the gap against the required map in `Issue.description`; link each to the anchor Control (Issue ↔ Control).\n- Create an Issue for each flagged period whose footage was reviewed — `issue_type: observation`, with the driving flag and the corroborate/explain/contradict finding in `Issue.description` — and link it to the badge-anomaly Issue it corroborates (Issue ↔ Issue).\n- Link (not upload) the reviewed footage segments to their footage-review Issue as URL references — footage stays in the external video management system by design; AssureSwarm holds links only.\n- Upload the badge and entry log review and the coverage assessment and footage-review log (XLSX/PDF) to this step.\n- Create an Issue for each confirmed breach or sensor outage — `issue_type: exception`, `source: management_identified`, `severity`, `identified_date`, with facility, sensor, reading, threshold, and duration in `Issue.description` (no Facility/Asset item type, so the affected facility and hosted system are named in the description text rather than a relationship).\n- Link each sensor-anomaly Issue to the anchor Control (Issue ↔ Control).\n- Upload the sensor alert review document (XLSX/PDF) to this step.\n\n**Exit criteria**\n- Logs pulled for every in-scope facility with no gap across the cycle period, and every flagged entry carrying a facility, badge holder, timestamp, and flag reason; coverage assessed for every in-scope facility with every gap documented; footage reviewed for every flagged period with a recorded finding; the physical security manager has ruled on which flags remain anomalous before consolidation and coverage scoring.\n- Telemetry reviewed for every in-scope facility; offline or silent sensors identified; each retained alert distinguished as confirmed versus false positive; the physical security manager has confirmed the alert list before consolidation and coverage scoring.","label":"Review camera surveillance coverage and footage","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-item-create","coach-items-link"]}},"id":"review-camera-surveillance-coverage"},{"data":{"decisionField":"anomaly_disposition","description":"Agent merges the badge, camera, and sensor findings into one severity-ranked register and correlates related flags to the same physical event; human decides whether confirmed anomalies must be escalated to security-event analysis","formData":{"fields":[{"key":"anomaly_disposition","label":"Anomaly Disposition","options":[{"label":"No anomalies confirmed, routine close","value":"no_anomalies_confirmed"},{"label":"Anomalies confirmed, escalate","value":"anomalies_confirmed"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Merge the badge, camera, and sensor findings into one de-duplicated, severity-ranked register, then resolve whether this cycle's events are routine and closeable at the physical-security level or whether one or more confirmed adverse physical events must be fed into security-event analysis. Owned by the physical security manager.\n\n**Inputs**\n- This cycle's badge-anomaly Issues, camera coverage-gap and footage-review Issues, and environmental sensor-anomaly Issues (all linked to the anchor Control) — both review streams must be signed off before consolidation.\n- The prior-cycle consolidated register (the prior cycle's consolidated-event Issues) and prior-cycle dispositions, for severity precedent.\n- The set of open workflows, to check whether a correlated event is already an active security-event case.\n\n**Procedure**\n_Items 1–7 are agent-run (items 1–5 folded from the former \"Consolidate and correlate anomalies\" step); the human moment is the disposition call in item 8._\n1. Gather every anomaly, coverage-gap, and footage-review item created this cycle across the three review streams.\n2. Correlate items that describe the same physical event by facility, time window, and location — for example a badge after-hours flag, the footage that corroborates it, and a coincident temperature breach in the same room together form one event.\n3. Link the correlated items together so the group reads as one event with multiple evidence sources.\n4. Rank each consolidated event by severity, weighted by the systems and data the facility hosts and the nature of the flag — a confirmed unauthorized entry into a room hosting production data outranks an explained after-hours cleaning entry.\n5. Confirm nothing is dropped: every raw finding either maps into a correlated event or stands as its own single-source event.\n6. Scan open workflows to check whether any correlated event is already an active security-event case, so no duplicate hand-off is raised.\n7. Review prior-cycle dispositions for severity precedent and draft the triage recommendation with its supporting evidence references.\n8. Pick the disposition against the criteria below and submit the SELECT.\n\n**Decision criteria**\n- Choose **anomalies_confirmed** (\"Anomalies confirmed, escalate\") when one or more consolidated events is a confirmed adverse physical event: confirmed unauthorized access, a confirmed environmental threat to a hosted system, or a corroborated multi-source flag that cannot be explained away.\n- Choose **no_anomalies_confirmed** (\"No anomalies confirmed, routine close\") when every flag this cycle is routine, explained, or already mitigated, with nothing meeting the escalation bar.\n\n**Record in AssureSwarm**\n- Create an Issue for each correlated physical event — `issue_type: exception`, `severity` set to the event's consolidated rank (the severity index carries the ranking), with the event summary and its evidence sources in `Issue.description`; link each to the anchor Control (Issue ↔ Control).\n- Link each consolidated-event Issue to its constituent badge-anomaly, footage-review, and sensor-anomaly Issues (Issue ↔ Issue) so the group reads as one event with multiple evidence sources.\n- Submit the `anomaly_disposition` SELECT field with the chosen branch; record the decision rationale with evidence references in the step result, and the decision owner in the step's approver record.\n- Upload the consolidated findings register (XLSX) and the triage recommendation with its supporting evidence references to this step.\n\n**Exit criteria** — Every raw finding is accounted for in the register (correlated or standalone) and each event is severity-ranked with nothing dropped or miscorrelated; the `anomaly_disposition` routing selector is submitted and the step result contains a rationale and owner recorded; the unused branch is prunable; on anomalies_confirmed the confirmed events are ready to package for hand-off, and on no_anomalies_confirmed the cycle proceeds straight to closure.","kind":"decision","label":"Triage physical anomalies","performedBy":{"primitives":["coach-query-data","coach-workflow-scan","coach-document-upload","coach-items-link","coach-item-create"]}},"id":"triage-physical-anomalies"},{"data":{"description":"Agent packages each confirmed anomaly with its corroborating evidence into a security-event case and hands it to security-event analysis; human confirms every confirmed anomaly was received and acknowledged","instructions":"**Objective** — Route every confirmed adverse physical event, with its full corroborating evidence, into the security-event analysis workflow, so analysis and remediation happen there rather than being resolved inside this monitoring review.\n\n**Inputs**\n- The consolidated-event Issues covered by the anomalies_confirmed disposition at triage, each with its linked badge-anomaly, footage-review, and sensor-anomaly evidence Issues.\n- The set of open security-event analysis workflow instances, to route each case correctly.\n\n**Procedure**\n1. For each confirmed event, package the badge, footage-reference, and sensor evidence into a security-event case capturing facility, systems and data hosted, event window, and severity.\n2. Link the case to its full evidence trail so security-event analysis inherits complete context without re-collecting it.\n3. Scan open security-event workflows and route each case to the correct in-flight analysis instance, or confirm a new one must be opened.\n4. Where the receiving system requires a standalone file, export the evidence package.\n5. Record case ID, receiving owner, and hand-off timestamp, and obtain acknowledgement from the receiving owner.\n\n**Record in AssureSwarm**\n- Create an Issue as the security-event case per confirmed event — `issue_type: finding`, `source: management_identified`, `severity`, `identified_date`, with facility, hosted systems and data, event window, and severity in `Issue.description` (there is no native Incident/Security Event item type, so the case is a finding-type Issue plus the exported evidence package below).\n- Link each case Issue to its constituent badge-anomaly, footage-review, and sensor-anomaly evidence Issues (Issue ↔ Issue) and to the anchor Control (Issue ↔ Control) so security-event analysis inherits the full evidence trail.\n- Assemble the hand-off package the security-event analysis workflow's first step consumes: export the evidence package (ZIP/XLSX) where the receiving system requires a standalone file, and upload the hand-off log recording case ID, receiving owner, and hand-off timestamp to this step.\n\n**Exit criteria** — Every event marked confirmed this cycle is packaged, routed, and acknowledged by the security-event analysis owner, with none left unrouted; the hand-off log records case ID, owner, and timestamp for each.","label":"Feed anomalies to security-event analysis","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-workflow-scan","coach-export-package","coach-document-upload"]}},"id":"feed-anomalies-to-security-event-analysis"},{"data":{"decisionField":"coverage_disposition","description":"Agent computes camera, sensor, and badge-system coverage-health metrics and a dashboard; human classifies the cycle's monitoring coverage as adequate or gapped","formData":{"fields":[{"key":"coverage_disposition","label":"Coverage Disposition","options":[{"label":"Coverage adequate, within tolerance","value":"coverage_adequate"},{"label":"Coverage gaps identified","value":"coverage_gaps_identified"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Judge whether the monitoring mechanisms themselves — cameras, sensors, and the badge system — operated with adequate coverage this cycle, independent of the physical anomalies found, so degraded monitoring capability is caught and tracked. Owned by the physical security manager.\n\n**Decision criteria**\n- Compute the cycle's coverage-health metrics from the reviewed camera coverage assessment (camera uptime, blind-spot count, footage-review backlog), the sensor review (sensor uptime, offline incidents), and badge-system uptime; build a coverage-health dashboard showing each metric against its threshold and the trend against prior cycles.\n- Choose **coverage_adequate** (\"Coverage adequate, within tolerance\") when every monitoring mechanism met its threshold with no metric breaching tolerance.\n- Choose **coverage_gaps_identified** (\"Coverage gaps identified\") when any camera, sensor, or badge-system metric breached its tolerance — for example a camera blind spot, a sensor offline beyond its allowed window, or a footage-review backlog over the limit.\n\n**Record in AssureSwarm**\n- Submit the `coverage_disposition` SELECT field with the chosen branch.\n- Record the rationale with the breached metrics in the step result, and the decision owner in the step's approver record.\n- Create or update the recurring coverage-health dashboard (camera/sensor/badge-system uptime, blind-spot count, footage-review backlog against thresholds and the trend versus prior cycles), and upload the coverage assessment summary document to this step.\n\n**Exit criteria** — The `coverage_disposition` form is submitted with rationale and owner recorded; the dashboard shows each metric against its threshold; the unused branch is prunable; on coverage_gaps_identified the breached metrics are ready to convert into corrective actions.","kind":"decision","label":"Assess monitoring coverage gaps","performedBy":{"primitives":["coach-query-data","coach-dashboard-create","coach-document-upload"]}},"id":"assess-monitoring-coverage-gaps"},{"data":{"description":"Agent converts each coverage gap into an owned corrective action; human confirms every gap is owned, dated, and tracked","instructions":"**Objective** — Convert every monitoring coverage gap identified this cycle into an owned, dated, tracked corrective action, so a camera blind spot, an offline sensor, or a badge-system gap does not persist unaddressed into the next cycle.\n\n**Inputs**\n- The coverage assessment document and the breached-metrics list from the coverage decision (this step is reached only on the coverage_gaps_identified branch), plus the camera coverage-gap Issues raised this cycle.\n- Prior-cycle corrective-action Issues still open (linked to the anchor Control), to avoid duplicating an already-tracked gap.\n\n**Procedure**\n1. For each breached metric, state the gap, its root cause, and the facility or system it affects.\n2. Assign each gap an owner, a due date, and an interim compensating measure — for example a temporary guard patrol while a camera is repaired.\n3. Raise a capability-level improvement item for any systemic gap: a facility with a chronic blind spot, or a sensor platform with repeated outages across cycles.\n4. Confirm no gap is left without an owner and due date.\n\n**Record in AssureSwarm**\n- Create an Issue for each coverage gap — `issue_type: deficiency`, `root_cause` (the gap's cause), `remediation_plan` (the fix plus the interim compensating measure), `issue_owner` (USER — the named owner), `target_remediation_date` (the due date); link each to the anchor Control (Issue ↔ Control).\n- For any systemic gap (a facility with a chronic blind spot, a sensor platform with repeated outages across cycles), create a capability-level Issue — `issue_type: opportunity` — with the same owner and date fields.\n- Link each corrective-action Issue to its driving coverage-gap Issue (Issue ↔ Issue).\n- Upload the corrective-action register document (XLSX) to this step.\n\n**Exit criteria** — Every coverage gap has a named owner and due date; systemic gaps have a capability-level improvement item; the physical security manager has confirmed nothing is left untracked before closure.","label":"Log corrective actions","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"log-corrective-actions"},{"data":{"description":"Automatically archive the authorized cycle record and carry open actions into the next cycle.","instructions":"**Objective** — Automatically preserve the authorized cycle record and its carry-forward actions after the preceding decision.\n\n**Inputs**\n- The full cycle record: the badge, camera, and sensor reviews; the consolidated register; the triage disposition and any security-event hand-offs; and the coverage assessment with its disposition and corrective actions.\n- The control execution log and the review schedule.\n\n**Procedure**\n1. Export the full review record and archive it in the designated evidence repository under retention controls; record the archive location and reference.\n2. Create carry-forward items for open corrective actions and any anomaly hand-off still awaiting security-event analysis acknowledgement, so they arrive as explicit inputs to next month's cycle.\n3. Record the cycle result and key coverage metrics — the Control has no native execution-log field, so this lives in the closure record document, with the archived workflow instance on the anchor Control serving as the durable execution trail.\n4. Confirm next month's review is scheduled.\n\n**Record in AssureSwarm**\n- Export the workflow instance (the full run) and archive it under retention controls; the workflow instance itself is the cycle's audit trail. Record the archive location and reference in the closure record.\n- Create a carry-forward Issue for each open corrective action and each hand-off still awaiting security-event analysis acknowledgement — left open, linked to its source Issue and to the anchor Control (Issue ↔ Control) so it arrives as an explicit input to next month's cycle.\n- Upload the closure record document (with the cycle result, key coverage metrics, and archive location) to this step — this document is the control execution log, as the Control type has no execution-log field.\n\n**Exit criteria** — The archived record is retrievable; carry-forward items exist and are linked for every open action and unacknowledged hand-off; the control execution log is updated and next month's review is scheduled; the authorized cycle record is complete.","label":"Close and archive","performedBy":{"primitives":["coach-workflow-export","coach-item-create","coach-items-link","coach-document-upload"]},"requiredApprovals":0},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:controls-physical-environment-monitoring-review"}
