{"description":"Standing operator workflow for remote/wireless/mobile access re-authorization, session trusted-channel and termination verification, and DNSSEC/name-resolution and time-service assurance, as a decision-aware quarterly cycle that contains rogue access before continuing and routes gaps to tracked corrective action. Each quarterly instance attaches to the existing standing Process item (process_type: security_process, frequency: quarterly) for Secure Connectivity & Network Trust Services — it enriches that Process cycle-over-cycle, never creating a duplicate — and that Process is related to the existing Control items UC-NET-02, UC-NET-03, and UC-NET-07 the cycle operates. In scope: remote-access methods, wireless networks, and organization-controlled mobile devices; systems hosting security-relevant sessions; authoritative DNS zones, recursive and caching resolvers, and authoritative time sources. Out of scope: endpoint hardening and identity/credential lifecycle beyond out-of-band key delivery. The cycle runs on its own quarterly trigger and consumes no upstream workflow handoff package; it produces the re-authorization register, the sweep and containment logs, the session-trust and name-resolution/time assurance records, the connectivity trust-posture dashboard and summary, and a corrective-action register — closing into an internal carry-forward that seeds the next quarterly instance (no handoff to a distinct downstream workflow).","edges":[{"id":"e-verify-connection-protections-and-sweep-rogue-access-contain-unauthorized-access","label":"Rogue detected","source":"verify-connection-protections-and-sweep-rogue-access","target":"contain-unauthorized-access","whenValue":"rogue_access_detected"},{"id":"e-verify-connection-protections-and-sweep-rogue-access-classify-connectivity-trust-posture","label":"Clean","source":"verify-connection-protections-and-sweep-rogue-access","target":"classify-connectivity-trust-posture","whenValue":"clean_no_rogue_access"},{"id":"e-contain-unauthorized-access-classify-connectivity-trust-posture","source":"contain-unauthorized-access","target":"classify-connectivity-trust-posture"},{"id":"e-classify-connectivity-trust-posture-remediate-and-track-gaps","label":"Gaps","source":"classify-connectivity-trust-posture","target":"remediate-and-track-gaps","whenValue":"gaps_identified"},{"id":"e-classify-connectivity-trust-posture-close-and-archive","label":"Confirmed","source":"classify-connectivity-trust-posture","target":"close-and-archive","whenValue":"trust_confirmed"},{"id":"e-remediate-and-track-gaps-close-and-archive","source":"remediate-and-track-gaps","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-NET-02","UC-NET-03","UC-NET-07","UC-ACCESS-10"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-secure-connectivity-network-trust-services","contentDigest":"sha256:2f2c8b341180d218856634cd273ef87ef09f1ea90339826604d82d8fe83d1704","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:2f2c8b341180d218856634cd273ef87ef09f1ea90339826604d82d8fe83d1704","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-secure-connectivity-network-trust-services"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-secure-connectivity-network-trust-services","source":"coworkcanvas-gallery","standards":["nist-800-53"],"teams":["it"]},"name":"Secure Connectivity & Network Trust Services Operation","nodes":[{"data":{"decisionField":"rogue_access_disposition","description":"Reauthorize the complete connection estate and decide rogue/under-protected connectivity from live configuration and sweep evidence.","formData":{"fields":[{"key":"rogue_access_disposition","label":"Rogue Access Disposition","options":[{"label":"Clean, no rogue access","value":"clean_no_rogue_access"},{"label":"Rogue access detected","value":"rogue_access_detected"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Reauthorize the complete connection estate and decide rogue/under-protected connectivity from live configuration and sweep evidence.\n\n**Inputs**\n- The remote-access method, wireless SSID, and organization-controlled mobile-device inventory (one record per method/device), each with its last-authorization date and assigned owner — queried live from the external NAC/MDM/wireless-controller systems; the prior cycle's attached re-authorization register is the AssureSwarm copy. There is no native Asset/Device item type, so this inventory is not held item-per-record (honest gap). This is the cycle's own initial input; no upstream workflow feeds it.\n- The documented usage restrictions and configuration/connection requirements per access type — Policy items (policy_type: standard, framework: nist-800-53, domains: network_communications_security), with the governed standard attached to each Policy item.\n- The prior-cycle operating log (the prior quarter's archived workflow instance / exported operating record) and any carried-over exceptions — existing open Issue items (issue_type: exception, source: self_assessment) linked to the anchor Process and Control items.\n- Control references — the existing Control items UC-NET-02/03/07 (control_id, framework: nist-800-53, domains: network_communications_security, control_owner = the network-security control owner) covering NIST 800-53 AC-17 (remote access), AC-18 (wireless access), AC-19 (mobile devices), SC-40 (wireless link protection).\n\n**Procedure**\n_This checkpoint absorbs “Re-authorize remote, wireless, and mobile access”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Re-authorize remote, wireless, and mobile access: Re-establish explicit, current authorization for every remote-access method, wireless network, and organization-controlled mobile device against its documented usage restrictions and configuration/connection requirements, so no connection is treated as permitted this cycle without a live authorization (UC-NET-02).\n2. Query the current remote-access methods, wireless SSIDs, and organization-controlled mobile-device inventory together with each item's last-authorization date and assigned owner.\n3. Pull the documented usage restrictions and configuration/connection requirements for each access type; compare them against the live configuration; flag every method or device whose configuration no longer matches its requirement.\n4. Test each item against three gates: a current explicit authorization exists, it is still tied to a live business need, and it is in configuration. Anything failing any gate is an exception.\n5. Draft a re-authorization package per access type and device, recording the authorizer, the business justification, and the requirement baseline it was checked against.\n6. Create an exception Issue (issue_type: exception, source: self_assessment) for each item lacking a current authorization, no longer tied to a business need, or out of configuration, and link each to Control UC-NET-02 (the inventory records are not AssureSwarm items, so the breached Control is the linkable parent).\n7. Assemble the re-authorization register listing every method and device with its disposition — re-authorized, or queued for revocation.\n8. Verify connection protections and sweep for rogue access: Resolve whether the authorized connection estate is clean or whether rogue or under-protected connectivity must be contained before the cycle continues; owned by the network-security control owner (UC-NET-02).\n\n**Decision criteria**\n- `clean_no_rogue_access` — every re-authorized connection meets its protection baseline (mutual or certificate-based authentication, an in-policy encryption cipher suite, and wireless link-layer protection such as 802.1X with WPA2/3-Enterprise commensurate with signal exposure) AND the wireless/network access-point sweep found no signal or connection outside the re-authorized inventory.\n- `rogue_access_detected` — the sweep found an access point or connection with no matching authorization record, OR the protection review found an authorized connection whose protections fall short of its exposure baseline; either condition must be contained before the posture is scored.\n\n**Procedure (run before deciding)**\n1. Query the authentication method, encryption cipher suite, and wireless link-layer protection configured for each re-authorized access type; compare each against the required protection baseline for its exposure level.\n2. Flag any authorized connection whose protections fall short of the baseline.\n3. Run the wireless and network access-point sweep; cross-reference every detected access point and connection against the re-authorization register; list every signal or connection with no matching authorization record.\n4. Draft the protection-baseline exceptions and sweep findings and attach them.\n\n**Record in AssureSwarm**\nQuery the external inventory and configuration (data query); create an exception **Issue** per gap (item create — issue_type: exception, source: self_assessment, identified_date) and link each **Issue ↔ Control UC-NET-02** (items link — the inventory records are not items, so the Control is the linkable parent); attach the re-authorization register as an XLSX step document (document upload).\nSubmit the SELECT field `rogue_access_disposition` (`clean_no_rogue_access` | `rogue_access_detected`); record the decision rationale and evidence references in the step result and name the decision owner. Query the external configuration and sweep data (data query); attach the sweep and protection-baseline findings as an XLSX/PDF step document (document upload).\n\n**Exit criteria**\n- Every remote-access method, wireless network, and organization-controlled mobile device is either explicitly re-authorized against its usage restrictions and connection requirements, or has an exception item queued for revocation; the register is attached.\n- The routing selector is submitted and the step result contains a rationale citing the sweep and protection evidence, and the unused branch is prunable.","kind":"decision","label":"Verify connection protections and sweep for rogue access","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-items-link","coach-document-upload"]}},"id":"verify-connection-protections-and-sweep-rogue-access"},{"data":{"description":"Agent isolates and removes the rogue access points/connections and confirms a clean re-scan; human verifies containment before verification continues","instructions":"**Objective** — Isolate and remove every rogue access point, unauthorized connection, or under-protected link the sweep surfaced, restoring the network trust boundary before the cycle's posture is scored (UC-NET-02).\n\n**Inputs**\n- The rogue and under-protected findings from the connection-protection and rogue-access sweep decision (its attached findings register and the `rogue_access_detected` disposition).\n- The required protection baseline per exposure level.\n- Network isolation and device reconfiguration access.\n\n**Procedure**\n1. Create a finding Issue (issue_type: finding, source: self_assessment, severity per exposure) for each rogue access point, unauthorized connection, or under-protected link, capturing its location, detection method, and risk.\n2. Link each Issue to Control UC-NET-02 (the sweep findings are step-attached evidence, not items, so the breached Control is the linkable parent).\n3. Drive disconnection, isolation, or reconfiguration of each item to the required protection baseline.\n4. Query a follow-up sweep to confirm the environment re-scans clean; if any item persists, iterate until the re-scan is clean.\n5. Assemble the containment log with the clean re-scan confirmation.\n\n**Record in AssureSwarm** — Create a finding **Issue** per rogue/under-protected item (item create — issue_type: finding, source: self_assessment, severity per exposure); link each **Issue ↔ Control UC-NET-02** (items link — the sweep findings are step evidence, not items, so the Control is the linkable parent); query the follow-up sweep (data query); attach the containment log and clean re-scan confirmation as a step document (document upload).\n\n**Exit criteria** — Every rogue, unauthorized, or under-protected item is contained or brought to baseline and the follow-up sweep is clean; the containment log is attached.","label":"Contain unauthorized access","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-query-data","coach-document-upload"]}},"id":"contain-unauthorized-access"},{"data":{"decisionField":"trust_posture_disposition","description":"Agent verifies session trusted channels, termination, and out-of-band key delivery and name-resolution and time-service assurance, then computes cycle metrics and a posture dashboard; human classifies the cycle as trust confirmed or gaps identified","formData":{"fields":[{"key":"trust_posture_disposition","label":"Trust Posture Disposition","options":[{"label":"Trust confirmed, within tolerance","value":"trust_confirmed"},{"label":"Gaps identified","value":"gaps_identified"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Verify session trusted channels, termination, and out-of-band key delivery (UC-NET-03) and name-resolution and time-service assurance (UC-NET-07), then resolve whether the secure-connectivity and network-trust capability operated within tolerance this cycle or carries gaps that need tracked remediation, so only the relevant closure path continues; owned by the control owner.\n\n**Inputs**\n- The inventory of security-relevant interaction paths, administrative consoles, privileged management interfaces, and inter-service trust paths — queried live from the external session/IAM systems; there is no native Asset item type, so these paths are not held item-per-record (honest gap).\n- The session-timeout and inactivity-termination configuration per in-scope system, and the credential and key-delivery mechanisms used for the in-scope access types.\n- The authoritative DNS zone list with DNSSEC signing status, key-rotation dates, and chain-of-trust validity; the recursive and caching resolver configuration; the DNS topology (internal vs. external resolver role separation, redundancy, failover) — queried live from the external DNS infrastructure, with no native Asset/zone item type (honest gap).\n- The NTP or authoritative time-source configuration and clock-drift telemetry across the estate.\n- The re-authorization register and the sweep/containment logs from the upstream tracks.\n- Control references: NIST 800-53 SC-11 (trusted path), SC-23 (session authenticity), SC-10 (network disconnect), SC-37 (out-of-band channels), SC-20/SC-21 (secure name resolution, authoritative and recursive), SC-22 (name-resolution architecture), SC-45 (time synchronization).\n\n**Procedure**\n_Items 1–11 are agent-run (folded from the former \"Verify session trusted channels, termination, and key delivery\" and \"Verify name-resolution assurance and time synchronization\" steps); the human moment is the posture call in item 15._\n1. Query the inventory of security-relevant interaction paths, administrative consoles, privileged management interfaces, and inter-service trust paths.\n2. Verify each path enforces mutual authentication (e.g., mutual TLS or certificate-based endpoint verification); flag any path relying on one-sided authentication.\n3. Verify session-integrity protections — sequence numbering, anti-replay tokens, or message authentication — are enabled on each path; flag any path without them.\n4. Query the session-timeout and inactivity-termination configuration for every in-scope system; flag any system with no enforced session-end or inactivity termination, or whose setting exceeds the documented threshold.\n5. Query the credential and key-delivery mechanisms for the in-scope access types; confirm each uses an out-of-band channel distinct from the primary session channel; flag any that do not.\n6. Assemble the session-trust verification record covering channel authentication, session integrity, termination, and out-of-band key delivery.\n7. Query DNSSEC signing status, key-rotation dates, and chain-of-trust validity for every authoritative zone in scope; flag any zone with an expired signature, a stale or soon-to-expire key, or unsigned records.\n8. Query the recursive and caching resolver configuration to confirm DNSSEC validation is enabled and enforced; flag any resolver that accepts unvalidated responses.\n9. Query the DNS topology to confirm internal and external resolver role separation and redundancy or failover across authoritative and recursive services; query or exercise failover behavior; flag any single point of failure or missing internal/external separation.\n10. Query the NTP or authoritative time-source configuration and clock-drift telemetry across the in-scope estate; flag any system not synchronized within tolerance to the authoritative source.\n11. Assemble the name-resolution and time-service assurance record covering signing, resolver validation, resilience, and clock synchronization.\n12. Compute the cycle metrics from every verification track: re-authorization completion and open exceptions; protection-baseline exceptions; rogue-access containment status; session trusted-channel and termination gaps; out-of-band key-delivery exceptions; DNSSEC and resolver-validation gaps; DNS resilience and time-synchronization exceptions.\n13. Build a connectivity trust-posture dashboard showing each metric against its threshold and the trend versus prior cycles.\n14. List every open exception with its owner and the evidence behind it, and draft the posture summary.\n15. Classify the posture against the criteria below and submit the branch with a rationale citing the metrics and dashboard.\n\n**Decision criteria**\n- `trust_confirmed` — every cycle metric is within tolerance and no exception is open: re-authorization complete with no open exceptions, no protection-baseline exceptions, rogue access contained or none found, session trusted-channel/termination and out-of-band key-delivery clean, DNSSEC and resolver validation clean, and DNS resilience and time synchronization within tolerance.\n- `gaps_identified` — any re-authorization, protection, session, or name-resolution/time exception remains open.\n\n**Record in AssureSwarm** — Query the external path, session, key-delivery, DNSSEC, resolver, topology, and time-source configuration (data query); attach the session-trust assurance record and the name-resolution and time-service assurance record as step documents (document upload) — those estates live in external systems with no native inventory item type, so the assurance records are the AssureSwarm evidence. Build the connectivity trust-posture dashboard (dashboard create) and attach the posture summary as a PDF/DOCX step document. Submit the SELECT field `trust_posture_disposition` (`trust_confirmed` | `gaps_identified`); record the rationale and evidence references and name the decision owner.\n\n**Exit criteria** — Every security-relevant path is mutually authenticated and integrity-protected, session-termination settings meet policy, and credential and key delivery is genuinely out-of-band; every authoritative zone is correctly signed, every recursive resolver validates DNSSEC, DNS fault tolerance and internal/external role separation are confirmed, and clock synchronization is within tolerance; both assurance records are attached; the routing selector is submitted and the step result contains a rationale citing the metrics and dashboard, and the unused branch is prunable.","kind":"decision","label":"Classify connectivity trust posture","performedBy":{"primitives":["coach-query-data","coach-dashboard-create","coach-document-upload"]}},"id":"classify-connectivity-trust-posture"},{"data":{"description":"Agent converts each identified gap into an owned corrective action; human confirms every gap is owned, dated, and escalated where required","instructions":"**Objective** — Convert every gap identified at the posture review into an owned, dated, tracked corrective action so no connectivity or network-trust exception degrades the standing capability unaddressed.\n\n**Inputs**\n- The posture summary and its open-exception list with owners and evidence (from the connectivity trust-posture classification).\n- The corrective-action SLA thresholds and escalation routing.\n\n**Procedure**\n1. Parse the posture summary to list each gap with its root cause and the metric or finding that surfaced it.\n2. Create a corrective-action Issue for each gap (issue_type: deficiency, or exception where a control gap is knowingly accepted; capturing root_cause, issue_owner, target_remediation_date, remediation_plan, source: self_assessment) and link it to the Control it degrades (UC-NET-02/03/07) and to the anchor Process.\n3. Raise capability-level improvement items for systemic gaps — a chronically under-protected access type, a recurring rogue-access source, or a resolver that repeatedly fails validation.\n4. Escalate any unresolved exception past its SLA to the accountable owner.\n5. Assemble the corrective-action register.\n\n**Record in AssureSwarm** — Create a corrective-action **Issue** per gap (item create — issue_type: deficiency [or exception], root_cause, issue_owner, target_remediation_date, remediation_plan, source: self_assessment); link each **Issue ↔ Control** it degrades (UC-NET-02/03/07) and **Issue ↔ Process** (items link — the metrics and findings are step evidence, not items, so the Control and anchor Process are the linkable parents); attach the corrective-action register as an XLSX step document (document upload).\n\n**Exit criteria** — Every gap has a named owner and due date, escalations were routed, and nothing is left untracked; the register is attached.","label":"Remediate and track gaps","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"remediate-and-track-gaps"},{"data":{"description":"Automatically archive the authorized cycle record and carry open actions into the next cycle.","instructions":"**Objective** — Automatically preserve the authorized cycle record and its carry-forward actions after the preceding decision.\n\n**Inputs**\n- The full operating record for this cycle: the re-authorization register, the sweep and containment logs, the session-trust and name-resolution/time assurance records, the posture summary, and the corrective-action register.\n- The retention and evidence-repository controls.\n- The next quarterly cadence date and upcoming DNSSEC key-rotation or contact-review dates.\n\n**Procedure**\n1. Export the full operating record and archive it in the designated evidence repository under retention controls; record the archive location and reference.\n2. Create carry-forward Issue items (issue_type: exception/deficiency, source: self_assessment) for open corrective actions and dated follow-ups — the next quarterly re-authorization date and upcoming DNSSEC key-rotation or contact-review dates — and link each to its source Issue and Control so it arrives as an explicit input to the next cycle.\n3. Update the control execution log with the cycle result and key metrics; confirm the next cadence review is scheduled.\n4. Assemble the closure record.\n\n**Record in AssureSwarm** — Archive the run itself as the audit trail and export the full operating record (workflow export); create carry-forward **Issue** items for open corrective actions and dated follow-ups (item create — issue_type: exception/deficiency, source: self_assessment) and link each **Issue ↔ its source Issue and Control** (items link); attach the closure record as a step document (document upload).\n\n**Exit criteria** — The archived record is immutable and retrievable, the next review is scheduled, nothing remains open without a tracked owner, the authorized cycle record is complete.","label":"Close and archive","performedBy":{"primitives":["coach-workflow-export","coach-item-create","coach-items-link","coach-document-upload"]},"requiredApprovals":0},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:controls-secure-connectivity-network-trust-services"}
