{"description":"Standing monthly operator workflow run against the existing supply-chain integrity Control item (UC-TPRM-07, frequency=monthly, domains=third_party_supply_chain_risk), with the OPSEC need-to-know Control (UC-TPRM-09) linked as the second in-scope control — enrich these existing Control items, never recreate them; the workflow instance attaches to the anchor Control as the durable operating record. Two concurrent workstreams. In scope: receipt-time tamper-evidence and authenticity inspection of critical systems and components, provenance and chain-of-custody upkeep, suspected-counterfeit disposition (each raised as a finding Issue linked to the anchor Control and the implicated Vendor) with inspector-training refresh where a lapse is found, and the OPSEC need-to-know review of the sensitive supply-chain information register with remediation of any overexposure. Named deliverables: the authenticated provenance and chain-of-custody register, the counterfeit-disposition cases, the OPSEC exposure-review worksheet, and the confirmed need-to-know-restricted disclosure footprint. No upstream workflow feeds this cycle — its inputs are the period's own receiving log and the sensitive supply-chain information register. This is a terminal standing control: procurement and vendor onboarding, contract-level third-party risk assessment, and facility physical security are out of scope, each handled by its own workflow; a substantiated counterfeit or compromised supplier is escalated to the third-party/vendor risk workflow rather than resolved here.","edges":[{"id":"e-disposition-inspection-findings-disposition-suspected-counterfeits","label":"Counterfeit suspected","source":"disposition-inspection-findings","target":"disposition-suspected-counterfeits","whenValue":"counterfeit_suspected"},{"id":"e-disposition-inspection-findings-log-corrective-actions-and-carryover","label":"Clean, authenticated","source":"disposition-inspection-findings","target":"log-corrective-actions-and-carryover","whenValue":"clean_authenticated"},{"id":"e-disposition-suspected-counterfeits-log-corrective-actions-and-carryover","source":"disposition-suspected-counterfeits","target":"log-corrective-actions-and-carryover"},{"id":"e-assess-need-to-know-and-disposition-remediate-opsec-overexposure","label":"Overexposure found","source":"assess-need-to-know-and-disposition","target":"remediate-opsec-overexposure","whenValue":"overexposure_found"},{"id":"e-assess-need-to-know-and-disposition-log-corrective-actions-and-carryover","label":"Properly restricted","source":"assess-need-to-know-and-disposition","target":"log-corrective-actions-and-carryover","whenValue":"properly_restricted"},{"id":"e-remediate-opsec-overexposure-log-corrective-actions-and-carryover","source":"remediate-opsec-overexposure","target":"log-corrective-actions-and-carryover"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-TPRM-07","UC-TPRM-09"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-supply-chain-integrity-opsec-operations","contentDigest":"sha256:6accc3950adde35373ca06d8c364cbd98d3206abe88ce5a64ae5d541ac074b30","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:6accc3950adde35373ca06d8c364cbd98d3206abe88ce5a64ae5d541ac074b30","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-supply-chain-integrity-opsec-operations"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-supply-chain-integrity-opsec-operations","source":"coworkcanvas-gallery","standards":["nist-800-53","iso-27001"],"teams":["it","procurement"]},"name":"Supply-Chain Integrity & OPSEC Operations","nodes":[{"data":{"decisionField":"inspection_disposition","description":"Agent compiles the period receiving log, runs tamper-evidence and authenticity checks against every receipt, and drafts a disposition recommendation; human decides whether the period is clean or contains suspected counterfeits","formData":{"fields":[{"key":"inspection_disposition","label":"Inspection Disposition","options":[{"label":"Clean, all receipts authenticated","value":"clean_authenticated"},{"label":"Counterfeit suspected","value":"counterfeit_suspected"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Inspect every critical system, component, and data-bearing item received this period for tamper-evidence and authenticity, then decide whether the period's receipts are clean and ready for provenance recording or whether one or more suspected counterfeits must be quarantined and dispositioned first. Owned by the Supply-Chain Security Lead.\n\n**Inputs**\n- The governing controls: the existing Control items UC-TPRM-07 (supply-chain integrity / anti-counterfeit — the anchor this monthly instance runs against) and UC-TPRM-09 (OPSEC need-to-know), `framework` [nist-800-53, iso-27001], `domains` third_party_supply_chain_risk — enrich the anchor Control, never recreate it.\n- The period's receiving log of critical receipts (supplier, purchase-order or contract reference, serial/lot number, quantity, packaging/design tamper-evidence classification): held in the external receiving/ERP system and pulled via `coach-query-data`; the period snapshot lands as a document on this step — there is no Receipt/Asset item type to hold per-receipt records.\n- Supplier authenticity references: the Vendor register (Vendor items — `category` hardware_supplier, `tier`, `business_owner`, `risk_owner`) plus the external manufacturer certifications, authorized-distributor lists, and serial/lot master or verification portal, whose copies attach here as evidence.\n- Prior chain-of-custody entries for the same part types — the prior cycle's provenance/custody register document attached at the previous instance (to detect a broken custody trail).\n- The period boundary (this monthly cycle's receiving window).\n- This is a parallel entry: its only inputs are the period's own receiving records — it runs concurrently with the sensitive-information register review and does not wait on it. No upstream workflow feeds this cycle.\n\n**Procedure**\n_Items 1–5 are agent-run (folded from the former \"Inspect receipts for tamper and authenticity\" step, which carried no separate human touch-point); the human moment is the disposition call in item 6._\n1. Pull the receiving log for the period with `coach-query-data` and enumerate every critical system, component, and data-bearing item received, with supplier, serial/lot, and tamper-evidence class. Confirm the count ties to the receiving-system total for the window — a missing consignment voids coverage, so reconcile before inspecting.\n2. For each receipt, record the physical inspection result: outer packaging and seal integrity, tamper-evident feature status (holograms, security tape, void labels, factory seals), and any physical indication of prior opening, resoldering, relabeling, or substitution.\n3. Verify authenticity for each receipt: match serial/lot against the manufacturer or authorized-distributor record, confirm a valid certificate of conformance where required, and check the part against known-counterfeit indicators (mismatched date codes, blacktopped chips, off-spec weight or markings). Flag any item that fails serial verification, lacks certification, or shows a broken chain of custody.\n4. Classify each receipt pass or fail, capture the supporting evidence (photos, portal screenshots, certificate references), and assemble the inspection-results register keyed by receipt.\n5. Aggregate the register and classify the period as fully passing or containing failures. For any failing item, confirm the failure is real (not a documentation gap resolvable on the spot) and cross-check open counterfeit-disposition cases with `coach-workflow-scan` to avoid a duplicate case; draft the disposition recommendation.\n6. The Supply-Chain Security Lead reviews the register and the recommendation and submits the disposition against the criteria below.\n\n**Decision criteria**\n- Choose `clean_authenticated` when every receipt passed both tamper-evidence and authenticity checks with sufficient evidence and no item is under suspicion.\n- Choose `counterfeit_suspected` when one or more receipts failed serial verification, lack certification, show tamper evidence, or otherwise cannot be authenticated — any single unresolved failure forces this branch; a clean remainder does not override one suspect item.\n\n**Record in AssureSwarm** — Submit the `inspection_disposition` SELECT. Record the decision rationale with explicit evidence references in the step result, and the deciding owner or approver. Attach the inspection-results register — one row per receipt with pass/fail tamper-evidence and authenticity status and its evidence (photos, portal screenshots, certificate references) — as an XLSX, together with the disposition recommendation (`coach-document-upload`); there is no Receipt/Asset item type, so this register is the authoritative per-receipt record for the period. Source the receiving log, supplier/serial data, and the aggregated results from the external receiving/ERP and the Vendor register via `coach-query-data`.\n\n**Exit criteria** — Every receipt in the period window has a recorded physical-inspection and authenticity result with evidence, the receipt count reconciles to the receiving system, and no critical receipt is left un-inspected; the routing selector is submitted and the step result contains a rationale; the selected branch matches the inspection evidence; the unused branch is prunable.","kind":"decision","label":"Disposition inspection findings","performedBy":{"primitives":["coach-query-data","coach-workflow-scan","coach-document-upload"]}},"id":"disposition-inspection-findings"},{"data":{"description":"Agent opens a disposition case per flagged item, quarantines and reports it, and drafts inspector-training refresh where a lapse contributed; human confirms each item is correctly dispositioned","instructions":"**Objective** — Quarantine and formally disposition each suspected-counterfeit receipt, report it per policy, and close any inspector-training gap that let it through — before the affected part type is trusted again.\n\n**Inputs**\n- The inspection-results register and the `counterfeit_suspected` decision rationale (which items, what evidence).\n- Any open counterfeit-disposition cases (to link rather than duplicate).\n- The counterfeit-reporting policy and designated reporting channel (e.g., GIDEP or the internal SCRM reporting path) — held as a Policy item (`policy_type` procedure, `policy_owner`, `framework` [nist-800-53, iso-27001], `domains` third_party_supply_chain_risk) — and the inspector-training roster.\n\n**Procedure**\n1. Open a disposition case for each suspected item as an Issue with `coach-item-create` — `issue_type` exception, `source` management_identified, `root_cause` the tamper/counterfeit evidence, `issue_owner`, `target_remediation_date`, and `remediation_plan` (return, reject, destroy, or escalate) — capturing supplier, purchase-order reference, failure evidence, and the quantity potentially affected; link each Issue to its inspection-register entry and to the anchor Control UC-TPRM-07 (Issue↔Control) with `coach-items-link`.\n2. Physically quarantine the flagged items (segregated, labeled, access-restricted) pending disposition so they cannot be issued or installed.\n3. Draft the supplier notification and, where the counterfeit-reporting threshold is met, a suspected-counterfeit report for the designated channel; capture disposition intent (return, reject, destroy, or escalate for forensic teardown).\n4. Review the inspection method that missed or late-caught the item to determine whether an inspector-training lapse contributed; if so, assign the existing inspector training-refresher activity to the affected inspector for that failure mode.\n5. Assemble the disposition-case log, supplier notification, report, and any training assignment.\n\n**Record in AssureSwarm**\n- Create one Issue per suspected item (`coach-item-create`; `issue_type` exception, `source` management_identified, `root_cause`, `remediation_plan`, `issue_owner`, `target_remediation_date`), linked to its inspection-register entry and to the anchor Control UC-TPRM-07 (Issue↔Control) via `coach-items-link`.\n- Record the inspector training-refresher assignment in the existing training roster where a lapse is found.\n- Attach the disposition-case log, notification, and report (`coach-document-upload`).\n\n**Exit criteria** — Every suspected item is quarantined and has a disposition case with a decided outcome; any required report is filed; a training-refresher is assigned wherever a lapse was identified.","label":"Disposition suspected counterfeits","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-form-create","coach-document-upload"]}},"id":"disposition-suspected-counterfeits"},{"data":{"decisionField":"opsec_disposition","description":"Agent pulls the sensitive supply-chain information register and its disclosure footprint, cross-references every recipient against the validated need-to-know roster, and scores the unmatched ones; human decides whether disclosure remains properly restricted or requires remediation","formData":{"fields":[{"key":"opsec_disposition","label":"OPSEC Disposition","options":[{"label":"Properly restricted to need-to-know","value":"properly_restricted"},{"label":"Overexposure found","value":"overexposure_found"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Establish the complete OPSEC review population from the sensitive supply-chain information register and its disclosure footprint, then decide whether this period's disclosure remains properly restricted to validated need-to-know or whether overexposure requires remediation before the cycle closes. Owned by the Supply-Chain Security Lead.\n\n**Inputs**\n- The register of sensitive supply-chain information: supplier identities, shipment and delivery schedules, and system/component configurations, by category.\n- The current disclosure footprint per category: distribution lists, shared drives/locations, and access grants (internal and external/third-party).\n- The validated need-to-know roster: personnel and third parties authorized per category, with justification and grant date.\n- This is a parallel entry: its inputs are the register and access data — it runs concurrently with the receipt-inspection workstream and does not depend on it. No upstream workflow feeds this cycle.\n\n**Procedure**\n_Items 1–5 are agent-run (folded from the former \"Review sensitive info register and access\" step, which carried no separate human touch-point); the human moment is the disposition call in item 6._\n1. Pull the sensitive-information register with `coach-query-data`, enumerating each category (supplier identities, shipment/delivery schedules, configurations) and its current distribution lists, shared locations, and access grants.\n2. Pull the need-to-know roster with each recipient's authorized categories, justification, and grant date.\n3. Cross-reference every access grant, distribution-list member, shared-location viewer, and external recipient against the roster; flag any recipient, list, drive, or external party not on the validated roster for its category.\n4. Compile the exposure-review worksheet: one row per category with its disclosure footprint and every unmatched recipient or distribution point.\n5. Score each unmatched recipient or distribution point by information-category sensitivity and likely adversary value with `coach-query-data`; confirm each flag is a genuine unauthorized disclosure, not a roster-record lag resolvable immediately, and draft the overexposure-findings summary.\n6. The Supply-Chain Security Lead reviews the worksheet and the findings summary and submits the disposition against the criteria below.\n\n**Decision criteria**\n- Choose `properly_restricted` when every recipient, list, and shared location matches the validated need-to-know roster and no unauthorized disclosure remains.\n- Choose `overexposure_found` when any recipient, distribution list, shared drive, or external party holds a sensitive category without validated need to know — a single confirmed unauthorized disclosure forces this branch.\n\n**Record in AssureSwarm** — Submit the `opsec_disposition` SELECT. Record the rationale with per-instance evidence references and the deciding owner or approver. Source the register, footprint, and roster via `coach-query-data`. Attach the exposure-review worksheet and the overexposure-findings summary (`coach-document-upload`).\n\n**Exit criteria** — Every sensitive-information category is represented with its full disclosure footprint, each recipient is matched or flagged against the need-to-know roster, and the worksheet covers the whole register for the period; the routing selector is submitted and the step result contains a rationale; the selected branch matches the exposure evidence; the unused branch is prunable.","kind":"decision","label":"Assess need-to-know and disposition","performedBy":{"primitives":["coach-query-data","coach-document-upload"]}},"id":"assess-need-to-know-and-disposition"},{"data":{"description":"Agent opens a remediation case per overexposure instance and revokes, narrows, or takes down the exposed disclosure; human confirms disclosure now matches need-to-know","instructions":"**Objective** — Bring every instance of overexposed sensitive supply-chain information back to the validated need-to-know standard and confirm no residual collection risk remains.\n\n**Inputs**\n- The exposure-review worksheet and the `overexposure_found` decision rationale (which instances, which categories, which recipients or locations).\n- Access-management, distribution-list, and shared-location administration paths; the information-owner and supplier-relationship-owner contacts.\n\n**Procedure**\n1. Open a remediation case for each overexposure instance as an Issue with `coach-item-create` — `issue_type` exception, `source` management_identified, `root_cause` the exposure detail (information category, unauthorized recipient or location, exposure duration), `issue_owner`, `target_remediation_date`, and `remediation_plan` (revoke, narrow, or take down); link each Issue to the exposure-review worksheet and to the OPSEC anchor Control UC-TPRM-09 (Issue↔Control) with `coach-items-link`.\n2. Execute the appropriate remedy per instance: revoke or narrow the access grant, remove the distribution-list entry, or request takedown or redaction of the sensitive information from the shared location.\n3. Notify the accountable information owner and, where the exposure involved supplier-identifying detail, the affected supplier-relationship owner; assess and record whether the exposure created a residual collection risk (e.g., data already scraped or forwarded) and any follow-on containment.\n4. Assemble the remediation log with action taken and confirmation evidence per instance.\n\n**Record in AssureSwarm**\n- Create one Issue per overexposure instance (`coach-item-create`; `issue_type` exception, `source` management_identified, `root_cause` = exposure detail, `issue_owner`, `target_remediation_date`, `remediation_plan`; set `actual_remediation_date` on confirmation), linked to the exposure-review worksheet and to the Control UC-TPRM-09 (Issue↔Control) via `coach-items-link`.\n- Attach the remediation log with confirmation evidence (`coach-document-upload`).\n\n**Exit criteria** — Every overexposure instance has a remediation case with an executed remedy and confirmation evidence; current disclosure now matches the validated need-to-know roster; residual risk is assessed and, where present, contained.","label":"Remediate OPSEC overexposure","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"remediate-opsec-overexposure"},{"data":{"description":"Review reconciled provenance and both workstream metrics, then sign off owned, dated and escalated exceptions.","instructions":"**Objective** — Review reconciled provenance and both workstream metrics, then sign off owned, dated and escalated exceptions.\n\n**Inputs**\n- The inspection-results register (all receipts, pass/fail), produced at the inspection-disposition step.\n- The disposition-case outcomes for any flagged items (present only when the counterfeit branch ran; on the clean branch there are none).\n- The existing bill-of-materials / chain-of-custody records and the inspector-training roster.\n- This node is a join: it starts once inspection findings are dispositioned — either the clean branch or the completed suspected-counterfeit disposition.\n- The provenance/custody register and any counterfeit-disposition cases (authenticity workstream output).\n- The exposure-review worksheet and any remediation cases (OPSEC workstream output).\n- The inspector-training roster and prior-cycle metrics for trend.\n- This node is a join: it needs the inspection disposition and the OPSEC disposition (with any remediation); update provenance within this checkpoint before computing both-workstream metrics.\n- The metrics summary and the out-of-tolerance list from the metrics-verification activities in this checkpoint.\n- The disposition, provenance, and remediation logs (root-cause detail per exception).\n- The full operating record for the cycle: inspection results, disposition cases, provenance updates, exposure-review worksheet, remediation log, and metrics summary.\n- The evidence-retention schedule — held as a Policy item (`policy_type` standard, `policy_owner`, `framework` [nist-800-53, iso-27001], `domains` third_party_supply_chain_risk) — and the designated archive repository.\n\n**Procedure**\n_This checkpoint absorbs “Update provenance and train inspectors”, “Verify cycle metrics and evidence”. The agent runs the preparation, evidence assembly and record updates below; the named owners retain the substantive decisions and approvals stated in the procedure._\n1. Update provenance and train inspectors: Record this period's receipts — with their inspection and disposition outcomes — into the bill-of-materials and chain-of-custody so provenance stays current and complete for every critical system and component.\n2. For every period receipt, add or update a row in the period's bill-of-materials and chain-of-custody register — supplier, serial/lot, inspection result, authenticity verification, and, for flagged items, the disposition outcome — keying each row to its inspection-results entry and any disposition-case Issue by receipt. There is no Asset/Component item type to hold per-part provenance, so this register document is the authoritative provenance record for the period.\n3. Confirm the inspector training-refresher assignment (if any was raised this cycle) is logged against the affected inspector; where no lapse was identified, record explicitly that inspector training remains current, citing the roster date.\n4. Reconcile the updated register against the receiving log with `coach-query-data` so no period receipt is missing a provenance row and no provenance row lacks an inspection result.\n5. Assemble the updated provenance and chain-of-custody register for the period.\n6. Verify cycle metrics and evidence: Confirm the cycle's authenticity-inspection and OPSEC-review evidence is complete and compute the metrics that support closing the cycle.\n7. Compute cycle metrics with `coach-query-data`: percent of period receipts inspected; counterfeit dispositions closed vs open; inspector training-refresh completion; percent of the sensitive-information register reviewed; overexposure instances remediated vs open.\n8. Build a supply-chain integrity and OPSEC dashboard with `coach-dashboard-create` showing each metric against its threshold and its trend versus prior cycles.\n9. List every metric outside tolerance — incomplete inspection coverage, an open counterfeit case, an unremediated overexposure instance, or overdue training — with its owner.\n10. Assemble the metrics summary and dashboard export.\n11. Log corrective actions and carryover: Convert every open exception from this cycle into an owned, dated, tracked corrective action, then close the monthly operating cycle on that record: archive the audit trail under retention and seed the next cycle with explicit carry-forward inputs.\n12. Parse the metrics summary and the disposition and exposure logs and list every open exception with its root cause.\n13. Create a corrective-action Issue for each exception with `coach-item-create` — `issue_type` exception, `source` management_identified — for incomplete inspection coverage, an unresolved counterfeit disposition, overdue inspector training, or an unremediated overexposure instance, setting `issue_owner`, `target_remediation_date`, `remediation_plan` (interim mitigation), and `root_cause`; link each Issue to its driving disposition/remediation case or metric and to the anchor Control (Issue↔Control) with `coach-items-link`.\n14. Raise capability-level improvement Issues (`issue_type` opportunity) for systemic gaps (e.g., a chronically understaffed inspection point, or an information category with no defined need-to-know roster), and escalate any regulatory or contractual notification obligation to the accountable owner.\n15. Assemble the corrective-action register. The Supply-Chain Security Lead reviews it and signs off that every open exception is owned, dated, and escalated where required — that sign-off is this cycle's closure.\n16. Export the full operating record with `coach-workflow-export` and archive it in the designated evidence repository under retention controls; record the archive location and reference.\n17. Create carry-forward Issues with `coach-item-create` — `issue_type` exception, `source` management_identified, `issue_owner`, `target_remediation_date` — for open corrective actions, any still-open counterfeit-disposition or overexposure-remediation Issue, and the next inspector-training due date; link each to its source and to the anchor Control (Issue↔Control) with `coach-items-link` so they arrive as explicit inputs to the next cycle.\n18. Update the control execution log with the cycle result and key metrics, confirm the next monthly review is scheduled, and assemble the closure record.\n\n**Record in AssureSwarm**\n- Step document: attach the updated provenance and chain-of-custody register — one row per period receipt with inspection result, authenticity verification, and any disposition outcome — as an XLSX (`coach-document-upload`). There is no Asset/Component item type, so this register document is the authoritative provenance record, matching the inspection-results register attached at the inspection-disposition step.\n- Reconcile against the receiving log (`coach-query-data`).\n- Compute metrics via `coach-query-data`; build the dashboard via `coach-dashboard-create`.\n- Attach the metrics summary and dashboard export (`coach-document-upload`).\n- Create one Issue per open exception (`coach-item-create`; `issue_type` exception, or opportunity for systemic-improvement items; `source` management_identified, `issue_owner`, `target_remediation_date`, `remediation_plan`), linked to its driving case/metric and to the anchor Control (Issue↔Control) via `coach-items-link`; create the carry-forward Issues the same way, linked to source and to the anchor Control.\n- Export and archive the operating record (`coach-workflow-export`).\n- Attach the corrective-action register and the closure record (`coach-document-upload`).\n\n**Exit criteria**\n- Provenance and chain-of-custody are complete and accurate for every period receipt; inspector-training status is recorded as current or refresh-assigned; reconciliation shows zero unmatched receipts.\n- Every metric is computed and shown against its threshold; each out-of-tolerance metric has a named owner; the evidence set for both workstreams is confirmed complete.\n- Every open exception has a named owner and due date; systemic gaps are raised as improvement items; required escalations are routed; the archived record is immutable and retrievable under retention; carry-forward items exist for every open thread; the next monthly cycle is scheduled. The Supply-Chain Security Lead's sign-off on the corrective-action register closes the cycle with nothing untracked.","label":"Log corrective actions and carryover","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-query-data","coach-document-upload","coach-dashboard-create","coach-workflow-export"]}},"id":"log-corrective-actions-and-carryover"}],"sourceTemplateId":"workflow-library:controls-supply-chain-integrity-opsec-operations"}
