{"description":"Operator workflow for the system owner and authorizing official to categorize a system by impact and criticality, maintain the approved system security and privacy plan, authorize internal connections, and grant and track authorization to operate, as a decision-aware flow with categorization-approval and authorization branches. In scope: a single system — its impact and criticality categorization, the system security and privacy plan, internal-connection authorization, and the authorization-to-operate decision with reauthorization tracking. Out of scope: the control assessments and testing that feed the authorization risk view (consumed as an input) and enterprise categorization-policy setting; there is no upstream or downstream workflow, so any cross-workflow dependency is declared as a step input rather than routed.","edges":[{"id":"e-approve-categorization-develop-security-privacy-plan","label":"Approved","source":"approve-categorization","target":"develop-security-privacy-plan","whenValue":"approved"},{"id":"e-approve-categorization-reconcile-categorization","label":"Revise","source":"approve-categorization","target":"reconcile-categorization","whenValue":"revision_required"},{"id":"e-reconcile-categorization-develop-security-privacy-plan","source":"reconcile-categorization","target":"develop-security-privacy-plan"},{"id":"e-develop-security-privacy-plan-authorize-internal-connections","source":"develop-security-privacy-plan","target":"authorize-internal-connections"},{"id":"e-authorize-internal-connections-authorize-to-operate","source":"authorize-internal-connections","target":"authorize-to-operate"},{"id":"e-authorize-to-operate-track-reauthorization-and-retain","label":"Authorize","source":"authorize-to-operate","target":"track-reauthorization-and-retain","whenValue":"authorize"},{"id":"e-authorize-to-operate-remediate-and-reauthorize","label":"Conditions","source":"authorize-to-operate","target":"remediate-and-reauthorize","whenValue":"authorize_with_conditions"},{"id":"e-remediate-and-reauthorize-track-reauthorization-and-retain","source":"remediate-and-reauthorize","target":"track-reauthorization-and-retain"},{"id":"e-develop-security-privacy-plan-track-reauthorization-and-retain","source":"develop-security-privacy-plan","target":"track-reauthorization-and-retain"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-RISK-18","UC-GOV-18","UC-AUDIT-26"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-categorization-planning-authorization","contentDigest":"sha256:8a94d321110b8bcc3298d0e3c8954403fa30e2ef9c4f66f96c2d4a62effbe3ec","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:8a94d321110b8bcc3298d0e3c8954403fa30e2ef9c4f66f96c2d4a62effbe3ec","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-system-categorization-planning-authorization"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-system-categorization-planning-authorization","source":"coworkcanvas-gallery","standards":["nist-800-53"],"teams":["it","compliance-legal"]},"name":"System Categorization, Security Planning & Authorization","nodes":[{"data":{"decisionField":"categorization_disposition","description":"Agent determines confidentiality, integrity, and availability impact for each information type, derives the high-water-mark categorization, runs the criticality analysis, and compiles the approval package; human accountable officials decide whether the categorization is approved or must be revised","formData":{"fields":[{"key":"categorization_disposition","label":"Categorization Disposition","options":[{"label":"Approved, proceed to planning","value":"approved"},{"label":"Revision required, recategorize","value":"revision_required"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Produce the system's security categorization (the confidentiality, integrity, and availability impact level for each information type and the aggregate high-water-mark category) with its criticality analysis, and resolve whether the accountable officials accept that determination so the security baseline and plan build on an authorized category, or whether an impact level or the aggregate must be reworked first. Owned by the accountable officials (system owner, with the authorizing official's delegate where applicable) (UC-RISK-18).\n\n**Inputs**\n- The authorization boundary and the information-type and internal-connection inventory established at intake — the components, dependencies, and the information the system processes, stores, and transmits. These are the workflow's initial inputs; there is no upstream workflow feeding this cycle.\n- Data classification and regulatory-sensitivity records, mission-dependence notes, and any prior categorization record for the system, pulled with coach-query-data.\n- The enterprise categorization policy and comparable systems, for the consistency check.\n- The named accountable officials for routing: system owner, information system security officer, privacy officer, and the senior authorizing official.\n- Standards references: NIST SP 800-53 RA-2 (categorization) and RA-9 (criticality analysis); NIST CSF ID.AM; ISO 27001 A.5.9 and A.5.12.\n\n**Procedure**\n_Items 1–7 are agent-run (folded from the former \"Categorize impact and analyze criticality\" step, which carried no separate human touch-point); the human moment is the officials' decision in item 8._\n1. For each information type in scope, determine the confidentiality, integrity, and availability impact as low, moderate, or high, with a one-line documented rationale each — anchor the level in data classification, regulatory sensitivity, and mission dependence (worked example: regulated PII drives confidentiality high; a public reference dataset is confidentiality low but may be integrity moderate).\n2. Derive the overall system security categorization by the high-water mark across all information types — the single highest impact across confidentiality, integrity, and availability drives the aggregate category. Record privacy impact separately wherever personally identifiable information is present.\n3. Map the components, functions, internal and external dependencies, and supply-chain relationships inside the authorization boundary.\n4. Run the criticality analysis: identify critical components, essential functions, and single points of failure, and rank them by the consequence of their compromise or loss measured against the categorization from items 1–2.\n5. Draft the prioritized protection-and-resilience recommendation, tying each critical component to the safeguards and redundancy it warrants (RA-9), and the categorization summary against RA-2 and NIST CSF ID.AM.\n6. Compile the categorization package with coach-query-data (the CIA impact levels, the aggregate category, the criticality analysis, and the rationale) and check it for consistency against the enterprise categorization policy and comparable systems, flagging any under- or over-categorization.\n7. Draft the approval memo stating the decision being asked, and attach and route it with coach-document-upload.\n8. The accountable officials review the package — every CIA impact determination and its justification, the aggregate categorization, the privacy impact, and the critical components, dependencies, and single points of failure — and submit the disposition against the criteria below.\n\n**Decision criteria**\n- Select **approved** when every confidentiality, integrity, and availability impact level is justified, the aggregate high-water-mark categorization is consistent with enterprise categorization policy and comparable systems, the criticality analysis is sound, and no under- or over-categorization remains — planning may proceed on this baseline.\n- Select **revision_required** when any impact determination, the aggregate categorization, or the criticality analysis must be reworked before the plan is developed (worked example: an information type carrying regulated data is categorized moderate when its regulatory sensitivity demands high, or a single point of failure was missed in the criticality analysis).\n\n**Record in AssureSwarm**\n- Submit the `categorization_disposition` SELECT field with the chosen value. Record the rationale and evidence references in the native step result and the named decision owner in the native approval record; the form contains only the routing SELECT.\n- The categorization record has no native item type — capture each CIA impact determination, the aggregate high-water-mark category, the privacy impact, and the supporting rationale in the categorization summary and keep it as a versioned document on this step.\n- Create a Risk item with coach-item-create for each durable criticality finding (category: cyber_security or business_continuity; likelihood and impact set), and link each to the anchor authorization Control with coach-items-link; findings that are not durable risks stay as rows in the criticality-analysis document.\n- Attach the categorization summary, the criticality analysis, and the routed approval memo with coach-document-upload.\n\n**Exit criteria** — Every CIA impact determination is justified, the high-water-mark categorization is complete with privacy impact captured, and the critical components, dependencies, and single points of failure are identified with protection priorities set; the `categorization_disposition` form is submitted with a rationale and named owner; the unused branch is prunable (approved routes straight to plan development, revision_required routes to reconciliation).","kind":"decision","label":"Approve system categorization","performedBy":{"primitives":["coach-query-data","coach-document-upload","coach-item-create","coach-items-link"]}},"id":"approve-categorization"},{"data":{"description":"Agent reworks the categorization to the officials' feedback and re-obtains sign-off; human confirms the revised categorization is now approved","instructions":"**Objective** — Rework the categorization to resolve every point the accountable officials raised so planning proceeds from an approved category and nothing is lost between the rejection and the rework (UC-RISK-18).\n\n**Inputs**\n- The `categorization_disposition` decision record with its revision rationale from the approval checkpoint.\n- The categorization record and its linked criticality findings to be amended.\n\n**Procedure**\n1. Parse the officials' feedback into a discrete list of required changes, each tied to a specific impact determination, the aggregate categorization, or a named criticality finding.\n2. Adjust each contested determination with its updated rationale, keeping the prior value and the reason for change visible so the audit trail shows what moved and why.\n3. Re-derive the aggregate high-water-mark categorization if any single impact level changed, and re-check that the criticality ranking still holds against the revised category.\n4. Re-assemble the corrected package and route it back to the accountable official for confirmation.\n\n**Record in AssureSwarm**\n- Update the categorization record via coach-document-upload as a new versioned document with its change log — it has no native item type, so preserve the prior value and the reason for change in the document, exactly as the categorization step keeps it document-only.\n- Amend any changed Risk criticality finding with coach-item-create as a new version (prior value kept in the rationale), and re-link the revised findings to the anchor authorization Control with coach-items-link.\n- Attach the revised criticality analysis with coach-document-upload.\n\n**Exit criteria** — The accountable official confirms the revised categorization resolves every point raised and is approved; the categorization baseline is stable for plan development.","label":"Reconcile categorization","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"reconcile-categorization"},{"data":{"description":"Approve the category-aligned plan and authorized-purpose assessment, controlled recipients, protection and review cadence.","instructions":"**Objective** — Approve the category-aligned plan and authorized-purpose assessment, controlled recipients, protection and review cadence.\n\n**Inputs**\nThe approved categorization and criticality record (the control baseline is driven by the aggregate impact level).\n- The current plan of record and its revision history, plus the concept-of-operations material, pulled with coach-query-data.\n- Standards reference: NIST SP 800-53 PL-2 (system security and privacy plan).\n\nThe approved plan of record from plan development.\n- The distribution list of authorized personnel and each recipient's basis for access.\n- The defined review interval and, when this cycle is the annual review, the change history since the last review.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. System owner, information system security officer and privacy officer owns the stated judgments and authorizations.*\n\n*Develop security and privacy plan.* Develop or update, and approve, the system security and privacy plan that describes the system fully enough to authorize it — purpose, boundary, operating context, requirements, and controls in place or planned — with its control baseline tied to the approved categorization (UC-GOV-18).\n\n1. Develop or update the plan so it describes the authorized purpose, the authorization boundary, the operating context and concept of operations, the security and privacy requirements, and the controls in place or planned.\n2. Tie the control baseline to the approved categorization: select the baseline for the aggregate impact level and reconcile selected and implemented controls so the baseline matches the category.\n3. Trace every security and privacy requirement to a control that is in place or planned, and flag any requirement with no covering control as a gap for the later plan of action and milestones.\n4. Version the plan so the approved plan and its full revision history are preserved and diffable.\n5. Draft the plan summary against PL-2 for the approvers.\n\n*Distribute, protect, and review plan.* Distribute the approved plan to the people who need it, protect it against unauthorized disclosure and modification, schedule its interval review, and verify the system is used only for its authorized purpose (UC-GOV-18).\n\n6. After the system owner and security/privacy officials approve the exact plan and distribution/protection scope, distribute that version to authorized personnel through controlled access, recording who received it and on what need-to-know basis.\n7. Apply the protection controls that guard the plan against unauthorized disclosure and modification — restrict access, preserve the version of record, and prevent uncontrolled copies.\n8. Schedule the defined-interval review; where this cycle is the annual review, compare the plan against the current system and list the updates the change history requires.\n9. Verify the system is used only for its intended and authorized purposes by comparing observed use against the authorized purpose with coach-query-data, and record any deviation as a finding.\n\n**Record in AssureSwarm**\nThe system security and privacy plan has no native item type — keep the approved plan, with its full revision history, as a versioned document on this step so the plan of record stays diffable.\n- Attach the plan and the PL-2 summary with coach-document-upload.\n\nDistribute through controlled access with coach-document-link, recording recipients and their basis.\n- Attach the distribution log, protection evidence, and the use-verification result with coach-document-upload.\n\n**Exit criteria**\nThe system owner and information system security officer confirm the plan completely and accurately describes purpose, boundary, operating context, requirements, and control-implementation status, and formally approve it as the plan of record, ready to distribute and to authorize connections against.\n\nThe system owner confirms the plan was distributed only to authorized personnel, is protected from unauthorized disclosure and modification, has its next interval review scheduled, and that the system's observed use matches its authorized purpose.","label":"Develop security and privacy plan","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-document-upload"]}},"id":"develop-security-privacy-plan"},{"data":{"description":"Agent documents and authorizes each internal system connection with interface characteristics, requirements, and information communicated; human confirms every connection is authorized before establishment","instructions":"**Objective** — Authorize and fully document every internal system connection before it is established, so no undocumented interface carries data into or out of the system and the plan and the authorized connections stay consistent (UC-AUDIT-26).\n\n**Inputs**\n- The approved security and privacy plan (each connection record links to it).\n- The internal-connection inventory, including any new connection this change introduces, pulled with coach-query-data.\n- Standards reference: NIST SP 800-53 CA-9 (internal system connections).\n\n**Procedure**\n1. Enumerate the internal system connections in and out of the authorization boundary, including any new connection introduced by this change.\n2. For each connection, document the interface characteristics, the security and privacy requirements it must meet, and the nature of the information communicated across it.\n3. Confirm each connection is authorized before establishment; hold any connection that is not yet documented or approved rather than letting it carry data.\n4. Keep the plan and the authorized connections consistent — every documented connection is reflected in the plan and every connection in the plan is documented here.\n\n**Record in AssureSwarm**\n- Connection-authorization records have no native item type — document each connection's interface characteristics, security and privacy requirements, and the information communicated as a row in the internal-connection authorization register, kept as a versioned document on this step so it stays consistent with the plan.\n- Attach the connection register and the authorization request against CA-9 with coach-document-upload.\n\n**Exit criteria** — The system owner and authorizing official confirm every internal connection is authorized before establishment and documented with its interface characteristics, security and privacy requirements, and the information it communicates.","label":"Authorize internal connections","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-items-link","coach-document-upload"]}},"id":"authorize-internal-connections"},{"data":{"decisionField":"authorization_decision","description":"Agent assembles the authorization package and risk summary for the authorizing official; human makes the formal authorization decision","formData":{"fields":[{"key":"authorization_decision","label":"Authorization Decision","options":[{"label":"Authorize to operate","value":"authorize"},{"label":"Authorize with conditions","value":"authorize_with_conditions"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Resolve the senior authorizing official's formal authorization decision that must precede production use, based on the assessed security and privacy risk to organizational operations, assets, and individuals (UC-AUDIT-26). Owned by the senior authorizing official.\n\n**Decision criteria**\n- Select **authorize** when the residual risk across the approved categorization, the security and privacy plan, the control-assessment results, and the authorized internal connections is acceptable for production, with no condition needing tracked remediation.\n- Select **authorize_with_conditions** when authorization is warranted only against specific conditions that must be remediated on a tracked plan of action and milestones (worked example: an open control deficiency with an acceptable interim mitigation) — the system may operate only within those limits.\n\nIf neither permitted authorization criterion is met, withhold authorization, keep production blocked and record the specific gap for the accountable owner; do not choose a favorable value merely to advance.\n\nAgent preparation before the decision: assemble the authorization package with coach-query-data (approved categorization, security and privacy plan, control-assessment results, authorized internal connections, and the residual-risk position); summarize the assessed risk so the decision is made on risk, not paperwork; draft the authorization decision document and propose the reauthorization frequency and the significant-change events that would force early reauthorization (CA-6); attach and route it with coach-document-upload.\n\n**Record in AssureSwarm** — Submit the `authorization_decision` SELECT field with the chosen value. Record the rationale and evidence references in the native result and the authorizing official in the native approval; do not add questionnaire fields to the selector. Mirror the routed package with coach-document-upload.\n\n**Exit criteria** — The `authorization_decision` form is submitted with a rationale and named authorizing official; the unused branch is prunable (authorize routes to recording the decision, authorize_with_conditions routes to condition tracking first).","kind":"decision","label":"Authorize to operate","performedBy":{"primitives":["coach-query-data","coach-document-upload"]}},"id":"authorize-to-operate"},{"data":{"description":"Agent converts each authorization condition into a tracked plan-of-action item with owner and date; human confirms conditions are owned and scheduled before production reliance","instructions":"**Objective** — Capture every condition attached to a conditional authorization as tracked, owned remediation so the authorizing official's limits are honored and none is lost before production reliance (UC-AUDIT-26).\n\n**Inputs**\n- The `authorization_decision` record with its conditions and limitations from the authorization checkpoint.\n- The authorization decision document and the residual-risk summary.\n\n**Procedure**\n1. Parse the authorization decision into each discrete condition and limitation the authorizing official imposed.\n2. For each condition, create an Issue (issue_type: deficiency, source: self_assessment) capturing the deficiency in its description, the severity, the issue_owner, the target_remediation_date, and — as the remediation_plan — the interim mitigation that makes operation acceptable in the meantime. This is the workflow's one clean native fit: a conditional-authorization condition is a self-assessed deficiency, and the plan of action and milestones is the set of these Issues.\n3. Set the conditional-reauthorization checkpoint at which the authorizing official reconsiders the authorization once the conditions are met or a milestone slips.\n4. Track the remediation to closure and surface any slippage against the milestones.\n\n**Record in AssureSwarm**\n- Create one Issue per condition with coach-item-create — issue_type: deficiency, source: self_assessment, severity, issue_owner, target_remediation_date, and remediation_plan = the interim mitigation — and link each to the anchor authorization Control and to the assessment Audit with coach-items-link.\n- Track the remediation to closure with coach-workflow-scan.\n- Attach the full plan of action and milestones with coach-document-upload.\n\n**Exit criteria** — The system owner and authorizing official confirm every condition is captured as a tracked item with a named owner and due date, and the conditional-reauthorization checkpoint is set, before the system is relied on in production.","label":"Track conditions and remediation","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-workflow-scan","coach-document-upload"]}},"id":"remediate-and-reauthorize"},{"data":{"description":"Record the signed decision, calendar and change triggers, retain the package and carry forward every owned condition under the existing authorization.","instructions":"**Objective** — Record the signed decision, calendar and change triggers, retain the package and carry forward every owned condition under the existing authorization.\n\n**Inputs**\nThe `authorization_decision` record and its effective date — arriving directly on the authorize branch, or after conditions are tracked on the conditional branch.\n- The connection-authorization records, and the reauthorization frequency and significant-change events proposed at the authorization decision (CA-6).\n\nThe recorded authorization decision and reauthorization tracking from the record checkpoint.\n- The distribution, protection, and review evidence from the plan-distribution checkpoint.\n- The full package: categorization, criticality analysis, security and privacy plan, connection authorizations, the authorization decision, and any plan of action and milestones.\n\n**Procedure**\n*The agent prepares the combined evidence and performs the recordkeeping below. No additional human intervention owns the stated judgments and authorizations.*\n\n*Record decision and set reauthorization.* Record the authorization decision, set the triggers that will force reauthorization, and retain the authorization and connection documentation under records controls, so the authorization stays current and provable (UC-AUDIT-26).\n\n1. Record the authorization decision and its effective date, and create the reauthorization tracking item carrying both the defined reauthorization frequency and the significant-change events that would force early reauthorization.\n2. Register the reauthorization date on the ongoing-authorization calendar so it surfaces ahead of expiry.\n3. Confirm the authorization decision and the internal-connection documentation are retained under the records-retention controls, recording the retention location and reference.\n\n*Close and archive.* Close the cycle, preserve the complete authorization record under retention controls, and seed the next categorization, plan review, and reauthorization so nothing is left untracked.\n\n4. Export the full authorization record with coach-workflow-export (categorization, criticality analysis, security and privacy plan, connection authorizations, the authorization decision, and any plan of action and milestones) and archive it in the designated evidence repository under retention controls, recording the archive location and reference.\n5. Create carry-forward items for the annual plan-review date, the reauthorization date, and any open plan-of-action items, so each arrives as an explicit input to the next cycle.\n6. Update the control execution log with the cycle result, the categorization, and the authorization outcome, and confirm the next cadence review is scheduled.\n\n**Record in AssureSwarm**\nThe reauthorization tracking record has no native item type — record the authorization decision, its effective date, the reauthorization frequency, and the significant-change triggers, and keep them as a versioned document on this step.\n- Attach the recorded decision, the reauthorization schedule, and the retention confirmation with coach-document-upload.\n\nExport and archive the record with coach-workflow-export.\n- Create the carry-forward items with coach-item-create and link them to their source with coach-items-link.\n- Attach the closure record with coach-document-upload.\n\n**Exit criteria**\nThe existing signed decision is recorded, reauthorization frequency and significant-change triggers are set, the date is on the calendar and documentation is retained; failed recording checks remain open with the system owner without a new approval.\n\nThe archived package is immutable and retrievable, the next plan review and reauthorization are scheduled and every open item has a tracked owner; record completion under the existing authorization with no separate closure declaration.","label":"Record decision and set reauthorization","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload","coach-workflow-export"]},"requiredApprovals":0},"id":"track-reauthorization-and-retain"}],"sourceTemplateId":"workflow-library:controls-system-categorization-planning-authorization"}
