{"description":"Standing operator workflow that runs the quarterly workplace and remote-work security cycle. Each quarterly instance ENRICHES the existing \"Workplace & Remote Work Security\" Process item (process_type: security_process, frequency: quarterly) — never a new one — and links to the three Control items it operates: UC-HR-07 (remote working), UC-PHYS-09, and UC-PHYS-11 (physical / output-device security). Three pillars run in parallel — the office walkthrough (clear-desk, clear-screen, output-device compliance), remote-work attestation verification and enforcement (device, screen privacy, secured environment, encrypted connectivity), and alternate-work-site control review and effectiveness assessment — and reconverge at the cycle-disposition decision, remediating exceptions in-cycle and tracking residual gaps to closure. Named deliverables: the signed walkthrough log and remediation log, the remote-work attestation-and-enforcement register, the alternate-site register and its site-effectiveness assessment, the corrective-action register, and the closure record. In scope: the offices and floors selected for this cycle, the remote-work population due for attestation, and currently approved and in-use alternate work sites. Out of scope: broader physical-security program design, HR remote-work policy authoring, and incident investigation itself. No upstream or downstream workflow feeds this cycle: it is self-seeding — at close it archives the run as the audit trail and hands its own next run a carry-forward package (open corrective-action Issues, the office/floor and alternate-site registers, next-quarter attestation renewals, and next alternate-site review dates) that is the explicit input to the next run.","edges":[{"id":"e-classify-walkthrough-findings-remediate-walkthrough-exceptions","label":"Exceptions","source":"classify-walkthrough-findings","target":"remediate-walkthrough-exceptions","whenValue":"exceptions_found"},{"id":"e-classify-walkthrough-findings-classify-cycle-disposition","label":"Clean","source":"classify-walkthrough-findings","target":"classify-cycle-disposition","whenValue":"clean"},{"id":"e-remediate-walkthrough-exceptions-classify-cycle-disposition","source":"remediate-walkthrough-exceptions","target":"classify-cycle-disposition"},{"id":"e-verify-and-enforce-remote-work-attestations-classify-cycle-disposition","source":"verify-and-enforce-remote-work-attestations","target":"classify-cycle-disposition"},{"id":"e-classify-cycle-disposition-log-corrective-actions","label":"Gaps","source":"classify-cycle-disposition","target":"log-corrective-actions","whenValue":"gaps_identified"},{"id":"e-classify-cycle-disposition-close-and-archive","label":"Healthy","source":"classify-cycle-disposition","target":"close-and-archive","whenValue":"healthy"},{"id":"e-log-corrective-actions-close-and-archive","source":"log-corrective-actions","target":"close-and-archive"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-HR-07","UC-PHYS-09","UC-PHYS-11"],"department":"it","domains":["controls"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=controls-workplace-remote-work-security-cycle","contentDigest":"sha256:9aef76dcd829f33f6e986e62c6a33afd2447bd2084e460e520eb5386cd30eae6","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:9aef76dcd829f33f6e986e62c6a33afd2447bd2084e460e520eb5386cd30eae6","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-workplace-remote-work-security-cycle"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-workplace-remote-work-security-cycle","source":"coworkcanvas-gallery","standards":["nist-800-53","iso-27001"],"teams":["it","hr","facilities"]},"name":"Workplace & Remote Work Security Cycle","nodes":[{"data":{"decisionField":"walkthrough_disposition","description":"Physically observe in-scope offices and judge the evidence-backed exception severity and repeat pattern.","formData":{"fields":[{"key":"walkthrough_disposition","label":"Walkthrough Disposition","options":[{"label":"Clean, no exceptions","value":"clean"},{"label":"Exceptions found","value":"exceptions_found"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Physically observe in-scope offices and judge the evidence-backed exception severity and repeat pattern.\n\n**Inputs**\nThe office/floor register for the offices and floors in scope this cycle — each floor, and every printer, scanner, and output-device location with its intended access-restriction configuration (badge or PIN release).\n- The prior-cycle walkthrough log and any still-open corrective actions carried into this cycle, so repeat locations, devices, and individuals are known going in.\n- The accountable owners for this cycle: Workplace Security Officer (walkthrough), IT security (device configuration), facilities.\n- Standards drivers: ISO 27001 A.7.7 (clear desk / clear screen); NIST 800-53 PE-5 (output device access).\n\n**Decision criteria**\n*The agent prepares the combined evidence and performs the recordkeeping below. Workplace Security Officer owns the stated judgments and authorizations.*\n\n*Conduct workplace walkthrough.* Produce a signed floor-by-floor walkthrough log recording every clear-desk, clear-screen, and output-device observation across the in-scope offices, so sensitive information left exposed at unattended desks, unlocked screens, printers, scanners, or output trays is caught this quarter.\n\n1. Build the floor-by-floor checklist from the office/floor register, listing every desk zone and every printer/scanner/output-device location with its intended release control (badge or PIN).\n2. Walk each in-scope office and floor. For every observation, open a walkthrough-finding record capturing location, type (unattended desk with sensitive material, unlocked idle screen, uncollected printed output in a tray, or a device release not gated by badge/PIN), and the time observed.\n3. Attach supporting photos or field notes to each finding record so the evidence is reperformable by a reviewer who was not present.\n4. For each output device, compare the access-restriction configuration observed on-site against the intended configuration in the register, and mark any mismatch (for example, a printer releasing without a badge tap).\n5. Record the physical observations in the officer’s native workpaper. Private remote-work facts are collected once in the parallel remote-work review; do not create a second request or ask the officer to fill in an executor questionnaire.\n6. Compile the physically observed finding records into the signed walkthrough log. The remote-work register separately records any observable private work area, missing screen lock or encryption, unapproved network, unsecured paper records or undeclared alternate site; the final cycle decision combines both registers without duplicating remote questionnaires.\n\n*Classify walkthrough findings.* Resolve whether this cycle's workplace walkthrough closed clean or produced exceptions that must be remediated in-cycle, owned by the Workplace Security Officer, so nothing exposed carries silently into the next quarter.\n\n\n\nChoose **clean** when the walkthrough log holds zero exceptions: no unattended sensitive material, no unlocked idle screens, and every output device releasing only under badge/PIN as intended.\n- Choose **exceptions_found** when one or more clear-desk, clear-screen, or output-device exceptions exist. Weigh severity in the rationale: an unattended sensitive document outranks an idle unlocked screen, which outranks a minor output-device configuration gap; a repeat location, device, or individual carried from the prior cycle raises severity regardless of type.\n\n**Record in AssureSwarm**\nOne item per observation (walkthrough-finding record) with location, type, and timestamp; link photos or notes to each.\n- Keep the walkthrough log as native executor work and link the separate remote-work register at cycle review. Use authoritative device signals and only unresolved outside-worker private facts to support the remote-work and alternate-site records.\n- Upload the compiled walkthrough log document to this step.\n\nSubmit the `walkthrough_disposition` SELECT (clean | exceptions_found).\n- In the native step result, record the exception count by location, type, and severity, note any repeat offenders versus the prior cycle, and cite the finding records as evidence. Name the decision owner or approver.\n\n**Exit criteria**\nEvery in-scope office and floor walked; every observation captured as a finding record with evidence; remote-work evidence is assigned to the parallel remote-work review, with contradictions tracked there; each output device's actual vs. intended release control compared and mismatches flagged; the compiled log uploaded and confirmed by the Workplace Security Officer to match what was observed on-site.\n\nThe form is submitted with a rationale that traces to the walkthrough log; the unused branch is prunable — a clean disposition drains straight to the cycle-disposition review, while exceptions route through remediation first.","kind":"decision","label":"Classify walkthrough findings","performedBy":{"primitives":["coach-query-data","coach-item-create","coach-document-upload"]}},"id":"classify-walkthrough-findings"},{"data":{"description":"Agent opens an owned remediation item for every exception and re-verifies device fixes; human confirms same-day correction of any exposure","instructions":"**Objective** — Correct every exception the walkthrough found and confirm any exposed sensitive material was secured the same day, producing a remediation log that closes the workplace pillar for this cycle.\n\n**Inputs**\n- The walkthrough-finding records classified as exceptions, with their location, type, and severity.\n- The walkthrough disposition rationale identifying repeat offenders and priority.\n- Device owners (IT security, for release-control reconfiguration) and desk/floor owners for physical corrections.\n\n**Procedure**\n1. For each exception, open a remediation item capturing the owner, the corrective action (collect and secure the document, re-lock or enforce the screen-lock timeout, reconfigure the device release to badge/PIN), and a due date; link each remediation item to its source walkthrough-finding record.\n2. For any exposed sensitive material, escalate to the item owner for immediate same-day collection or secure disposal, and record explicit confirmation of completion with a timestamp.\n3. Once IT security applies an output-device release-control change, re-query the device configuration and confirm it now matches the intended badge/PIN release before closing that item.\n4. For repeat offenders, note the pattern on the remediation item so it can be escalated as a systemic issue at cycle close.\n5. Compile the remediation log linking each exception to its corrective action and completion evidence.\n\n**Record in AssureSwarm**\n- One remediation item per exception, with owner and due date, linked to its finding record.\n- Completion confirmation note and timestamp on same-day exposures; re-verification note on device fixes.\n- Upload the compiled remediation log to this step.\n\n**Exit criteria** — Every exception has a named owner and due date; every exposed sensitive item was collected or secured the same day with recorded confirmation; every output-device fix was re-verified against intended configuration; the remediation log is uploaded and confirmed by the Workplace Security Officer.","label":"Remediate walkthrough exceptions","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-query-data","coach-document-upload"]}},"id":"remediate-walkthrough-exceptions"},{"data":{"description":"Agent collects and cross-checks remote-work attestations against technical enforcement signals; human confirms compliance and that access is restricted for anyone who fails","formData":{"fields":[{"helperText":"For a requested privacy confirmation, unchecked means the workspace is not private. An unsubmitted request remains missing evidence; do not infer a positive answer.","key":"workspace_private","label":"My work area is private enough that screens and calls are not observable by others","required":false,"type":"checkbox"},{"key":"network","label":"Primary work network","options":[{"label":"Home network with WPA2/WPA3 and a changed default password","value":"home_wpa"},{"label":"Shared or co-working network","value":"shared"},{"label":"Public network","value":"public"}],"required":false,"type":"select"},{"helperText":"Enter \"None\" if you hold none.","key":"paper_records","label":"Paper records or removable media holding company data in my workspace","required":false,"type":"textarea"},{"key":"alternate_site","label":"Alternate work locations used this period","type":"text"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Confirm every in-scope remote worker has attested to a policy-required device, screen privacy, secured environment, and encrypted connectivity, that each attestation is backed by a technical enforcement signal, and that access is restricted for anyone non-compliant or unattested — producing the attestation-and-enforcement register for this cycle.\n\n**Inputs**\n- The remote-work population due for quarterly attestation this cycle, drawn from the prior-cycle attestation register and the current HR remote-worker roster.\n- Each worker's technical signals: MDM device-compliance status, VPN or zero-trust encrypted-connectivity enrollment and connection logs, and prior privacy-screen and secured-environment attestations.\n- The remote-work security policy — a Policy item (policy_type: standard, framework: iso-27001 + nist-800-53) — defining the required device standard, screen-privacy control, secured work environment, and encrypted connectivity.\n- Standards drivers: ISO 27001 A.6.7 (remote working); NIST 800-53 AC-17 (remote access).\n\n**Procedure**\n1. Pull the remote-work population due this quarter and, for each worker, their MDM compliance flag, VPN/zero-trust enrollment, and last privacy/environment attestation.\n2. Reuse current authoritative MDM, device-lock, encryption and VPN/zero-trust evidence plus existing private-workspace declarations. For unresolved private facts only, assign the attached request to remote workers outside the full workflow executor and approver roster (including officer, IT, facilities, HR and remediation owners). Identify the specific unknowns and known worker/period context; optional unasked fields may stay blank, but every asked question needs an actual response or a recorded gap. Executors record their own evidence and declarations natively for another authorized reviewer to assess. Do not request technical facts the managed systems already supply.\n3. Cross-reference every attestation against its technical enforcement signal: a \"device compliant\" attestation must be backed by an MDM compliant flag; an \"encrypted connectivity\" attestation by a VPN/zero-trust connection log. Flag any attestation the technical record does not support (attested-but-unenforced).\n4. For every worker who is non-compliant, lacks required evidence, or is attested-but-unenforced, authorized IT staff apply or confirm the policy-required access restriction and independently verify its actual enforcement before allowing access; an Issue alone is not enforcement. Open a remote-access-restriction Issue that names the failing worker in its title and description (there is no Person/worker item type to link to) and link it to the UC-HR-07 Control, so access is held pending remediation.\n5. Compile the attestation-and-enforcement register listing each worker's attestation status, technical signal, and any restriction raised.\n\n**Record in AssureSwarm**\n- Preserve current authoritative device and connectivity evidence, outside-worker responses only for requested missing private facts, and native executor declarations. Record actual access enforcement and independent verification per affected worker.\n- One remote-access-restriction Issue per failing worker — the worker named in the Issue title and description (no Person item type to link) — linked to the UC-HR-07 Control.\n- Upload the attestation-and-enforcement register to this step.\n\n**Exit criteria** — Every in-scope remote worker has current evidence covering the applicable policy pillars or an explicit gap; each technical assertion is corroborated by authoritative signals, and private facts by actual evidence or outside responses; non-compliant, unattested, and attested-but-unenforced workers each have an access-restriction item pending remediation; the register is uploaded and confirmed by the Workplace Security Officer.\n\n**Form recipient** — Only an in-scope remote worker outside all workflow executor and approver roles receives a request, and only for private facts unavailable in current records. Use known identity and period context; record executor contributions in native workpapers/results instead.","label":"Verify and enforce remote-work attestations","performedBy":{"primitives":["coach-query-data","coach-form-create","coach-form-fill","coach-item-create","coach-items-link","coach-document-upload"]}},"id":"verify-and-enforce-remote-work-attestations"},{"data":{"decisionField":"readiness_disposition","description":"Agent refreshes the alternate-work-site register, tests site-control effectiveness and the incident-reporting channel, and computes cycle-health metrics and a dashboard across all three pillars; human classifies the cycle as healthy or gaps-identified","formData":{"fields":[{"key":"readiness_disposition","label":"Readiness Disposition","options":[{"label":"Healthy, within tolerance","value":"healthy"},{"label":"Gaps identified","value":"gaps_identified"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Refresh the approved alternate-work-site register and assess whether its controls and incident-reporting channel actually work, then resolve whether the full cycle — workplace walkthrough, remote-work attestation enforcement, and alternate-site controls — closed within tolerance or carries gaps needing tracked corrective action. This is the join where all three pillars reconverge, and the single human moment is the Workplace Security Officer's disposition call.\n\n**Inputs**\n- The current approved alternate-work-site list (co-working spaces, client sites, secondary offices), each with a last-review date and its required controls (locked storage, screen privacy, no unsecured printing, visitor escort).\n- Workers' declared work locations for this cycle, to detect in-use sites missing from the approved list.\n- The remote-work / alternate-site security policy — a Policy item (policy_type: standard, framework: iso-27001 + nist-800-53) — defining minimum required controls by site type.\n- Effectiveness evidence per in-use site: worker self-assessment responses, site-visit or virtual-inspection notes, and incident or problem reports originating from that site.\n- The incident-reporting channel configuration (monitored mailbox, hotline, service portal) and its reachability requirements.\n- The other two pillars' outputs: the walkthrough log and remediation log, and the remote-work attestation-and-enforcement register.\n- Standards drivers: ISO 27001 A.6.7 (remote working); NIST 800-53 PE-17 (alternate work site).\n\n**Procedure**\n_Items 1–10 are agent-run (folded from the former \"Maintain alternate-site register\" and \"Assess alternate-site effectiveness and reporting channel\" steps); the human moment is the disposition call in item 11._\n1. Pull the approved alternate-work-site list with each site's last-review date and required physical and information-security controls.\n2. Compare the approved list against workers' declared work locations; flag any site in active use that is not on the approved list as an unapproved-site exception for action.\n3. For each approved site whose control requirements are stale (past the review interval), missing, or no longer matching how the site is actually used, draft updated required-control definitions.\n4. Refresh the register so every approved site has a current review date and a clear, complete set of required controls, and every in-use-but-unapproved site is flagged.\n5. For each in-use alternate site, compile the effectiveness evidence: self-assessment responses, inspection notes, and any incidents or problems originating from that site.\n6. Reuse the remote-work responses, site inspections and other current evidence first. Only where a site-control fact or worker knowledge of the reporting path is still unknown, assign a short request for that specific missing fact to a worker at the site who is outside the entire executor/approver roster. Do not repeat questions already answered in the remote-work request. Executors use native workpaper evidence; a worker response never substitutes for the technical reachability test.\n7. Test that the incident-reporting channel is actually reachable from each alternate site's network and device configuration (the mailbox delivers, the hotline connects, the portal loads); record any site where the channel is unreachable.\n8. For each site, conclude whether the required controls are effective, partially effective, or ineffective, citing the evidence, and note any reporting-channel gap.\n9. Compile the effectiveness assessment and reporting-channel confirmation across all in-use sites.\n10. Roll the three pillars together: build the cycle-health dashboard showing each pillar metric against its threshold and the trend versus prior cycles, and list every still-open breach with its owner and evidence.\n11. The Workplace Security Officer reviews the register, the site-effectiveness assessment, and the cycle-health dashboard, and picks the disposition below.\n\n**Decision criteria**\n- Choose **healthy** when every metric across all three pillars is within tolerance with nothing open: all walkthrough exceptions remediated, remote-work attestation and enforcement complete for the in-scope population, every in-use alternate site assessed effective, every site in active use on the approved register, and the incident-reporting channel reachable from every site.\n- Choose **gaps_identified** when any of these remains open: an unremediated walkthrough exception, a non-compliant / unattested / attested-but-unenforced remote worker, a site in use but not on the approved list, an alternate-site control assessed ineffective or partially effective, or an unreachable reporting channel.\n\n**Record in AssureSwarm**\n- Updated required-control definitions on the affected site records; flags on in-use unapproved sites.\n- Preserve site-effectiveness evidence, any narrowly scoped outside-worker missing-fact response and the actual reporting-channel test per site. Record executor assessments and the routing rationale natively.\n- Upload the refreshed alternate-site register and the effectiveness-and-reporting-channel assessment to this step.\n- Submit the `readiness_disposition` SELECT (healthy | gaps_identified).\n- Build the cycle-health dashboard and upload the readiness summary.\n- In the native step result, list every open breach across the three pillars with its owner and evidence, and name the decision owner or approver.\n\n**Exit criteria** — The approved alternate-site register is complete and current, with required controls clearly defined per approved site and every in-use site either approved or flagged; controls are assessed as effective, partially effective, or ineffective at each in-use site with cited evidence, and workers there confirmed a working incident-and-problem reporting channel or the gap is recorded; the register, assessment, dashboard and readiness summary are attached; the form is submitted with a rationale enumerating any open breaches and their owners; the unused branch is prunable — healthy drains straight to close, while gaps route through corrective-action logging first.","kind":"decision","label":"Classify cycle disposition","performedBy":{"primitives":["coach-query-data","coach-dashboard-create","coach-document-upload","coach-form-create","coach-form-fill"]}},"id":"classify-cycle-disposition"},{"data":{"description":"Agent converts each identified gap into an owned corrective action; human confirms every gap is owned, dated, and escalated where required","instructions":"**Objective** — Convert every gap identified at the cycle-disposition review into an owned, dated, tracked corrective action — escalating systemic issues — so nothing degrades the workplace or remote-work security posture unaddressed.\n\n**Inputs**\n- The readiness summary and disposition rationale listing each open breach, its pillar (walkthrough / remote-work attestation / alternate site), and the record that surfaced it.\n- Owners for each pillar and the escalation path for systemic or capability-level issues.\n\n**Procedure**\n1. Parse the readiness summary into a discrete list of gaps, each tagged with its pillar, root cause, and the driving record.\n2. Propose a corrective-action item per gap capturing root cause, owner, due date, and interim mitigation; obtain each accountable owner’s native acceptance before registering the commitment, and link it to the record that drove it.\n3. Raise capability-level improvement items for systemic patterns — for example, a chronically understaffed walkthrough cadence, a stale attestation-enforcement integration where attestations are not backed by MDM/VPN signal, or a recurring unapproved alternate site — and route them to the escalation owner.\n4. Confirm no gap from the readiness summary is left without a corresponding corrective-action item.\n5. Compile the corrective-action register for review.\n\n**Record in AssureSwarm**\n- One corrective-action item per gap (root cause, owner, due date, interim mitigation), linked to its driving record.\n- Capability-level improvement items for systemic issues.\n- Upload the corrective-action register to this step.\n\n**Exit criteria** — Every gap has a named owner and due date; systemic issues are raised as capability-level items and escalated; nothing from the readiness summary is left untracked; the register is uploaded and confirmed by the Workplace Security Officer before closure.","label":"Log corrective actions","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-document-upload"]}},"id":"log-corrective-actions"},{"data":{"description":"Archive the authorized cycle record and carry forward owned open items and renewal dates without a further human sign-off.","instructions":"**Objective** — Close the quarterly operating cycle, preserve the audit trail under retention controls, and seed the next cycle's inputs, so the cycle ends with nothing untracked and the next run starts with explicit carryover.\n\n**Inputs**\n- The signed operating record for the cycle: walkthrough log and remediation log, remote-work attestation-and-enforcement register, alternate-site register and effectiveness assessment, both disposition decisions, and the corrective-action register (when gaps were identified).\n- The evidence repository location and its retention policy; the quarterly review schedule.\n\n**Procedure**\n1. Export the full operating record and archive it in the designated evidence repository under retention controls; record the archive location and reference.\n2. Carry forward existing open items and create only missing schedule entries for the next cycle: open corrective actions, next quarter's remote-work attestation renewals, and each alternate site's next review date; link each to its source record.\n3. Update the control execution log (UC-HR-07, UC-PHYS-09, UC-PHYS-11) with the cycle result and key metrics, and confirm the next quarterly review is scheduled.\n4. Confirm the archived record is immutable and retrievable, and that no item remains open without a tracked owner.\n5. Compile and upload the closure record.\n\n**Record in AssureSwarm**\n- Archived operating record with its recorded location and reference.\n- Carry-forward items (open corrective actions, attestation renewals, next site-review dates) linked to their source records.\n- Control execution log updated; closure record uploaded to this step.\n\n**Exit criteria** — The archived record is immutable and retrievable; the next quarterly review is scheduled; every open item has a tracked owner carried forward; the recorded officer disposition and any required corrective-owner commitments are present; the agent records cycle completion without a new human sign-off.","label":"Close and archive","performedBy":{"primitives":["coach-workflow-export","coach-item-create","coach-items-link","coach-document-upload"]},"requiredApprovals":0},"id":"close-and-archive"}],"sourceTemplateId":"workflow-library:controls-workplace-remote-work-security-cycle"}
