{"description":"Triage a finding, agree the Remediations that will clear it, then validate and approve the closure of each one before closing the finding itself.","edges":[{"id":"e-plan-owner-closure-decision","source":"plan-owner","target":"closure-decision"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-RISK-14"],"department":"risk-management","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-issue-remediation-verification","contentDigest":"sha256:eb09ca81ac511655754f2d0a447ea40841ae72efcf42e3bfb39ce73400e26a0c","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:eb09ca81ac511655754f2d0a447ea40841ae72efcf42e3bfb39ce73400e26a0c","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-issue-remediation-verification"},"lineOfDefense":"monitor","mappingStatus":"mapped","risks":[],"slug":"grc-issue-remediation-verification","source":"coworkcanvas-gallery","standards":["nist-800-53","soc2"],"teams":["risk-management","operations"]},"name":"Issue Remediation and Verification","nodes":[{"data":{"description":"Finding/remediation planning owner: Agree the finding boundary, root cause and exact set of owned corrective actions, including evidence and conditions that will establish resolution.","instructions":"**Objective** — Confirm scope and root cause and agree each separately owned Remediation, its safeguards, delivery expectations and closure criteria.\n\n**Inputs**\nThe linked request or system record, the approved procedure and configuration, and the reviewed outputs of prerequisite steps. Resolve the named operating and approving roles before execution.\n\n**Procedure**\n*Autonomous preparation incorporates Triage Finding and Confirm Root Cause; Finding/remediation planning owner reviews the combined evidence.*\n1. Confirm the finding scope, affected evidence, related control, current risk, and root-cause analysis before agreeing a remediation path.\n2. Break the finding into the discrete corrective actions that will clear it and raise a Remediation record for each, naming its owner, target date, required implementation evidence, interim safeguards and escalation path. Each Remediation carries its own delivery workflow; this step decides what that set is and when the finding can be considered addressed.\n\n**Record in AssureSwarm**\nRecord the actions and evidence examined, their actual dates and source references, the responsible role, the human decision and unresolved exceptions in this step's result. Attach or link the evidence using the supported record and review path. Never record credentials or secret values.\n\n**Exit criteria**\nAgree the finding boundary, root cause and exact set of owned corrective actions, including evidence and conditions that will establish resolution.\nThe procedure's stated checks and authorized human decision are supported by evidence; failed checks or unresolved conditions remain visible with an owner and next action. Approval to execute and approval to close remain separate where the procedure requires them.","kind":"task","label":"Agree the Remediations and Their Owners"},"id":"plan-owner"},{"data":{"description":"Authorized remediation validator and finding closure authority: Apply each Remediation’s own committed validation method, return failures to delivery and approve closure only for validated actions and a fully addressed finding.","instructions":"**Objective** — Collect implementation evidence, validate each linked Remediation against its own method and criteria, and approve the finding’s closure only after every required action is validated and closed.\n\n**Inputs**\nThe linked request or system record, the approved procedure and configuration, and the reviewed outputs of prerequisite steps. Resolve the named operating and approving roles before execution.\n\n**Procedure**\n*Autonomous preparation incorporates Collect Implementation Evidence; Validate Each Linked Remediation; Authorized remediation validator and finding closure authority reviews the combined evidence.*\n1. Collect the implementation records, changed procedures or configuration, retained operating evidence, and any exception disposition the linked Remediations produced, so each can be validated on its own terms rather than as one undifferentiated package.\n2. Take each Remediation linked to this finding in turn and apply the validation method that record names - design retest, operating retest, evidence inspection, reperformance or monitoring. Record the outcome against every closure criterion on that record, not a single verdict for the finding as a whole. Inspecting evidence is not reperforming a control; use the method the record commits to. A Remediation that fails validation returns to its own delivery workflow - a failed validation is a result, not a reason to widen the criteria. Then assess residual risk and document any part of the finding no Remediation covers.\n3. Approve closure of each validated Remediation, then decide the finding itself: close it only where every linked Remediation is validated and closed, and record what remains where any is still open. Record the closure decision, the verification basis, residual risk, linked evidence, and any monitoring required after closure. Where a corrective action changed how a control operates, confirm the operating template reflects the change so the next cycle runs the new way rather than the old.\n\n**Record in AssureSwarm**\nRecord the actions and evidence examined, their actual dates and source references, the responsible role, the human decision and unresolved exceptions in this step's result. Attach or link the evidence using the supported record and review path. Never record credentials or secret values.\n\n**Exit criteria**\nApply each Remediation’s own committed validation method, return failures to delivery and approve closure only for validated actions and a fully addressed finding.\nThe procedure's stated checks and authorized human decision are supported by evidence; failed checks or unresolved conditions remain visible with an owner and next action. Approval to execute and approval to close remain separate where the procedure requires them.","kind":"task","label":"Approve Closure of the Finding"},"id":"closure-decision"}],"sourceTemplateId":"workflow-library:grc-issue-remediation-verification"}
