IT Workflows

Open-source workflows owned by or involving IT. Review the steps, responsibilities and evidence, then download templates for your AssureSwarm instance.

All workflows 212 IT 92 HR 11 Finance 27 Internal Audit 45 Risk Management 32 Compliance & Legal 32 Privacy 11 Procurement 15 Executive 20 AI Governance 11 Facilities 7 Business Operations 9
  • AI Guardrail Configuration & Agent Permission Review — AI Governance; with IT · 5 steps
    Operate the monthly and per-release first-line review of the guardrail stack around every deployed AI agent: confirm the layered input defenses and endpoint limits that screen adversarial input, injection, and jailbreak attempts and prevent scraping and model extraction; diff each agent's tool allow-list, permissions, approval gates, sandboxing, and configuration artifacts against its authorized scope; and check output filters and grounding, secrets redaction, misuse refusals, and secure-code-generation defaults against baseline. Two decisions route over-permissioned agents and guardrail drift through remediation and retest. The cycle closes with a signed guardrail attestation, cycle metrics, and owned remediation actions linked to the anchor Control.
  • AI Operations Monitoring & Incident Response — AI Governance; with IT · 5 steps
    Operate the monthly review of the deployed AI estate: confirm automatic event logging and retention and work performance, anomaly, and drift alerts to closure; verify human-oversight staffing and intervention records; and screen AI uses against intended use and legal prohibitions. Triage reports from the AI concern channels, execute any required incident communications and regulator reporting within mandated timeframes, and retain all resolution records.
  • AI System Development, Data & Deployment Gate — AI Governance; with IT · 7 steps
    Run the release board gate that every new AI system and substantial modification must clear before deployment. The gate approves responsible-AI objectives and per-system requirements before build, governs training, validation, and test data with bias mitigation, executes the pre-deployment impact assessment and EU AI Act risk classification, confirms Annex IV-grade technical documentation, and records verification, validation, and deployment sign-off, with retraining and other changes re-entering the same gate.
  • Audit Logging Coverage & Integrity Operations — IT · 5 steps
    Operate the monthly cycle that verifies audit logging is enabled across systems, applications, and network components against the security-relevant event catalog, validates record content completeness and clock synchronization, and confirms log protection, tamper alerting, and retention against the documented schedule. Each monthly instance attaches to the existing audit-logging Control (UC-LOG-01) in the control library and produces a coverage matrix, record content-completeness results, clock-drift report, and retention and capacity attestation, with every gap logged as an Issue related back to that Control.
  • Authentication Platform & Session Policy Operations — IT · 5 steps
    Monthly authentication-platform operating cycle: verify MFA enforcement and enrollment across remote, privileged, and sensitive-data access, confirm secure log-on and federation channels, defend against brute-force and anomalous logons, and enforce session lock, termination, and concurrent-session limits together with the system-use and last-logon notifications shown at every sign-in.
  • Authorized Software & Component Integrity Control — IT · 7 steps
    Operate the monthly software-estate cycle: reconcile installed software against the approved catalog and allowlist, remove or escalate unauthorized installations, and confirm installation rights stay restricted to authorized personnel from trusted sources with usage tracked against license entitlements. For everything entering the estate, verify supplier trust and signature integrity before installation, blocking and investigating anything that fails.
  • Backup & Recovery Testing — IT · 2 steps
    Test recoverability for a system by performing an actual restoration and measuring the result against recovery objectives.
  • Business Continuity & DR Test Exercise — Business Operations; with IT · 6 steps
    Run one operating cycle of a BC/DR plan-testing control: plan and execute a business continuity or disaster recovery exercise against RTO and RPO objectives, capture gaps as findings, and fold them back into the BC and DR plans.
  • Change & Release Management (CAB) — IT; with Finance · 7 steps
    Operate the weekly Change Advisory Board and the per-change pipeline for every application, database, infrastructure, configuration, and procedure change: request intake, security and risk impact analysis, environment segregation and configuration-baseline verification, acceptance testing, CAB authorization, and controlled deployment with rollback plans and post-implementation verification. Emergency changes follow the expedited path and are ratified at the next CAB, all under one evidence set.
  • Change Request, Approval & Migration — IT · 2 steps
    Move a system change from request through independent testing and approval to production migration, evidencing developer-migrator segregation.
  • Continuous Controls Monitoring (ISCM) Cycle — IT; with Risk Management · 4 steps
    Run recurring control monitoring by collecting metrics, comparing thresholds, triaging degradation, updating POA&M, reporting health, and tuning cadence.
  • Controlled Hardware & System Maintenance — IT; with Facilities · 7 steps
    Operate the maintenance desk that schedules, approves, documents, and reviews hardware and system maintenance, repair, and replacement per manufacturer and organizational requirements, sanitizing equipment before off-site work and verifying security controls after every completion. Control the maintenance tools, personnel, and nonlocal sessions that touch in-scope systems, from inspection and approved-personnel checks to authenticated, recorded, and terminated remote connections.
  • Cryptographic Key Management Review — IT · 3 steps
    Periodic cryptographic hygiene review: inventory keys and certificates, verify custody and rotation, flag weak algorithms, and remediate.
  • CSF 2.0 Profile & Maturity Assessment — IT; with Executive · 5 steps
    Build a controls-scoped CSF Current Profile, Target Profile, Tier assessment, gap plan, and CISO-ready roadmap.
  • Cybersecurity Assurance Review — Internal Audit; with IT · 8 steps
    Run a CAE-owned cybersecurity assurance review on the existing IT-audit engagement item — IIA Topical Requirement coverage tested against NIST 800-53 — producing a four-Cs findings register and a Standard 14.5 posture conclusion for report drafting.
  • Cybersecurity Incident Response — IT · 5 steps
    Operate the controls-scoped detect-to-respond loop from validation through containment, eradication, recovery, POA&M updates, and technical lessons learned.
  • Data Conversion & Migration — IT · 2 steps
    Convert data into a target system with evidenced completeness and accuracy reconciliation between source and target.
  • Data Encryption & In-Use Protection Operations — IT · 5 steps
    Operate the quarterly sweep of data stores and transmission paths against the encryption standard: at-rest encryption or tokenization with minimized retention, strong cryptography and trusted certificates on every open and external channel, and controlled transmission and removable-media movement, with CISO-approved compensating controls kept current where encryption is infeasible. The same cycle verifies data-in-use protections - field masking, process isolation, enclave configurations, identity-scoped access, and memory clearing - on high-sensitivity workloads.
  • Data Governance Council Operations — Business Operations; with Privacy, IT · 6 steps
    Run quarterly data governance and required integrity-board oversight: review charter standing, lifecycle policy, quality and integrity trends and sharing agreements, then approve minutes and report owned actions at the defined interval.
  • Data Retention & Secure Disposal — IT; with Privacy · 4 steps
    Enforce retention schedules each cycle: identify expired data, dispose of it verifiably, and protect and sanitize physical media with certificates of destruction.
  • Deception, Honeytoken & OPSEC Concealment Operations — IT · 6 steps
    Run the standing detection-engineering deception cycle each quarter against the existing deception/OPSEC concealment Control in the control library: deploy, verify, and reposition honeypot/honeynet decoys and honeyclient sandbox detonation ahead of user delivery, and seed, monitor, and test honeytoken, beacon, and watermark taint mechanisms across systems and datasets. In parallel, operate the OPSEC process that identifies critical operational information (captured as Risk items), analyzes adversary collection paths, and deploys concealment and misdirection countermeasures (Control items) on designated systems, handing any confirmed activation to the incident-response workflow with a preserved evidence package rather than duplicating containment.
  • Emergency Change — IT · 2 steps
    Record an emergency change that bypassed normal change control, evidence the elevated access used, and retrospectively test whether the bypass was justified.
  • Employee Offboarding — HR; with IT · 4 steps
    HR authorizes the departure and effective time, IT evidences removal, the manager transfers work and assets, and HR decides closure with residual obligations visible.
  • Employee Onboarding — HR; with IT · 3 steps
    HR and the manager approve joiner facts and entitlements, IT evidences access grants, and HR resolves readiness conditions before recording an active engagement.
  • End-User Computing Inventory & Validation — IT · 2 steps
    Inventory the spreadsheets and end-user tools feeding reporting for a system, and test their access, change, and integrity controls.
  • Endpoint, Media & Information Handling Custody — IT · 5 steps
    Operate the monthly endpoint, media, and information-handling custody desk: verify fleet endpoint safeguards and acceptable-use acknowledgments, review off-premises and external-system use, and keep unneeded ports, I/O devices, and sensors restricted. Run removable media end to end — authorization, classification-based storage, tracked movement, and verified sanitization or destruction with retained certificates — and maintain the information-transfer rulebook and agreements covering electronic, physical-courier, and verbal disclosure.
  • Enterprise GRC Platform Integration Bridge — IT; with Risk Management · 5 steps
    Define mappings, migrate or provision records, run bidirectional sync, monitor health, resolve conflicts, and confirm system-of-record coverage.
  • Environmental & Utility Systems Maintenance — Facilities; with IT · 5 steps
    Run the monthly preventive-maintenance calendar that independently tests and maintains fire and water detection systems, environmental monitoring, emergency power and lighting, protected cabling, and electromagnetic shielding, producing the single maintenance-and-inspection log of test records, service tickets, and alarm-notification checks.
  • Equipment Maintenance, Movement & Marking Control — Facilities; with IT · 7 steps
    Operate the recurring equipment control cycle: run maintenance to manufacturer specification with only authorized personnel and full activity/fault logging, and authorize, monitor, and track every asset delivery, removal, and movement through isolated loading areas. Apply the siting checklist and marking verification at installation or relocation, and tie maintenance, movement, and marking evidence together in the quarterly reconciliation.
  • Facility Access Administration & Monitoring — Facilities; with IT · 6 steps
    Operate continuous facility-access administration: authorize, issue, and periodically review physical credentials, enforce entry controls and visitor escort/logging, and secure, rotate, and revoke keys, combinations, and badges on compromise, termination, or role change. Run the monthly review of surveillance, intrusion-detection output, physical access logs, and visitor records, investigate anomalies, and confirm data-center/protected-asset access and environmental safeguards with facilities.
  • Financial Systems Transaction Integrity Monitoring — Finance; with IT · 6 steps
    Operate the recurring financial-systems transaction-integrity cycle each period on the existing financial-reporting Process — clearing rejected-input and suspense queues, dispositioning automated-processing exceptions, and reconciling interface transfers. Validate system-generated reports and spreadsheets before reliance, with configuration retested on every change and evidence captured as you go.
  • GCP Physical and Environmental Subservice Reliance — IT; with Risk Management · 5 steps
    Evaluate GCP assurance-report scope, physical and environmental controls, exceptions and user responsibilities; record a bounded reliance decision rather than claiming to operate provider facilities.
  • Identity & Authenticator Lifecycle Administration — IT · 6 steps
    Operate the standing identity desk: issue unique identifiers for every user, service, and device from the authoritative source, hold shared-identifier requests to documented approval with compensating controls, and run the monthly sweep that deactivates dormant identifiers and enforces non-reuse. Proof identities proportional to assurance level before binding credentials, then administer the authenticator lifecycle end to end: verified issuance with defaults changed and strength enforced, protected storage, transmission, and entry, embedded-credential checks, and scheduled rotation or compromise- and separation-triggered revocation.
  • Identity Assurance Review — IT · 5 steps
    Review IAL, AAL, and FAL requirements against current identity proofing, authentication, and federation controls, then remediate and validate gaps.
  • Incident & Problem Management — IT · 2 steps
    Record an incident on a system, evidence containment against response targets, and determine root cause with preventive action.
  • Incident Management Lifecycle — Business Operations; with IT, Compliance & Legal · 7 steps
    Assess and govern an incident from its detection clock through verified recovery and approved notifications; determine corrective actions or risk acceptance and retain the evidence, reporting handoff and follow-up schedule.
  • Incident Reporting Channels & Spillage Response — IT; with Compliance & Legal · 7 steps
    Operate the standing incident-reporting capability: run the monitored mailbox, hotline, and service portal with full acknowledgment and triage routing, execute the information-spillage response procedure end to end, and maintain reviewed contacts with authorities and special-interest groups.
  • Incident Response Readiness Program — IT · 6 steps
    Operate the annual incident response readiness cycle against the existing incident-response Control (UC-IR-01, with the training-and-testing Control UC-IR-02 linked to the same instance): maintain the written IR plan — a Policy item whose governed document attaches to it — through designated-management approval and protected distribution to named responders, then deliver role-based IR training and run the scheduled capability test as a readiness Audit. Feed exercise and training gaps back into the plan and training program as corrective-action Issue items, with significant incidents or organizational changes triggering off-cycle runs of the same procedure.
  • Information Security Program Governance Review — IT; with Executive · 6 steps
    Operate the CISO's recurring security program governance review on the standing "Information Security Program Governance" Process item: each quarter enrich the senior-management-approved information security program plan (its Policy item) and keep security roles, authorities, and reporting lines current, and each year deliver the written board report confirming the CISO mandate and run the security workforce competency review, so the program stays approved, resourced, and owned through organizational change.
  • ISMS Internal Audit & Management Review — Internal Audit; with IT, Executive · 6 steps
    Run the ISMS clause 9.2 internal audit and clause 9.3 management review: findings, corrective actions, review inputs, decisions, and follow-up.
  • ISMS Risk Assessment & Treatment Cycle — IT; with Risk Management · 7 steps
    Perform ISO 27005 risk assessment and treatment planning to produce current risks and SoA inputs for ISO 27001 control applicability.
  • ISO 27001 SoA Review & Controls Assessment — IT; with Compliance & Legal · 8 steps
    Review Statement of Applicability decisions, verify implementation evidence, assess controls, remediate gaps, and publish the approved SoA version.
  • IT Asset Inventory & Classification Upkeep — IT · 6 steps
    Run the quarterly cycle that reconciles the authoritative hardware, software, systems, and services inventory against discovery scans and change records, correcting discrepancies and confirming owner, location, and security attributes for every in-scope component. In the same cycle, review and refresh the classification, priority, and labeling of information and associated assets, including on physical media, so both registers stay current for downstream audit, compliance, and security scoping.
  • IT Availability & Resilient Failure Operations — IT · 5 steps
    Operate the monthly IT availability control across the full cycle: monitor scheduled batch jobs and system processing with documented incident and problem resolution, verify backups with periodic restore testing and track processing availability against service expectations, protect network services against denial-of-service events with fail-secure component behavior and alternate communications readiness, and work the mean-time-to-failure replacement queue with verified fail-safe procedures that place failing systems into a known, alerting safe state.
  • IT Governance Objective Review (COBIT) — Executive; with IT · 4 steps
    Assess COBIT capability from evidence and owner interviews, compare it with approved targets and commit improvements where needed; obtain board direction and review actual progress through the closing cadence.
  • IT Operations & Capacity Management Cycle — IT · 5 steps
    Operate the weekly IT operations and capacity management cycle against the standing IT Operations & Capacity Management process — each week a new workflow instance on that Process item executes job scheduling, processing, infrastructure monitoring, and facility management per documented procedure, then reconciles outcomes and corrects any exceptions. Review processing capacity and utilization against forecast demand, trigger capacity additions before thresholds are breached, and confirm priority-based allocation and quotas keep protecting shared resources, with breach alerts routed to responsible personnel. Produces the named evidence set: the weekly operations review minutes, the consolidated exception log, and the capacity-and-utilization report.
  • Job Scheduling & Batch Monitoring — IT · 1 steps
    Review scheduled job execution for a system over a period, evidencing failure detection, escalation, and resolution.
  • Joiner-Mover-Leaver Access Lifecycle — IT; with HR · 6 steps
    Handle joiner, mover, and leaver events end-to-end: provision role-based access, adjust with SoD checks on transfer, and evidence timely removal on exit.
  • Malware, Email & Web Content Defense Operations — IT · 5 steps
    Operate the monthly malicious-content defense cycle: verify centrally managed anti-malware coverage, scanning, signature updates, and tamper protection across every commonly affected component, and review quarantine, alerting, and detection-log handling. Tune email and web filtering for spam and phishing at entry and exit points, and maintain mobile-code technology authorizations and website category and reputation filtering with enforcement-log review.
  • Network & Provider Service Monitoring — IT; with Procurement · 5 steps
    Operate the monthly cycle that keeps network devices hardened and controlled and network-service documentation (security features, service levels, management responsibilities, including outsourced services) current, monitoring delivered services for conformance and addressing deviations. Review external providers' activity, service status, and security-relevant events against contractual obligations through their logs and reports, confirm cross-organizational audit-exchange methods and identity-context preservation, and feed every deviation into a single owned remediation log.
  • Network Segmentation & Boundary Rule Management — IT · 6 steps
    Operate the boundary estate end to end as a quarterly workflow instance on the existing boundary-protection Control: maintain the trust-zone model, gate and implement rule changes to managed interfaces under a deny-by-default baseline, monitor boundary traffic for external threats, and run the quarterly segmentation and rule-set review evidenced by a verified rule-change record log. Enforce label preservation and guard-rule policy at every cross-domain interconnection point so only authorized data types and flow directions pass between security domains.
  • New System Implementation (SDLC) — IT · 2 steps
    Take a new system from control requirements through testing and acceptance to an evidenced go-live readiness decision.
  • NIST RMF System Authorization (ATO) Cycle — IT; with Compliance & Legal · 9 steps
    Move a single information system through the seven RMF phases — prepare, categorize, select, implement, assess, authorize, and monitor — to reach and sustain an authorization-to-operate, producing the FIPS 199 categorization, SSP, SAR, POA&M, and signed ATO letter as one authorization package.
  • Offboarding & Access Revocation — IT · 2 steps
    Revoke a leaver access across every in-scope system within the policy window, evidence each revocation, and approve the revocation record.
  • Onboarding & Access Provisioning — IT · 2 steps
    Provision a joiner access from an approved role profile, evidence each grant, and approve the provisioning record that ITGC access testing samples.
  • Outsourced & Critical-Component Development Oversight — Procurement; with IT · 6 steps
    Each quarter, review every active outsourced and third-party development engagement for secure-development, IP-ownership, and audit-rights contract terms, verify deliverables against requirements with security-testing evidence on file, and screen developers of critical systems before granting development-environment access. Maintain the register of components critical to security or mission and the rationale and assurance evidence behind every specialized or custom development decision made because commercial items could not meet requirements.
  • Periodic User Access Review — IT · 2 steps
    Run a periodic entitlement recertification for a system, evidence reviewer decisions, and confirm that required revocations were executed.
  • Platform Isolation & Separation Enforcement — IT · 5 steps
    Operate the semiannual platform isolation cycle: verify user, system-management, and security functions remain separated across sensitivity domains via partitioning or virtualization, confirm shared resources are cleared or sanitized between users and processes while covert-channel bandwidth stays under threshold, and verify hardware- and software-enforced separation mechanisms keep critical code protected from runtime alteration.
  • Privacy Breach Assessment & Notification — Privacy; with IT · 9 steps
    Assess a personal-data breach handed off from incident response: scope the exposure, decide notifiability against GDPR, US state, and HIPAA clocks, notify regulators and affected individuals on time, and close with a defensible breach-register entry.
  • Privileged Access & Authorization Model Management — IT · 6 steps
    Operate the quarterly privileged-access control cycle: recertify every privileged account against its business justification and time bound, enforce separate accounts for administrators, review logged utility-program use, and process application-allowlist changes so unauthorized software stays blocked. In the same cycle, maintain the role and security-attribute authorization model against organizational change and spot-test that enforcement points across applications, databases, and infrastructure apply approved authorizations to sensitive data, source code, and administrative functions.
  • Privileged Access Review — IT · 2 steps
    Review privileged, service, and emergency accounts on a system for continued business justification, supporting activity, and compensating monitoring.
  • Production Operations & Processing Integrity Cycle — IT; with Finance · 6 steps
    Run the scheduled production-processing cycle, resolve batch and monitoring incidents, verify recoverability and input/output integrity, and certify the evidence with owned carry-forwards.
  • Public Content & External Sharing Authorization — IT; with Compliance & Legal · 5 steps
    Operate the standing publication-authorization capability: verify only trained, designated individuals post to public-facing systems, confirm external information shares carry information-owner authorization consistent with classification and sharing agreements, and run the quarterly sweep that re-verifies the documented no-authentication actions and inspects public content for nonpublic exposure.
  • Resilience & Failover Readiness Verification — IT · 5 steps
    Each quarter, verify that the alternate storage site, alternate processing capability, and diverse telecommunications the organization's recovery objectives depend on remain current, separated from primary-site hazards, and able to assume operations within RTO, and that safe-mode, alternate-communications, and alternate-security-mechanism designs on critical systems are configured and ready. Findings convert into owned corrective actions, with any recovery-time-impacting gap escalated immediately rather than held for end-of-cycle closure.
  • Resilient Architecture & Non-Persistence Operations — IT · 5 steps
    Operate the quarterly non-persistence and resilient-architecture program against the existing NIST 800-53 SI/SC resilience Control: refresh designated non-persistent components and services from known-good trusted sources, purge stale information, verify diverse sourcing and fragmentation of high-value data, and review thin-node, technology-heterogeneity, and distributed processing and storage posture against current threats.
  • Secure Baseline & Integrity Drift Management — IT · 7 steps
    Operate the monthly secure-baseline cycle: maintain and approve hardening baselines and least-functionality settings against accepted industry standards, run configuration-compliance scans and remediate drift as findings, triage file-integrity, hash/signature, and secure-boot alerts while verifying security functions operate correctly, and keep the configuration management plan and procedures current annually or after significant environment change.
  • Secure Connectivity & Network Trust Services Operation — IT · 5 steps
    Operate the quarterly cycle that re-authorizes remote, wireless, and organization-controlled mobile access, sweeps for rogue connections, and verifies session-trust and out-of-band credential-delivery protections. The same cycle confirms DNSSEC-authenticated, fault-tolerant name resolution and clock synchronization to authoritative time sources.
  • Secure Development & Release Security Gate — IT · 7 steps
    Operate the secure-development lifecycle at every release: engineer security and privacy-by-design requirements into the build, execute the documented security test plan with retained evidence against defined acceptance criteria, and verify hardened runtime behavior before production. Between releases, track vulnerability remediation and patching within risk-based timeframes and queue unsupported software for replacement at the quarterly portfolio review.
  • Secure SDLC Phase-Gate Program — IT · 8 steps
    Operate the secure SDLC phase-gate program that every development initiative passes through: chair the intake, requirements, design, and build/release gates against the documented secure development lifecycle, verifying governed scope and security resourcing, approved application-security requirements, secure-architecture review, and secure-coding and trust-boundary input-validation evidence at each stage. Monitor adherence to and performance of the process itself and track every exception to closure.
  • Security & Privacy Architecture Review Board — IT; with Privacy · 9 steps
    Operate the standing Security & Privacy Architecture Review Board: maintain the enterprise, security, and privacy architecture views that describe how systems, information flows, and protections align with mission and strategy, review solution designs and acquisition decisions for architectural alignment, and push approved updates into system security plans and acquisition requirements.
  • Security Awareness Training Campaign — IT; with HR · 4 steps
    Run a security awareness campaign end-to-end: curriculum, launch, completion tracking, phishing simulation, escalation, and effectiveness reporting.
  • Security Control Assessment & POA&M Remediation — IT; with Compliance & Legal · 7 steps
    Enrich the engagement Audit item: assess a system's controls with 800-53A methods, record determinations, open a POA&M Issue per gap, re-validate remediation, and issue the Security Assessment Report (SAR).
  • Security Monitoring & Detection Operations — IT · 7 steps
    Run the SOC's weekly monitoring cycle as a recurring instance on the standing continuous security-monitoring control: verify continuous monitoring is deployed and functioning under the documented strategy across hosts, networks, and applications, and report security status to the defined roles. Work the central SIEM analysis queue to correlate and enrich events with threat intelligence, triage flagged anomalies to genuine security events, and verify the health, coverage, and tuning of the continuous protection services.
  • Security Policy Suite Review — IT; with Compliance & Legal · 6 steps
    Operate the annual (and change-triggered) review cycle for the full security policy suite across eight policy families: secure acquisition, development, configuration-management, and maintenance; asset, media, and physical protection; access control, identification, and personnel security; communications protection and cryptography; security awareness and cyber-hygiene; audit-logging, monitoring, and system integrity; contingency planning and disruption mitigation; and incident response. Each policy is reviewed against current risk and threat inputs, updated, reapproved, and disseminated with communication and acknowledgment tracking captured as one evidence set.
  • SOC 2 Readiness & Evidence Collection — IT; with Compliance & Legal · 5 steps
    Get an already-opened SOC examination Audit engagement audit-ready for SOC 2/SOC 1: map the Control library to each in-scope Trust Services Criterion, close readiness gaps, run the PBC evidence request list with QA, and coordinate the CPA firm — producing the criteria-to-control mapping matrix and gap matrix, the owned PBC request list, the QA'd evidence set, and the cross-referenced PBC response package.
  • SOX ITGC Testing — Internal Audit; with IT, Finance · 8 steps
    Scope and test SOX-relevant ITGCs by referencing the controls-owned 800-53 catalog and test scripts rather than rebuilding procedures.
  • Supply-Chain Integrity & OPSEC Operations — IT; with Procurement · 5 steps
    Operate the standing supply-chain integrity program: inspect each period's critical system and component receipts for tamper-evidence and authenticity, keep provenance and chain-of-custody records current, and disposition suspected counterfeits with inspector-training refresh where lapses appear. In the same monthly cycle, review the register of sensitive supply-chain information to confirm disclosure remains limited to parties with a validated need to know and remediate any overexposure found.
  • System and Third-Party Risk Review — Risk Management; with IT, Procurement · 2 steps
    Evaluate system criticality, data flows, supplier evidence, gaps and compensating controls before accepting its risk posture.
  • System Categorization, Security Planning & Authorization — IT; with Compliance & Legal · 7 steps
    Operate the per-system control — anchored on the existing NIST 800-53 system-authorization Control in the library, one workflow instance per system per authorization cycle — that categorizes each system and its information by confidentiality, integrity, and availability impact with criticality analysis and accountable-official approval, develops and maintains the approved system security and privacy plan (PL-2), authorizes and documents internal system connections (CA-9), and secures the formal authorization-to-operate decision before production use, with reauthorization tracked on frequency and significant change (CA-6). Named deliverables: the security categorization summary and criticality analysis, the system security and privacy plan, the internal-connection authorization register, and the signed authorization-to-operate decision with its plan of action and milestones.
  • System ITGC Operation — IT · 3 steps
    Operate account lifecycle, authentication, recertification, production-change review and vendor-assurance review for one system.
  • Technical Security Testing & Pentest Engagement — IT · 6 steps
    Plan, execute, rate, report, and retest an authorized penetration test on an existing IT-audit engagement record — producing the validated-findings register, the penetration-test report, and a per-control assurance conclusion — mapping each finding to affected controls and secure-design defects and confirming fixes.
  • Technology Investment & Project Risk Governance — Executive; with IT · 7 steps
    The quarterly technology investment board applies defined benefit, cost, and risk criteria to evaluate, prioritize, and monitor the technology and innovation portfolio, taking corrective action where value is not being realized. The cycle carries the annual capital-planning leg that allocates security funding and personnel to the risk strategy and enforces security-risk sections in every project gate from initiation through delivery.
  • Technology Lifecycle & Capacity Review — IT · 6 steps
    Quarterly cycle that reconciles the solution asset record for components, ownership, and licensing, acts on use and cost optimization, and drives components approaching end of support to a replacement or upgrade plan or a documented, risk-accepted compensating control before support lapses. The same cycle monitors solution availability and capacity against current and forecast demand, raises corrective plans for projected shortfalls, and validates that agreed targets were met in the prior period.
  • Threat Intelligence & Insider Threat Program — IT · 7 steps
    Operate the threat program each cycle: ingest and share threat intelligence, run intel-driven hunts, and review insider-threat indicators with a governed response.
  • Transfer & Access Modification — IT · 2 steps
    Modify a mover access for a new role, remove entitlements the prior role no longer justifies, and approve the modification record.
  • User Access Review & Recertification — IT; with Finance · 5 steps
    Quarterly user access review: extract entitlements, certify with managers, revoke and evidence removals across in-scope systems.
  • User Activity & External Exposure Monitoring — IT; with HR · 7 steps
    Operate the monthly cycle of the standing user-activity and external-exposure monitoring control: review captured privileged and remote session activity and personnel technology usage against acceptable-use expectations, restricting access to authorized reviewers and routing findings to HR and legal counsel per the disclosed monitoring terms. In the same cycle, sweep external open-source and dark-web channels for improperly disclosed organizational information, alerting designated personnel and initiating takedown on discovery, with every confirmed finding from both halves recorded as an Issue linked to the control and consolidated into one restricted case log feeding security-event evaluation.
  • Vendor Offboarding & Secure Termination — Procurement; with IT · 8 steps
    Execute a vendor's contractual exit provisions end to end on each relationship termination: revoke all access and credentials, transition the service to its successor, return or verifiably destroy organizational data, securely dispose of dedicated components and tooling using defined techniques, and retain the required post-relationship evidence.
  • Vendor Risk Assessment and Disposition — Procurement; with Risk Management, IT · 2 steps
    Assess the actual supplier's contracts, assurance reports, access, continuity and exit evidence; obtain expert challenge and an authorized reliance disposition.
  • Vendor SOC 1/SOC 2 Report Review & CUEC Mapping — Procurement; with IT · 5 steps
    Review vendor SOC reports, exceptions, CUECs, bridge letters, and reliance conclusions for controls assurance and service-organization dependencies.
  • Vulnerability & Patch Management Cycle — IT · 6 steps
    Recurring vulnerability management cycle: scan, triage by severity, patch on SLA, verify by rescan, and risk-accept residuals with expiry.
  • Workplace & Remote Work Security Cycle — IT; with HR, Facilities · 6 steps
    Operate the quarterly workplace and remote-work security cycle: walk offices for clear-desk, clear-screen, and output-device compliance, and verify and enforce remote-working device, privacy, environment, and connectivity attestations before granting access. Review the approved alternate-work-site list, assess control effectiveness, and confirm workers there have a functioning incident-reporting channel.
Privacy Terms