{"catalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","download":{"releaseId":"sha256:e07c17abfa52522bba15426a77a507e56bb55e02328d52bff92a67f2e82f9ac4","slug":"controls-change-release-management-operation","url":"/controls/assets/agent_workflow-controls-change-release-management-operation-f4a540f2.07c26f17e26ed5b8.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://assureswarm.com/workflows/all/?w=controls-change-release-management-operation","description":"Change & Release Management (CAB) as a decision-aware workflow that runs one recurring weekly instance against the EXISTING change-management ITGC Control item in the control library (domains: secure_configuration_change_management; mapped via Control.framework to nist-800-53, cobit-2019, iso-27001, and soc1, alongside the related UC-CONFIG-02/03, UC-ACCESS-16, and UC-SDLC-06/07/08/09 controls) — it enriches that control's operating evidence each cycle, it does not create the control. Upstream it consumes the open change-request queue and the emergency-change log exported from the ticketing system, plus the prior cycle's closure export as its carry-forward backlog. It covers change intake, security and risk impact analysis, environment segregation and configuration-baseline control, acceptance testing, the single CAB authorization gate, the emergency-change path, and controlled deployment with rollback and post-implementation verification — producing the prioritized CAB agenda and authorization packet, per-change risk-assessment memos, the environment-and-baseline verification memo, acceptance-testing summaries, the deployment-and-verification record, and the archived per-cycle evidence set. In scope: application, database, infrastructure, configuration, and procedure changes across development, test, and production environments. Out of scope: authoring the change itself — this workflow governs authorization and release, not development of the underlying code or configuration. Studio ships no native Change Request item type, so per-change records live as lines in step documents and in the workflow instance rather than as items. This is a terminal workflow with no downstream handoff: closure archives the cycle evidence set in place under retention, and the next cycle's intake reads this instance's closure export as its carry-forward source.","details":{"canonicalUrl":"https://assureswarm.com/workflows/all/?w=controls-change-release-management-operation","capabilities":[],"controls":["UC-CONFIG-02","UC-CONFIG-03","UC-ACCESS-16","UC-SDLC-07","UC-SDLC-06","UC-SDLC-08","UC-SDLC-09"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:e07c17abfa52522bba15426a77a507e56bb55e02328d52bff92a67f2e82f9ac4","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-change-release-management-operation","standards":["nist-800-53","cobit-2019","iso-27001","soc1"],"teams":["it","finance"]},"id":"wf:C41","mapUrl":"https://assureswarm.com/controls/?v=1&node=wf%3AC41","slug":"controls-change-release-management-operation","sourceIds":["cobit-2019","iso-27001","nist-800-53","soc1","soc2","sox"],"sourceUrl":null,"title":"Change & Release Management (CAB)","type":"workflow"},"relationships":[{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:31bba5c22a2a5f37c88f8fd9fde19b93fa0dba136c0a76723313abd2158b9621","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/controls/data/v1/records/uc-uc-config-02-175d55b0.json","targetId":"uc:UC-CONFIG-02","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:9fcff12028e176d5c2873539c7d60baa0ea46c4326e0725998744121fab21a9c","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/controls/data/v1/records/uc-uc-access-16-7a8d6d65.json","targetId":"uc:UC-ACCESS-16","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:b022fc233777d25d28095b221559ac0d3cf7e839c8481f82e0d806e22d4686ea","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/controls/data/v1/records/uc-uc-config-03-3a08a2b1.json","targetId":"uc:UC-CONFIG-03","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:c2f5ec1ee219dfe5cf1ab92be5980ca23f2065db7827e4a1cec03981a3f7e9b1","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/controls/data/v1/records/uc-uc-sdlc-08-29ce69df.json","targetId":"uc:UC-SDLC-08","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:c864fa00f5335636be6d821a5f146456add5940d3e01652e7dbc180a471e9624","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/controls/data/v1/records/uc-uc-sdlc-06-c1afc713.json","targetId":"uc:UC-SDLC-06","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:f2c816489faa7b3d7c854a41723a32f75cb9decb7945ab3b3dde36825745dbd2","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/controls/data/v1/records/uc-uc-sdlc-07-22470d8b.json","targetId":"uc:UC-SDLC-07","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:fb95cde5b0511e45ed39f3328947e9546d9b035cf18a4b708c2f28735b86435f","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/controls/data/v1/records/uc-uc-sdlc-09-659d0280.json","targetId":"uc:UC-SDLC-09","type":"operates"}],"schemaVersion":1}
