{"catalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","download":{"releaseId":"sha256:b2b60d5b71524bcba64dfd8b7e013b7e9d84760abf3e6e37c8fc922e9cd462a6","slug":"controls-secure-baseline-integrity-drift-management","url":"/controls/assets/agent_workflow-controls-secure-baseline-integrity-drift-management-cd0cea34.27abf2cc1b578dcc.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://assureswarm.com/workflows/all/?w=controls-secure-baseline-integrity-drift-management","description":"Standing monthly operator workflow for the secure-baseline and integrity-drift cycle: maintain and approve hardening baselines and least-functionality settings against accepted industry standards, run configuration-compliance scanning and remediate drift as findings, triage file-integrity, hash/signature, and secure-boot alerts while verifying security functions self-test correctly, and keep the configuration management plan current annually or after significant environment change. In scope: system components and network security controls governed by CM-2/CM-6/CM-7/CM-9 and SI-6/SI-7 (ISO 27001 A.8.9, PCI DSS Req.1/Req.2, NIST CSF PR.PS-01/DE.CM-09). Out of scope: incident containment and response — unexplained changes are escalated as potentially adverse events to the detect-to-respond incident-analysis practice rather than contained here. Anchor: each monthly run is a recurring workflow instance attached to the EXISTING secure-configuration Control item (the CM-2/CM-6/CM-7 hardening-baseline control — domains=secure_configuration_change_management, frequency=monthly, framework nist-800-53/pci-dss/iso-27001); the cycle enriches that standing Control and never creates a new one. No upstream workflow feeds this cycle — it is self-seeding: its inputs are the prior instance's archived operating record, the approved hardening-baseline standards (Policy items linked to the Control), the open drift/integrity backlog and baseline-reassessment carry-forward (Issue items linked to the anchor Control), and the CM-plan review calendar. Named deliverables: the approved hardening-baseline standards and least-functionality list, the configuration-compliance scan-result register, the integrity-alert and self-test register, drift and corrective-action findings (Issue items linked to the Control), the reviewed configuration management plan (Policy item), the cycle-health dashboard and readiness summary, and the signed, archived cycle operating record. The only cross-workflow handoff is the adverse-event escalation package handed to the detect-to-respond incident-analysis practice.","details":{"canonicalUrl":"https://assureswarm.com/workflows/all/?w=controls-secure-baseline-integrity-drift-management","capabilities":[],"controls":["UC-CONFIG-01","UC-CONFIG-09","UC-VULN-06"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:b2b60d5b71524bcba64dfd8b7e013b7e9d84760abf3e6e37c8fc922e9cd462a6","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-secure-baseline-integrity-drift-management","standards":["nist-800-53","nist-csf-2","pci-dss","iso-27001"],"teams":["it"]},"id":"wf:C42","mapUrl":"https://assureswarm.com/controls/?v=1&node=wf%3AC42","slug":"controls-secure-baseline-integrity-drift-management","sourceIds":["coso-ic","iso-27001","nist-800-53","nist-csf-2","pci-dss","soc2"],"sourceUrl":null,"title":"Secure Baseline & Integrity Drift Management","type":"workflow"},"relationships":[{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:3b26e94b700880beb32e18f95ddf00ad9d0fc5fcc1b55fc76d62f1c7c798eabf","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c42-b0991cdd.json","sourceId":"wf:C42","targetDetailPath":"/controls/data/v1/records/uc-uc-config-09-3da3afe2.json","targetId":"uc:UC-CONFIG-09","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:780969ece294077a0a3eb6766c5c9bec461c5012a735ef1dac1cf1200b143bca","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c42-b0991cdd.json","sourceId":"wf:C42","targetDetailPath":"/controls/data/v1/records/uc-uc-vuln-06-3863b890.json","targetId":"uc:UC-VULN-06","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:c5a0abd0f44091c916d1ebca5f3334bc24ef1624e00e5e6c020616c28f420451","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c42-b0991cdd.json","sourceId":"wf:C42","targetDetailPath":"/controls/data/v1/records/uc-uc-config-01-8f911a32.json","targetId":"uc:UC-CONFIG-01","type":"operates"}],"schemaVersion":1}
