{"catalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","download":{"releaseId":"sha256:56f4d460ec2172652bc4235d954f73627ac76beea09d8a1e37f8b00c06837147","slug":"controls-authorized-software-component-integrity-control","url":"/controls/assets/agent_workflow-controls-authorized-software-component-integrity-control-ccc66fb7.3a79461ee4ad413c.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://assureswarm.com/workflows/all/?w=controls-authorized-software-component-integrity-control","description":"Authorized Software & Component Integrity Control run as a decision-aware monthly cycle that enriches the existing \"Authorized Software & Component Integrity\" Control item in the control library (control_id UC-CONFIG-05/UC-CONFIG-06, frequency monthly, domains secure_configuration_change_management + third_party_supply_chain_risk) — each run is a workflow instance attached to that Control item, never a newly created control. It originates on its own (parallel entry threads consuming the cycle's own software-inventory, catalog/allowlist, install-rights, supplier-intake, and telemetry feeds) and also carries forward the prior cycle's still-open Issue items linked to the same Control. In scope: reconciling installed software across the in-scope endpoints, servers, and system images against the approved catalog and technical allowlist (the discrepancy register), triaging unauthorized installations to catalog-update / removal / escalation, verifying installation rights stay restricted to the authorized-installer roster from trusted sources (the install-rights and trusted-source exception list), tracking usage against license entitlements (the license-position report), and verifying supplier trust and signature integrity for every component acquired this cycle (the component verification register). Named deliverables — the discrepancy register, triage dispositions, catalog/allowlist change record, per-host removal evidence, install-rights and trusted-source exception list, component verification register, blocked-component investigation findings, and license-position report — are archived as the signed monthly cycle record on the workflow instance. Out of scope: incident containment and forensics — any suspected-malicious component is handed off, evidence intact, to the incident-response workflow, which owns that containment; this control cycle does not duplicate it.","details":{"canonicalUrl":"https://assureswarm.com/workflows/all/?w=controls-authorized-software-component-integrity-control","capabilities":[],"controls":["UC-CONFIG-05","UC-CONFIG-06"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:56f4d460ec2172652bc4235d954f73627ac76beea09d8a1e37f8b00c06837147","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-authorized-software-component-integrity-control","standards":["nist-800-53","iso-27001","soc2","nist-csf-2"],"teams":["it"]},"id":"wf:C43","mapUrl":"https://assureswarm.com/controls/?v=1&node=wf%3AC43","slug":"controls-authorized-software-component-integrity-control","sourceIds":["iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Authorized Software & Component Integrity Control","type":"workflow"},"relationships":[{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:124988e2cf6b7833f2dd43b8ea888ec4df7e58583484cb675efdd2decb13400d","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c43-e401f9da.json","sourceId":"wf:C43","targetDetailPath":"/controls/data/v1/records/uc-uc-config-06-31f293f7.json","targetId":"uc:UC-CONFIG-06","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:4eb2e4328a9f90720b3f93ff75430535c2b9fc365c2b0d75d4ca8ad6723578bb","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c43-e401f9da.json","sourceId":"wf:C43","targetDetailPath":"/controls/data/v1/records/uc-uc-config-05-84d5ee43.json","targetId":"uc:UC-CONFIG-05","type":"operates"}],"schemaVersion":1}
