{"catalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","download":{"releaseId":"sha256:5cac159c5608c5b61cb33e581c2d64594b9fb4227bae0e17d8b24e9a45659ecf","slug":"controls-malware-email-web-content-defense-operations","url":"/controls/assets/agent_workflow-controls-malware-email-web-content-defense-operations-78d327b4.0426a255ca75bf51.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://assureswarm.com/workflows/all/?w=controls-malware-email-web-content-defense-operations","description":"Standing operator workflow for anti-malware coverage, detection handling, spam and phishing filtering, and mobile-code and website-content control, run on a monthly cadence by the security operations malware defense lead. Each monthly run is a new workflow instance attached to the existing Process item \"Malware, Email & Web Content Defense Operations\" (process_type: security_process, frequency: monthly), with Item relationships to the Control items it operates — UC-VULN-05 (malicious code protection) and UC-NET-13 (mobile code) in the control library (framework: nist-800-53, iso-27001, pci-dss). In scope: every system component commonly affected by malicious software, the email and web filtering entry and exit points, the mobile-code technologies in use, and website category and reputation filtering. Out of scope: endpoint patching and vulnerability remediation, incident response beyond first-line quarantine and alerting, and network firewall rule management. No upstream workflow feeds it: the monthly scope, the in-scope component and channel list, the accountable owners, and the prior-cycle carryover — the previous instance's open Issue items and step documents — are its own initial inputs. It produces the coverage reconciliation report, the detection-and-response log, the mobile-code authorization list, the tuned email/web and website-content filtering packages, a capability-health dashboard, a signed readiness classification, and a corrective-action register. It is terminal by design: rather than hand off to a downstream workflow, the close-and-archive step preserves the signed operating record under retention and loops carry-forward Issue items into the next monthly cycle.","details":{"canonicalUrl":"https://assureswarm.com/workflows/all/?w=controls-malware-email-web-content-defense-operations","capabilities":[],"controls":["UC-VULN-05","UC-NET-13"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:5cac159c5608c5b61cb33e581c2d64594b9fb4227bae0e17d8b24e9a45659ecf","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-malware-email-web-content-defense-operations","standards":["nist-800-53","iso-27001","pci-dss"],"teams":["it"]},"id":"wf:C44","mapUrl":"https://assureswarm.com/controls/?v=1&node=wf%3AC44","slug":"controls-malware-email-web-content-defense-operations","sourceIds":["iso-27001","nist-800-53","pci-dss"],"sourceUrl":null,"title":"Malware, Email & Web Content Defense Operations","type":"workflow"},"relationships":[{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:16145adcf912d6562f3fdbd6c8cac63b3df1e8b6cd132754c583b608f8930bc7","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c44-c8ff29dd.json","sourceId":"wf:C44","targetDetailPath":"/controls/data/v1/records/uc-uc-vuln-05-5870fcee.json","targetId":"uc:UC-VULN-05","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:92574c9f6490a9c26946ae9223b5e2a3b0596de54a898d472215cff4ccc42699","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c44-c8ff29dd.json","sourceId":"wf:C44","targetDetailPath":"/controls/data/v1/records/uc-uc-net-13-df790edf.json","targetId":"uc:UC-NET-13","type":"operates"}],"schemaVersion":1}
