{"catalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","download":{"releaseId":"sha256:34aca58a1949cc61cbda5f1776993eb0af48461d9776ab5c1babe8a6ce002c0c","slug":"controls-platform-isolation-separation-enforcement","url":"/controls/assets/agent_workflow-controls-platform-isolation-separation-enforcement-b069e776.85f939a0d671b59e.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://assureswarm.com/workflows/all/?w=controls-platform-isolation-separation-enforcement","description":"Platform Isolation & Separation Enforcement as a decision-aware operator workflow. Each semiannual run attaches to the existing platform-isolation Control item — UC-NET-04 (framework nist-800-53, family SC, frequency semi_annual, control_owner = security architect), with sibling Controls UC-NET-05 and UC-NET-06 linked — enriching that standing control with a fresh cycle of evidence rather than creating any new anchor; consecutive instances stack on the same Control as its cycle history. Three verification streams run in parallel — user/system-management/security function and sensitivity-domain separation, shared-resource sanitization and covert-channel bandwidth reduction, and hardware- and software-enforced separation-mechanism integrity — and converge into a single posture review and closure. It consumes the prior cycle's still-open findings (Issue items carried forward on the anchor Control) plus live platform telemetry, and produces named deliverables: the function-and-domain separation matrix, the shared-resource sanitization report, the covert-channel analysis report, the hardware/software-mechanism verification report, a consolidated isolation-posture dashboard and evidence summary, and a signed cycle closure record. In scope: the semiannual verification and corrective-action closure of platform isolation across all in-scope platform components. Out of scope: the platform-engineering re-architecture behind a fix (tracked here as corrective-action Issues, executed by platform engineering) and boundary/network-protection controls owned by their own cycle. No upstream workflow feeds this cycle; its only handoff is downstream to its own next run — open corrective actions are left as OPEN Issue items on the anchor Control and arrive as explicit inputs to the next semiannual instance.","details":{"canonicalUrl":"https://assureswarm.com/workflows/all/?w=controls-platform-isolation-separation-enforcement","capabilities":[],"controls":["UC-NET-04","UC-NET-05","UC-NET-06"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:34aca58a1949cc61cbda5f1776993eb0af48461d9776ab5c1babe8a6ce002c0c","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-platform-isolation-separation-enforcement","standards":["nist-800-53"],"teams":["it"]},"id":"wf:C50","mapUrl":"https://assureswarm.com/controls/?v=1&node=wf%3AC50","slug":"controls-platform-isolation-separation-enforcement","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"Platform Isolation & Separation Enforcement","type":"workflow"},"relationships":[{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:3f95c9a723e1d23219dbfd9f3deeed28cfa4709548b8dc597d4a95a333ea5b11","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c50-4402d67a.json","sourceId":"wf:C50","targetDetailPath":"/controls/data/v1/records/uc-uc-net-05-b8a440f7.json","targetId":"uc:UC-NET-05","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:635338f7e05b03c1d8773471b3f96f488881db9ff56c9eda531c3710b6f80457","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c50-4402d67a.json","sourceId":"wf:C50","targetDetailPath":"/controls/data/v1/records/uc-uc-net-04-d99d6d16.json","targetId":"uc:UC-NET-04","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:94c26cfd5dead60f6a061a1d76c189d2f8243601d9889b4b066291ae1cc8793d","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c50-4402d67a.json","sourceId":"wf:C50","targetDetailPath":"/controls/data/v1/records/uc-uc-net-06-f006626f.json","targetId":"uc:UC-NET-06","type":"operates"}],"schemaVersion":1}
