{"catalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","download":{"releaseId":"sha256:e5bce4d7d0bd2ac48f5625d0c4cbb521d09feb8cd9232f576d0ea17b80116570","slug":"controls-security-monitoring-detection-operations","url":"/controls/assets/agent_workflow-controls-security-monitoring-detection-operations-f46a70dc.a40be44d174d41a7.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://assureswarm.com/workflows/all/?w=controls-security-monitoring-detection-operations","description":"Each weekly cycle is a recurring instance attached to the existing continuous security-monitoring Control item (domains: logging_monitoring_detection, control_type: detective, frequency: weekly) — the cycle enriches that standing Control with its operating record, never creating a duplicate control. It consumes the prior cycle's carry-forward (unresolved queue Issues, open watchlist entries, open corrective actions) and the documented continuous-monitoring strategy (a Policy item linked to the Control), and produces named deliverables: the deployment coverage-and-effectiveness assessment, the enriched central SIEM analysis queue, the maintained detection watchlist, and the signed cycle security-status report. In scope: verifying monitoring deployment and effectiveness, working the central SIEM threat-intel analysis queue, triaging flagged anomalies, maintaining the detection watchlist, reporting security status to the defined roles, and verifying continuous protection-service health and tuning across hosts, networks, and applications at both the perimeter and the interior. Out of scope: incident containment, eradication, and recovery — confirmed security events are handed off mid-cycle to the Security Incident Response workflow rather than duplicated here.","details":{"canonicalUrl":"https://assureswarm.com/workflows/all/?w=controls-security-monitoring-detection-operations","capabilities":[],"controls":["UC-LOG-04","UC-LOG-05","UC-BCDR-13"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:e5bce4d7d0bd2ac48f5625d0c4cbb521d09feb8cd9232f576d0ea17b80116570","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-security-monitoring-detection-operations","standards":["nist-csf-2","nist-800-53","iso-27001","soc2"],"teams":["it"]},"id":"wf:C53","mapUrl":"https://assureswarm.com/controls/?v=1&node=wf%3AC53","slug":"controls-security-monitoring-detection-operations","sourceIds":["cobit-2019","iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Security Monitoring & Detection Operations","type":"workflow"},"relationships":[{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:39f18e04d3d5f4f20aebb3067d2197f33a603fe34b15f0c52a85e73ad998d214","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c53-cbf08eb0.json","sourceId":"wf:C53","targetDetailPath":"/controls/data/v1/records/uc-uc-log-05-8f316c34.json","targetId":"uc:UC-LOG-05","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:983a9be40f6813a4d7d516887840738a76058c5de2b25f4daae96ef7fef2886d","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c53-cbf08eb0.json","sourceId":"wf:C53","targetDetailPath":"/controls/data/v1/records/uc-uc-log-04-4bc40d21.json","targetId":"uc:UC-LOG-04","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:d11c5a590a6921ffae253d315bf99e37f47b67b5d281af9679a02896f997f162","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c53-cbf08eb0.json","sourceId":"wf:C53","targetDetailPath":"/controls/data/v1/records/uc-uc-bcdr-13-aa7feb8e.json","targetId":"uc:UC-BCDR-13","type":"operates"}],"schemaVersion":1}
