{"catalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","download":{"releaseId":"sha256:a888b24c454491205bba369e73ed0139ce9a3cf388284946ad997285d29dca56","slug":"controls-supply-chain-integrity-opsec-operations","url":"/controls/assets/agent_workflow-controls-supply-chain-integrity-opsec-operations-e6b78df4.95f88dad72e60291.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://assureswarm.com/workflows/all/?w=controls-supply-chain-integrity-opsec-operations","description":"Standing monthly operator workflow run against the existing supply-chain integrity Control item (UC-TPRM-07, frequency=monthly, domains=third_party_supply_chain_risk), with the OPSEC need-to-know Control (UC-TPRM-09) linked as the second in-scope control — enrich these existing Control items, never recreate them; the workflow instance attaches to the anchor Control as the durable operating record. Two concurrent workstreams. In scope: receipt-time tamper-evidence and authenticity inspection of critical systems and components, provenance and chain-of-custody upkeep, suspected-counterfeit disposition (each raised as a finding Issue linked to the anchor Control and the implicated Vendor) with inspector-training refresh where a lapse is found, and the OPSEC need-to-know review of the sensitive supply-chain information register with remediation of any overexposure. Named deliverables: the authenticated provenance and chain-of-custody register, the counterfeit-disposition cases, the OPSEC exposure-review worksheet, and the confirmed need-to-know-restricted disclosure footprint. No upstream workflow feeds this cycle — its inputs are the period's own receiving log and the sensitive supply-chain information register. This is a terminal standing control: procurement and vendor onboarding, contract-level third-party risk assessment, and facility physical security are out of scope, each handled by its own workflow; a substantiated counterfeit or compromised supplier is escalated to the third-party/vendor risk workflow rather than resolved here.","details":{"canonicalUrl":"https://assureswarm.com/workflows/all/?w=controls-supply-chain-integrity-opsec-operations","capabilities":[],"controls":["UC-TPRM-07","UC-TPRM-09"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:a888b24c454491205bba369e73ed0139ce9a3cf388284946ad997285d29dca56","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-supply-chain-integrity-opsec-operations","standards":["nist-800-53","iso-27001"],"teams":["it","procurement"]},"id":"wf:C60","mapUrl":"https://assureswarm.com/controls/?v=1&node=wf%3AC60","slug":"controls-supply-chain-integrity-opsec-operations","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"Supply-Chain Integrity & OPSEC Operations","type":"workflow"},"relationships":[{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:24502ff03a69d28f5d40639734c82e5611e8dafee3afefd29b103fcf579cc256","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c60-62941eb6.json","sourceId":"wf:C60","targetDetailPath":"/controls/data/v1/records/uc-uc-tprm-09-eb9772d0.json","targetId":"uc:UC-TPRM-09","type":"operates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:e9bcf6f06bb517f3f7d07073bf3502c0bb1a581b41df0fd29e61f632524f7f8a","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c60-62941eb6.json","sourceId":"wf:C60","targetDetailPath":"/controls/data/v1/records/uc-uc-tprm-07-c98d7242.json","targetId":"uc:UC-TPRM-07","type":"operates"}],"schemaVersion":1}
