workflow

Cybersecurity Assurance Review

Cybersecurity Assurance Review — a CAE-owned assurance engagement that runs on the EXISTING Audit item opened from the audit plan (audit_type=it_audit, status PLANNED, lead_auditor and scope already set): the workflow instance attaches to that item and enriches it end to end, never creating a duplicate engagement record. It covers the three IIA Cybersecurity Topical Requirement domains (governance, risk management, and control activities) over the cyber estate bounded in the engagement memo (in scope: named legal entities, networks, cloud tenants, and OT/ICS where included; out of scope: areas whose assurance is documented as delivered by other engagements), testing against the NIST 800-53 Rev 5 catalog with CSF 2.0 / ISO 27001 as the aggregation frame. It originates from the audit plan (no upstream workflow) and produces the findings register (one four-Cs Issue per finding), the cyber posture summary carrying the per-domain and overall Standard 14.5 conclusions, and the approved engagement package — which it hands to the downstream Audit Report Drafting workflow.

In catalog since 2026-09-17T22:28:00Z · Last changed 2026-10-04T21:48:26Z (791ff2dd3a45)

Record JSON · Open in map · Data retrieval guide

Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.

Attributes

domain
audit
department
internal-audit
lineOfDefense
assure

Details

teams
  • internal-audit
  • it
domains
  • audit
standards
  • iia-2024
  • nist-800-53
sourceTemplateId
workflow-library:audit-cybersecurity-assurance-review
releaseId
sha256:5e8581e8e3eaf54e774bec9c229c3df83fda70ddbd184c7cd0efcf97c904992a
canonicalUrl
https://evidenceflows.com/workflows/all/?w=audit-cybersecurity-assurance-review
capabilities
    mappingStatus
    mapped
    lineOfDefense
    assure
    controls
    • UC-AUDIT-12
    • UC-AUDIT-13
    • UC-AUDIT-16
    • UC-AUDIT-23
    • UC-GOV-15
    • UC-VULN-01
    • UC-LOG-04
    • UC-IR-01
    • UC-BCDR-13
    • UC-LOG-01
    • UC-LOG-03
    • UC-LOG-05
    • UC-LOG-08
    • UC-VULN-05
    • UC-AUDIT-14
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings
          • code
            reliance-basis-incomplete
            title
            Reliance basis is incomplete
            message
            Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.
            missing
            • independence
            • competence
            • evidence
            • recency
            • reliance rationale
            nodeIds

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:5e8581e8e3eaf54e774bec9c229c3df83fda70ddbd184c7cd0efcf97c904992a

            Connections