workflow
System Categorization, Security Planning & Authorization
Operator workflow for the system owner and authorizing official to categorize a system by impact and criticality, maintain the approved system security and privacy plan, authorize internal connections, and grant and track authorization to operate, as a decision-aware flow with categorization-approval and authorization branches. In scope: a single system — its impact and criticality categorization, the system security and privacy plan, internal-connection authorization, and the authorization-to-operate decision with reauthorization tracking. Out of scope: the control assessments and testing that feed the authorization risk view (consumed as an input) and enterprise categorization-policy setting; there is no upstream or downstream workflow, so any cross-workflow dependency is declared as a step input rather than routed.
In catalog since 2026-09-17T22:28:00Z · Last changed 2026-10-04T21:48:26Z (791ff2dd3a45)
Record JSON · Open in map · Data retrieval guide
Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.
Attributes
- domain
- controls
- department
- it
- lineOfDefense
- operate
Details
- teams
- it
- compliance-legal
- domains
- controls
- standards
- nist-800-53
- sourceTemplateId
- workflow-library:controls-system-categorization-planning-authorization
- releaseId
- sha256:9d420efd98ff3cd738357bd2684ec74af78fd4a28ce827490826519cac427b5d
- canonicalUrl
- https://evidenceflows.com/workflows/all/?w=controls-system-categorization-planning-authorization
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-RISK-18
- UC-GOV-18
- UC-AUDIT-26
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:9d420efd98ff3cd738357bd2684ec74af78fd4a28ce827490826519cac427b5d
Connections
- System Categorization, Security Planning & Authorization operates UC-GOV-18 — Document and approve system security and privacy plans
- System Categorization, Security Planning & Authorization operates UC-RISK-18 — Categorize systems and components by impact and criticality
- System Categorization, Security Planning & Authorization operates UC-AUDIT-26 — Authorize systems and internal connections before operation