workflow
Technology Investment & Project Risk Governance
Technology Investment & Project Risk Governance as a decision-aware checkpoint graph, run as a recurring workflow instance attached to the existing Process item for the technology-investment / portfolio-governance process (process_type: business_process) — each quarterly board cycle enriches that standing process record rather than creating a new one. In the cycle the investment board refreshes its criteria, scores and prioritizes the technology and innovation portfolio, routes the annual capital-planning leg that allocates security funding to the risk strategy, monitors in-flight value and reprioritizes or terminates where value is not realized, and enforces security-risk sections in every project gate with ERM-linked artifacts. In scope: the quarterly technology investment-board review (always), the annual capital-planning and security-budget leg (when the funding and staffing envelope must be set or re-planned this cycle), and every project stage gate falling due. Out of scope: individual project execution and delivery mechanics and day-to-day security operations. The cycle consumes the ERM cyber-risk register (Risk items, category: cyber_security) and the approved program business cases as standing inputs, and produces a board decision record and evidence pack as its named deliverable. There is no downstream workflow hand-off, so cross-references are recorded as linked records (Issue ↔ Risk) rather than routed onward; the scored portfolio, in-flight programs, and stage-gated projects have no native item type and live as step documents.
In catalog since 2026-09-17T22:28:00Z · Last changed 2026-10-04T21:48:26Z (791ff2dd3a45)
Record JSON · Open in map · Data retrieval guide
Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.
Attributes
- domain
- grc
- department
- executive
- lineOfDefense
- operate
Details
- teams
- executive
- it
- domains
- grc
- standards
- cobit-2019
- nist-csf-2
- iso-31000
- nist-800-53
- sourceTemplateId
- workflow-library:grc-technology-investment-project-risk-governance
- releaseId
- sha256:389ee0c0d9b646364a0a29f9dbd84078626e09a4b85663b75d0b125f47a4ea5c
- canonicalUrl
- https://evidenceflows.com/workflows/all/?w=grc-technology-investment-project-risk-governance
- capabilities
- mappingStatus
- mapped
- lineOfDefense
- operate
- controls
- UC-GOV-13
- UC-GOV-11
- UC-RISK-02
- roleIntegrity
- activityCount
- 0
- ermPhases
- lineRoles
- serviceModes
- warnings
Source
No record-specific source URL is provided.
Download workflow template · Release: sha256:389ee0c0d9b646364a0a29f9dbd84078626e09a4b85663b75d0b125f47a4ea5c
Connections
- Technology Investment & Project Risk Governance operates UC-GOV-11 — Allocate adequate resources and budget for security
- Technology Investment & Project Risk Governance operates UC-GOV-13 — Govern the technology investment portfolio for value
- Technology Investment & Project Risk Governance operates UC-RISK-02 — Integrate risk management into enterprise processes and projects