{"catalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","download":{"releaseId":"sha256:2ea82fce95c0f1a36a1a8ff4d185e3d7ff2a6bfc2faf95ed6695487740ec5c25","slug":"controls-key-management-crypto-review","url":"/assets/agent_workflow-controls-key-management-crypto-review-386c58b8.de2928f1205419cf.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=controls-key-management-crypto-review","description":"Periodic cryptographic key management review as a decision-aware workflow covering inventory, custody, rotation, algorithm strength, and verified remediation. The workflow instance attaches to the existing Audit item opened for this review cycle (audit_type it_audit or compliance; Audit.scope = the review scope statement; Audit.period_start/period_end = the review period; Audit.lead_auditor = the review owner) — enrich that record, never create a duplicate — and it links to the cryptographic Control items under review (domains cryptography_key_management, e.g. UC-CRYPTO-02, UC-CRYPTO-03). In scope: all managed key stores — cloud KMS, HSM partitions, certificate stores, secrets managers, and code-signing infrastructure — across in-scope environments. Out of scope: application-layer data classification and the identity provider, which are covered by their own reviews. No upstream workflow feeds this review; it is triggered by its periodic cadence, an incident, an audit request, or an algorithm-deprecation notice — scope is set on the Audit at kickoff, not handed off. The named deliverables are the signed cryptographic key management attestation (mapped to ISO 27001 A.8.24 and NIST SP 800-53 SC-12/SC-13) and the indexed, redacted evidence package filed against the anchor Audit; there is no downstream handoff workflow.","details":{"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=controls-key-management-crypto-review","capabilities":[],"controls":["UC-CRYPTO-03","UC-CRYPTO-02"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:2ea82fce95c0f1a36a1a8ff4d185e3d7ff2a6bfc2faf95ed6695487740ec5c25","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-key-management-crypto-review","standards":["nist-800-53","iso-27001"],"teams":["it"]},"download":{"releaseId":"sha256:2ea82fce95c0f1a36a1a8ff4d185e3d7ff2a6bfc2faf95ed6695487740ec5c25"},"history":{"digest":"39aab374c22e87e307f39a926084c8dc13f3c28d7e2f94a90ae41a7b2d2624af","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-10-04T21:48:26Z","updatedRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4"},"id":"wf:C18","mapUrl":"https://evidenceflows.com/?v=1&node=wf%3AC18","slug":"controls-key-management-crypto-review","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"Cryptographic Key Management Review","type":"workflow"},"relationships":[{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:41028e6a12818f87ff90dc730bd26db7d7757f5249270ece920529d42ce751fd","properties":{},"sourceDetailPath":"/data/v1/records/wf-c18-ca9e8eba.json","sourceId":"wf:C18","targetDetailPath":"/data/v1/records/uc-uc-crypto-02-9be37a83.json","targetId":"uc:UC-CRYPTO-02","type":"operates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:ed322e411e241abba50f4810b12a82d486be0fa3e964e7ea474959747aa90805","properties":{},"sourceDetailPath":"/data/v1/records/wf-c18-ca9e8eba.json","sourceId":"wf:C18","targetDetailPath":"/data/v1/records/uc-uc-crypto-03-8821a347.json","targetId":"uc:UC-CRYPTO-03","type":"operates"}],"schemaVersion":1}
