{"catalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","download":{"releaseId":"sha256:9d420efd98ff3cd738357bd2684ec74af78fd4a28ce827490826519cac427b5d","slug":"controls-system-categorization-planning-authorization","url":"/assets/agent_workflow-controls-system-categorization-planning-authorization-c06df4ca.86f116bf2ede730c.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=controls-system-categorization-planning-authorization","description":"Operator workflow for the system owner and authorizing official to categorize a system by impact and criticality, maintain the approved system security and privacy plan, authorize internal connections, and grant and track authorization to operate, as a decision-aware flow with categorization-approval and authorization branches. In scope: a single system — its impact and criticality categorization, the system security and privacy plan, internal-connection authorization, and the authorization-to-operate decision with reauthorization tracking. Out of scope: the control assessments and testing that feed the authorization risk view (consumed as an input) and enterprise categorization-policy setting; there is no upstream or downstream workflow, so any cross-workflow dependency is declared as a step input rather than routed.","details":{"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=controls-system-categorization-planning-authorization","capabilities":[],"controls":["UC-RISK-18","UC-GOV-18","UC-AUDIT-26"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:9d420efd98ff3cd738357bd2684ec74af78fd4a28ce827490826519cac427b5d","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-system-categorization-planning-authorization","standards":["nist-800-53"],"teams":["it","compliance-legal"]},"download":{"releaseId":"sha256:9d420efd98ff3cd738357bd2684ec74af78fd4a28ce827490826519cac427b5d"},"history":{"digest":"29907a52af1a5da0fa12498ffe14af74bfe20fd62ec0193a7185b5b46dc7da78","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-10-04T21:48:26Z","updatedRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4"},"id":"wf:C24","mapUrl":"https://evidenceflows.com/?v=1&node=wf%3AC24","slug":"controls-system-categorization-planning-authorization","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"System Categorization, Security Planning & Authorization","type":"workflow"},"relationships":[{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:2d426686837ee3a83ab5d4eb309b160dd1831dba8ed91202530b257de1e922b2","properties":{},"sourceDetailPath":"/data/v1/records/wf-c24-000b9f1d.json","sourceId":"wf:C24","targetDetailPath":"/data/v1/records/uc-uc-gov-18-680359d2.json","targetId":"uc:UC-GOV-18","type":"operates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:64ecb25913c9fd315ec017e8b5a042f5449f98d0c168671c93970dee902680a4","properties":{},"sourceDetailPath":"/data/v1/records/wf-c24-000b9f1d.json","sourceId":"wf:C24","targetDetailPath":"/data/v1/records/uc-uc-risk-18-23752e70.json","targetId":"uc:UC-RISK-18","type":"operates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:b7caeed24da4e8e13deb2ffd4774086bfed35722f82b3844ef0bfa8aa2abaa79","properties":{},"sourceDetailPath":"/data/v1/records/wf-c24-000b9f1d.json","sourceId":"wf:C24","targetDetailPath":"/data/v1/records/uc-uc-audit-26-3a91d068.json","targetId":"uc:UC-AUDIT-26","type":"operates"}],"schemaVersion":1}
