{"catalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","download":{"releaseId":"sha256:bf0ef729fa70f1979dd81feb60f1f6006cf80e1e602034d4fe629936f6c967c8","slug":"controls-platform-isolation-separation-enforcement","url":"/assets/agent_workflow-controls-platform-isolation-separation-enforcement-b069e776.627a49dc1c9ef03b.json"},"kind":"record","record":{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=controls-platform-isolation-separation-enforcement","description":"Platform Isolation & Separation Enforcement as a decision-aware operator workflow. Each semiannual run attaches to the existing platform-isolation Control item — UC-NET-04 (framework nist-800-53, family SC, frequency semi_annual, control_owner = security architect), with sibling Controls UC-NET-05 and UC-NET-06 linked — enriching that standing control with a fresh cycle of evidence rather than creating any new anchor; consecutive instances stack on the same Control as its cycle history. Three verification streams run in parallel — user/system-management/security function and sensitivity-domain separation, shared-resource sanitization and covert-channel bandwidth reduction, and hardware- and software-enforced separation-mechanism integrity — and converge into a single posture review and closure. It consumes the prior cycle's still-open findings (Issue items carried forward on the anchor Control) plus live platform telemetry, and produces named deliverables: the function-and-domain separation matrix, the shared-resource sanitization report, the covert-channel analysis report, the hardware/software-mechanism verification report, a consolidated isolation-posture dashboard and evidence summary, and a signed cycle closure record. In scope: the semiannual verification and corrective-action closure of platform isolation across all in-scope platform components. Out of scope: the platform-engineering re-architecture behind a fix (tracked here as corrective-action Issues, executed by platform engineering) and boundary/network-protection controls owned by their own cycle. No upstream workflow feeds this cycle; its only handoff is downstream to its own next run — open corrective actions are left as OPEN Issue items on the anchor Control and arrive as explicit inputs to the next semiannual instance.","details":{"canonicalUrl":"https://evidenceflows.com/workflows/all/?w=controls-platform-isolation-separation-enforcement","capabilities":[],"controls":["UC-NET-04","UC-NET-05","UC-NET-06"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:bf0ef729fa70f1979dd81feb60f1f6006cf80e1e602034d4fe629936f6c967c8","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-platform-isolation-separation-enforcement","standards":["nist-800-53"],"teams":["it"]},"download":{"releaseId":"sha256:bf0ef729fa70f1979dd81feb60f1f6006cf80e1e602034d4fe629936f6c967c8"},"history":{"digest":"3be7a4266d063e9bafb2c74c5f2139822b456a45f7d3cb82d018c7fc85e3c1c4","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-10-04T21:48:26Z","updatedRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4"},"id":"wf:C50","mapUrl":"https://evidenceflows.com/?v=1&node=wf%3AC50","slug":"controls-platform-isolation-separation-enforcement","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"Platform Isolation & Separation Enforcement","type":"workflow"},"relationships":[{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:3f95c9a723e1d23219dbfd9f3deeed28cfa4709548b8dc597d4a95a333ea5b11","properties":{},"sourceDetailPath":"/data/v1/records/wf-c50-4402d67a.json","sourceId":"wf:C50","targetDetailPath":"/data/v1/records/uc-uc-net-05-b8a440f7.json","targetId":"uc:UC-NET-05","type":"operates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:635338f7e05b03c1d8773471b3f96f488881db9ff56c9eda531c3710b6f80457","properties":{},"sourceDetailPath":"/data/v1/records/wf-c50-4402d67a.json","sourceId":"wf:C50","targetDetailPath":"/data/v1/records/uc-uc-net-04-d99d6d16.json","targetId":"uc:UC-NET-04","type":"operates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:94c26cfd5dead60f6a061a1d76c189d2f8243601d9889b4b066291ae1cc8793d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c50-4402d67a.json","sourceId":"wf:C50","targetDetailPath":"/data/v1/records/uc-uc-net-06-f006626f.json","targetId":"uc:UC-NET-06","type":"operates"}],"schemaVersion":1}
