Workspace cues
Sections are operational lanes — evidence and approvals bind here once workflow services connect.
Posture signal scenario
Corporate Headquarters — Elevated Workplace Violence Risk
Boundary · Corporate HQ campus · executive floors · public lobby · parking structures
Corporate Headquarters · Security Plan Workspace
System boundary: Corporate HQ campus · executive floors · public lobby · parking structures
Owner · Corporate Security · Governance · Updated May 7, 2026, 4:10 PM
Scenario workflow traceability
One easy-to-follow thread: assessment findings → living security plan → readiness event or exercise → playbook steps → standards alignment → short leadership summary.
Linked Assessment
RA-HQ-WV-2026-01
Corporate Headquarters — Workplace Violence Risk Assessment
Status language standardized for demo.
Linked SSP
ssp-hq-01
Corporate Headquarters · Security Plan Workspace
Evidence lockers and section readiness gates.
Linked Readiness event
INC-HQ-WV-2026-07
Corporate Headquarters — Workplace Violence Monitoring
Topic under watch with status cadence (placeholder).
Linked Playbook
pb-wv-response-01
Workplace Violence Response
Checklist + escalation triggers + comms templates.
Linked Governance
gov-std-wv-001
Workplace Violence Prevention Standard
Subscription-ready standards + maturity tags.
Linked Report
RPT-QTR-POSTURE-2026-Q2
Quarterly Security Posture Brief
Board-briefing shell aggregates posture.
Linked operational items
Evidence-driven governance ties assessments to control narratives and playbook readiness.
Linked assessment
RA-2025-011
Payments Processing Cell — readiness assessment
Linked assessment
RA-2025-009
Regional distribution center — physical readiness baseline
Linked playbook
pb-ops-disruption-bridge
Operations disruption response bridge
Campus-level continuity event
Linked playbook
pb-vendor-continuity
Critical vendor continuity disruption
Tier-1 facilities services vendor
Stakeholder-facing posture statement and scope boundaries.
Executive Summary
Stakeholder-facing posture statement and scope boundaries. Drafted statements and structured fields bind here. This is intentionally not a document editor — it’s a governance lane with operational evidence anchors.
Evidence locker
Evidence locker · Exec summary
Drop artifacts, cross-links, and control citations to make this section attestable.
Facility footprint, mission alignment, and organizational context.
Site Overview
Facility footprint, mission alignment, and organizational context. Drafted statements and structured fields bind here. This is intentionally not a document editor — it’s a governance lane with operational evidence anchors.
Evidence locker
Evidence locker · Site
Drop artifacts, cross-links, and control citations to make this section attestable.
Mission-critical spaces, services, and dependency registry for the site.
Critical Assets
Mission-critical spaces, services, and dependency registry for the site. Drafted statements and structured fields bind here. This is intentionally not a document editor — it’s a governance lane with operational evidence anchors.
Evidence locker
Evidence pointers · Assets
- ev-022 · Critical asset inventory extract
Operational and physical risk themes, regional context, and site-relevant historical signals.
Threat Landscape
Operational and physical risk themes, regional context, and site-relevant historical signals. Drafted statements and structured fields bind here. This is intentionally not a document editor — it’s a governance lane with operational evidence anchors.
Evidence locker
Evidence locker · Threats
Drop artifacts, cross-links, and control citations to make this section attestable.
Preventive, detective, and corrective measures mapped to architecture.
Security Controls
Control narratives and implementation statements reconcile against the mapping matrix. Inheritance, POA&M linkage, and evidence binding are stubbed.
Control mapping matrix
Obligation traceability — authoritative frameworks attach via catalog integration.
| Control | Framework reference | Coverage | Owner |
|---|---|---|---|
PL-02 Perimeter & lobby monitoring program NIST SP 800-171 · 3.1.12 | NIST SP 800-171 · 3.1.12 | Partial | Security program lead |
AC-03 Physical access provisioning & badging FedRAMP Moderate · AC-3 | FedRAMP Moderate · AC-3 | Full | Facilities security coordinator |
IR-04 Incident assessment & declaration criteria ISO 27001:2022 · A.5.26 | ISO 27001:2022 · A.5.26 | Planned | Crisis Mgmt |
CP-10 Alternate processing for continuity HIPAA · §164.308(a)(7) | HIPAA · §164.308(a)(7) | Gap | BCP Office |
Escalation paths and coordination loops with security, facilities, and crisis partners.
Incident Procedures
This lane is operational by design — incident bridges and communications must align to playbook readiness and governance thresholds.
Linked playbook
pb-ops-disruption-bridge
Operations disruption response bridge
Campus-level continuity event
Linked playbook
pb-vendor-continuity
Critical vendor continuity disruption
Tier-1 facilities services vendor
Continuity, restoration priorities, and alternate processing paths.
Recovery Procedures
Continuity, restoration priorities, and alternate processing paths. Drafted statements and structured fields bind here. This is intentionally not a document editor — it’s a governance lane with operational evidence anchors.
Evidence locker
Evidence locker · Recovery
Drop artifacts, cross-links, and control citations to make this section attestable.
Third-party concentration, assurance artifacts, and exit strategies.
Vendor Dependencies
Third-party concentration, assurance artifacts, and exit strategies. Drafted statements and structured fields bind here. This is intentionally not a document editor — it’s a governance lane with operational evidence anchors.
Evidence locker
Evidence locker · Vendors
Drop artifacts, cross-links, and control citations to make this section attestable.
Framework obligations traceable to controls and evidence artifacts.
Compliance Mapping
Framework obligations traceable to controls and evidence artifacts. Drafted statements and structured fields bind here. This is intentionally not a document editor — it’s a governance lane with operational evidence anchors.
Evidence locker
Evidence locker · Compliance
Drop artifacts, cross-links, and control citations to make this section attestable.
Attestable artifacts, retention posture, and auditor retrieval hooks.
Evidence Attachments
Evidence locker
Evidence attachments (workspace)
This pane becomes the controlled evidence locker: classification labels, checksums, retention gates, and reviewer attestation chains.
Campus perimeter diagram — Rev K
ev-001 · Diagram
Section · security-controlsMay 1, 2026Annual physical security assessment summary
ev-014 · Attestation
Section · evidence-attachmentsApr 12, 2026Critical asset inventory extract
ev-022 · Policy
Section · critical-assetsApr 30, 2026
Reviewer lineage, sign-off packets, and publication gates.
Review & Approval
Reviewer lineage, sign-off packets, and publication gates. Drafted statements and structured fields bind here. This is intentionally not a document editor — it’s a governance lane with operational evidence anchors.
Evidence locker
Evidence locker · Review
Drop artifacts, cross-links, and control citations to make this section attestable.