How Do I Validate My Document?
Before embarking on a procedure, policy, process, or any type of controls documentation, contact the process librarian so the intended object can be verified and cataloged in the process objects database.
Figure 1. Validate a Process Object
Document Type - Process Profile
The purpose of a process profile is to capture and document essential elements associated with a business process. A process is a series of actions, changes, or functions bringing about a result.
Elements included in a process profile are selected by the process team. Generally, the elements include, but are not limited to:
- Version Control and Change History
- Purpose And Scope
- Associated Control Objectives
- Critical Success Factors
- Performance Indicators - Baseline Performance
- Goals/Measures
- Service Level Considerations
- Related /Source Documents
- Forms And Templates
- Quality Records - Including SQM
- Process Diagram
- Process Deviations and Current State
- Trigger And Exit Criteria
- Acronyms/Definitions
- Safety Issues
- Risk Management Plan
- Process Definition (Inputs and Outputs to Other Processes)
- Status Codes-Metadata
Characteristics of Process
Highest level of abstraction and the lowest level of detail, the High-level set of steps that collectively accomplish a business function: Typically includes sub or component level processes and often used by more than one program or department
Consider whether the following statements are true.
The process flow diagram demonstrates the steps involved in creating any process object. If this is viewed online, the flow includes all process properties in the flow objects. For more information, see Appendix A.
Figure 2. Should I write a process profile?
Where Do I Find the Process Profile Template?
\\...\PAL\Templates\Process Profile Template.dot
Figure 3. What are the steps and controls in writing a process profile?




Whether you're preparing for Cybersecurity certification, working with government standards, or simply starting your career in compliance, these are the NIST Federal Information Processing Standards (FIPS), Special Publication (SP), and Interagency Report (IR) topics