Processes
What will AGI do for Review and monitor application security controls?
With no child occupations seeded, the score relies entirely on the APQC lens and process description. The top-level category 'Develop and manage IT resilience and risk' establishes a strong baseline for knowledge-work, and the description explicitly names testing and analyzing 'security control for IT applications.' This work happens entirely within software and network environments, driving a highly digital scalar.
A scheduled compliance review, a new application deployment, or an automated threat alert initiates the assessment of application security controls.