Activities: Role-Performed Units of Work

Last Audited: 2026-08-14
Tier-2 Authoritative
In Plain Language

An activity is a well-defined unit of work carried out by a specific role. Activities are the building blocks of daily work, transforming input artifacts (like user requirements) into output artifacts (like verified code and test reports). Every activity has clear entry criteria, step-by-step guidance, and exit verification gates, ensuring work is repeatable, measurable, and auditable.

The Anatomy of a Regulated Activity

In NUP, an activity is not an informal calendar meeting or a generic to-do item. It is a formalized, role-performed process step that transforms defined inputs into verified outputs. Every activity consists of four essential components:

1. Responsible Role

A qualified individual or team (e.g. Solutions Architect, QA Engineer) accountable for performing the work.

2. Input Artifacts

The prerequisite baseline documents, user stories, or design specifications required before work starts.

3. Structured Steps

A repeatable, documented procedure following verified engineering or compliance recipes.

4. Output & Verification

Newly produced or updated version-controlled artifacts, validated against formal quality gates.

Activity Breakdown Structure (ABS)

Activities decompose high-level engineering disciplines into granular, assignable work units. For example, within the Software Design & Architecture discipline, activities break down as follows:

📁 DISC-ENG-02: Software Design & Architecture
├── 📄 ACT-02.1: Analyze System Boundary & Interfaces (Role: Solutions Architect)
├── 📄 ACT-02.2: Perform Threat Modeling per STRIDE (Role: Security Architect)
├── 📄 ACT-02.3: Draft Architecture Decision Records (ADRs) (Role: Lead Engineer)
└── 📄 ACT-02.4: Conduct Peer Design Review & Baseline Gate (Role: Review Board)
Draft Activity Work Breakdown Structure

Generate a step-by-step activity breakdown for regulated pull request reviews.

Create a structured Activity Breakdown Structure (ABS) for a regulated code review activity: 1. Entry Criteria (prerequisites before review begins) 2. Role-Performed Steps (author checklist, peer reviewer verification, automated security scans) 3. Exit Verification Criteria (approval thresholds, test evidence capture) 4. Regulatory Traceability (mapping to ISO 27001 Control A.8.28)

Community Discussion & Feedback

Attributed peer feedback and official Netspective architecture notes.

Was this documentation helpful?(100% found this helpful • 0 ratings)

Leave Feedback or Question

○ Loading user info...
0/2000 chars

Discussion (0)

Loading discussion thread...