All records
Page 13 of 17. 1677 records.
Browse the catalog · First JSON page
unified
UC-AI-04 — Assess impacts and classify AI systems before deployment
unified
UC-AI-05 — Set responsible AI development objectives and requirements
unified
UC-AI-06 — Maintain AI system technical documentation
unified
UC-AI-07 — Verify, validate, and control AI deployment and changes
unified
UC-AI-08 — Log and monitor AI system behavior in operation
unified
UC-AI-09 — Govern AI data quality, provenance, and preparation
unified
UC-AI-10 — Meet transparency obligations for AI systems
unified
UC-AI-11 — Operate AI concern, incident, and external reporting channels
unified
UC-AI-12 — Enforce responsible and lawful use of AI systems
unified
UC-AI-13 — Assign AI value-chain roles and discharge obligations
unified
UC-AI-14 — Manage responsible AI with suppliers and customers
unified
UC-AI-15 — Fulfill general-purpose AI model provider obligations
unified
UC-AI-16 — Ensure human oversight of AI decisions
unified
UC-AI-17 — Define customer data-use and output-rights policies for AI services
unified
UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse
unified
UC-AI-19 — Constrain agent actions and tool use to authorized scope
unified
UC-AI-20 — Prevent harmful, out-of-scope, hallucinated, and over-exposed AI outputs
unified
UC-AI-21 — Commission independent third-party AI evaluations on a quarterly cadence
unified
UC-AI-22 — Prevent leakage of credentials and secrets through AI systems
unified
UC-AI-23 — Prevent misuse of AI systems for cyber offense and catastrophic harm
unified
UC-AI-24 — Operate an AI quality management system
unified
UC-AI-25 — Guide code-generating systems toward secure patterns and safe dependencies
unified
UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software
unified
UC-ASSET-02 — Inventory data and document processing activities and flows
unified
UC-ASSET-03 — Classify, prioritize, and label information and assets
unified
UC-ASSET-04 — Control storage media through use, storage, and destruction
unified
UC-ASSET-05 — Inventory supplier services and assess critical suppliers
unified
UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems
unified
UC-ASSET-07 — Manage assets through their life cycle and recover them at exit
unified
UC-ASSET-08 — Transfer information securely under defined rules and agreements
unified
UC-ASSET-09 — Receive, analyze, and act on threat and vulnerability intelligence
unified
UC-ASSET-10 — Assess and track changes and exceptions for risk impact
unified
UC-ASSET-11 — Improve security plans and processes from operational lessons
unified
UC-ASSET-12 — Operate scheduled processing, backup, and availability monitoring
unified
UC-AUDIT-01 — Maintain an independent internal audit function
unified
UC-AUDIT-02 — Establish a board-approved internal audit mandate and charter
unified
UC-AUDIT-03 — Ensure board oversight and support of internal audit
unified
UC-AUDIT-04 — Uphold integrity and ethical conduct in internal auditing
unified
UC-AUDIT-05 — Maintain auditor objectivity and disclose impairments
unified
UC-AUDIT-06 — Ensure auditor competency and continuing development
unified
UC-AUDIT-07 — Exercise due professional care and professional skepticism
unified
UC-AUDIT-08 — Protect confidential information obtained in audit work
unified
UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan
unified
UC-AUDIT-10 — Manage internal audit financial, human, and technology resources
unified
UC-AUDIT-11 — Establish audit methodologies and engagement work programs
unified
UC-AUDIT-12 — Plan engagements with risk-based objectives, scope, and criteria
unified
UC-AUDIT-13 — Gather and analyze evidence to develop engagement findings
unified
UC-AUDIT-14 — Evaluate findings and develop recommendations and action plans
unified
UC-AUDIT-15 — Document and supervise engagement work
unified
UC-AUDIT-16 — Communicate final engagement results to stakeholders
unified
UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
unified
UC-AUDIT-18 — Communicate with stakeholders on assurance matters
unified
UC-AUDIT-19 — Operate an audit quality assurance and improvement program
unified
UC-AUDIT-20 — Obtain external quality assessments of internal audit
unified
UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
unified
UC-AUDIT-22 — Review risk strategy and performance with leadership
unified
UC-AUDIT-23 — Coordinate independent assurance reviews across providers
unified
UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements
unified
UC-AUDIT-25 — Maintain quality records and information for internal control
unified
UC-AUDIT-26 — Authorize systems and internal connections before operation
unified
UC-AUDIT-27 — Govern expanded internal audit ERM responsibilities
unified
UC-BCDR-01 — Maintain business continuity and disaster recovery plans
unified
UC-BCDR-02 — Establish and govern an ICT operational resilience framework
unified
UC-BCDR-03 — Back up data and verify restorability
unified
UC-BCDR-04 — Provide redundant and alternate processing, storage, and telecom
unified
UC-BCDR-05 — Manage capacity to meet availability requirements
unified
UC-BCDR-06 — Resolve operational incidents and eliminate root causes
unified
UC-BCDR-07 — Execute recovery plans to restore systems and operations
unified
UC-BCDR-08 — Declare recovery complete and set post-incident norms
unified
UC-BCDR-09 — Communicate recovery status to stakeholders
unified
UC-BCDR-10 — Test recovery capabilities and train contingency personnel
unified
UC-BCDR-11 — Sustain operations via safe modes and alternate mechanisms
unified
UC-BCDR-12 — Operate IT services according to defined procedures
unified
UC-BCDR-13 — Operate continuous security protection services
unified
UC-BCDR-14 — Embed control activities in business processes
unified
UC-BCDR-16 — Participate in cyber threat intelligence sharing
unified
UC-CONFIG-01 — Harden systems to approved secure configuration baselines
unified
UC-CONFIG-02 — Authorize, test, and approve changes before production
unified
UC-CONFIG-03 — Separate environments and protect production data in testing
unified
UC-CONFIG-04 — Build security and privacy into software design and upkeep
unified
UC-CONFIG-05 — Permit only authorized software installation and use
unified
UC-CONFIG-06 — Verify authenticity and integrity of hardware and software
unified
UC-CONFIG-07 — Perform controlled, timely maintenance of systems and hardware
unified
UC-CONFIG-08 — Control maintenance tools, personnel, and remote sessions
unified
UC-CONFIG-09 — Document configuration management policy, plan, and procedures
unified
UC-CONFIG-10 — Map where information resides and how data is processed
unified
UC-CRYPTO-01 — Encrypt data at rest and in transit
unified
UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modules
unified
UC-CRYPTO-03 — Manage cryptographic keys and certificates across their lifecycle
unified
UC-CRYPTO-04 — Protect data in use from unauthorized access
unified
UC-DATA-01 — Process personal data only under a documented lawful basis
unified
UC-DATA-02 — Obtain and honor consent for collection, use, and disclosure
unified
UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessary
unified
UC-DATA-04 — Restrict processing of special categories of personal data
unified
UC-DATA-05 — Provide privacy notices and transparency to data subjects
unified
UC-DATA-06 — Provide data subjects access to their personal data
unified
UC-DATA-07 — Keep personal data accurate and honor correction requests
unified
UC-DATA-08 — Execute deletion and other rights requests within deadlines
unified
UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it
unified
UC-DATA-10 — Protect physical media containing sensitive data