All records
Page 15 of 17. 1677 records.
Browse the catalog · First JSON page
unified
UC-PHYS-03 — Protect facilities against fire, water, and environmental hazards
unified
UC-PHYS-04 — Site facilities and equipment to minimize hazards and exposure
unified
UC-PHYS-05 — Provide emergency power, lighting, and resilient utilities
unified
UC-PHYS-06 — Protect power and communications cabling from damage and taps
unified
UC-PHYS-07 — Shield systems from electromagnetic leakage and pulse threats
unified
UC-PHYS-08 — Maintain equipment to preserve availability and integrity
unified
UC-PHYS-09 — Prevent information exposure at desks, screens, and outputs
unified
UC-PHYS-10 — Control and track asset delivery, removal, and movement
unified
UC-PHYS-11 — Secure alternate work sites
unified
UC-PHYS-12 — Mark hardware components with handling designations
unified
UC-RISK-01 — Establish and maintain a tailored risk management framework
unified
UC-RISK-02 — Integrate risk management into enterprise processes and projects
unified
UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria
unified
UC-RISK-04 — Define objectives and business context for risk assessment
unified
UC-RISK-05 — Communicate and consult with stakeholders on risk
unified
UC-RISK-06 — Perform periodic enterprise risk assessments
unified
UC-RISK-07 — Identify and analyze risks and opportunities to objectives
unified
UC-RISK-08 — Evaluate and prioritize risks against risk criteria
unified
UC-RISK-09 — Select, plan, and implement risk treatments
unified
UC-RISK-10 — Maintain a risk register and report the portfolio view
unified
UC-RISK-11 — Assess changes that could significantly affect risk and control
unified
UC-RISK-12 — Assess and mitigate fraud risk including management override
unified
UC-RISK-13 — Monitor and review risk management performance
unified
UC-RISK-14 — Track deficiencies to closure with remediation action plans
unified
UC-RISK-15 — Continually improve the risk management program
unified
UC-RISK-16 — Conduct privacy impact assessments for high-risk processing
unified
UC-RISK-17 — Operate threat intelligence and threat hunting
unified
UC-RISK-18 — Categorize systems and components by impact and criticality
unified
UC-SDLC-01 — Follow a secure development lifecycle with approval gates
unified
UC-SDLC-02 — Plan and resource development programs and projects
unified
UC-SDLC-03 — Define and approve security requirements for applications
unified
UC-SDLC-04 — Engineer systems with secure architecture and design
unified
UC-SDLC-05 — Enforce secure coding and input validation standards
unified
UC-SDLC-06 — Maintain configuration control over systems and code
unified
UC-SDLC-07 — Approve, test, and accept changes before production release
unified
UC-SDLC-08 — Maintain current system documentation and knowledge
unified
UC-SDLC-09 — Prepare and train users for new and changed systems
unified
UC-SDLC-10 — Oversee outsourced development and vet developers
unified
UC-SDLC-11 — Apply specialized development to critical components
unified
UC-SDLC-12 — Manage solution assets and retire unsupported components
unified
UC-SDLC-13 — Plan solution availability and capacity
unified
UC-SDLC-14 — Protect production systems during audit testing
unified
UC-TPRM-01 — Operate a third-party security risk management program
unified
UC-TPRM-02 — Perform risk-based due diligence before engaging vendors
unified
UC-TPRM-03 — Bind vendors to security and privacy terms by contract
unified
UC-TPRM-04 — Monitor vendor performance, services, and risk
unified
UC-TPRM-05 — Include suppliers in incident notification and response
unified
UC-TPRM-06 — Manage secure termination and disposal at relationship end
unified
UC-TPRM-07 — Verify component authenticity, provenance, and integrity
unified
UC-TPRM-08 — Govern security of external and cloud service use
unified
UC-TPRM-09 — Protect supply chain information through OPSEC
unified
UC-TRAIN-01 — Deliver security awareness training to all personnel
unified
UC-TRAIN-02 — Train personnel with specialized security roles and duties
unified
UC-TRAIN-03 — Record training completion and measure effectiveness
unified
UC-TRAIN-04 — Communicate control responsibilities and reporting channels
unified
UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence
unified
UC-VULN-02 — Test security through independent penetration exercises
unified
UC-VULN-03 — Remediate identified flaws within defined timeframes
unified
UC-VULN-04 — Test software security during development and acceptance
unified
UC-VULN-05 — Block malware, spam, and phishing across all systems
unified
UC-VULN-06 — Verify software, firmware, and information integrity
unified
UC-VULN-07 — Harden runtime error handling, output filtering, and memory
unified
UC-VULN-08 — Engineer systems to fail predictably and safely
unified
UC-VULN-09 — Employ non-persistence and information-resilience techniques
unified
UC-VULN-11 — Embed taint mechanisms to detect data exfiltration
workflow
Cybersecurity Assurance Review
workflow
Internal Audit Ethics, Objectivity & Competency Program
workflow
Fraud & Forensic Investigation Engagement
workflow
Audit Fieldwork, Findings & Reporting
workflow
ISO 27001 Certification Readiness
workflow
Process Narrative & Walkthrough
workflow
SOC 2 Trust Services Readiness
workflow
Continuous Monitoring & Agent Evaluation
workflow
Fraud Risk Assessment & JE Testing
workflow
ITGC Change & Provisioning Testing
workflow
Substantive Testing & Data Analytics
workflow
Internal Audit Engagement Lifecycle
workflow
Audit Engagement Planning
workflow
Finding Remediation & Action-Plan Monitoring
workflow
Quality Assurance & Improvement Program Cycle
workflow
Audit Report Drafting
workflow
Third-Party Vendor Assurance Engagement
workflow
Internal Audit Charter, Independence & Board Governance Cycle
workflow
Annual Internal Audit Planning & Resource Management
workflow
Monthly Financial Close
workflow
Recruiting and Hiring Decision
workflow
Continuous Controls Monitoring (ISCM) Cycle
workflow
Technical Security Testing & Pentest Engagement
workflow
Vendor SOC 1/SOC 2 Report Review & CUEC Mapping
workflow
User Access Review & Recertification
workflow
Vulnerability & Patch Management Cycle
workflow
Business Continuity & DR Test Exercise
workflow
Security Awareness Training Campaign
workflow
ISMS Internal Audit & Management Review
workflow
SOC 2 Readiness & Evidence Collection
workflow
Cryptographic Key Management Review
workflow
Joiner-Mover-Leaver Access Lifecycle
workflow
CSF 2.0 Profile & Maturity Assessment
workflow
Threat Intelligence & Insider Threat Program
workflow
Data Retention & Secure Disposal