Unified records
Page 1 of 3. 289 records.
Browse the catalog · First JSON page
unified
UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle
unified
UC-ACCESS-02 — Review user access rights periodically
unified
UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties
unified
UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software
unified
UC-ACCESS-05 — Enforce approved authorizations for information and functions
unified
UC-ACCESS-06 — Manage unique identities and identifiers end to end
unified
UC-ACCESS-07 — Proof identities before binding credentials
unified
UC-ACCESS-08 — Manage and protect authenticators across their lifecycle
unified
UC-ACCESS-09 — Authenticate all users with multi-factor authentication
unified
UC-ACCESS-10 — Authenticate devices and services before granting connections
unified
UC-ACCESS-11 — Defend logons against brute-force and anomalous attempts
unified
UC-ACCESS-12 — Lock, limit, and terminate user sessions
unified
UC-ACCESS-13 — Notify users of system terms and previous logon activity
unified
UC-ACCESS-14 — Authorize public content and external information sharing
unified
UC-ACCESS-15 — Design control activities over technology access
unified
UC-ACCESS-16 — Authorize, test, and approve changes and development
unified
UC-ACCESS-17 — Execute, monitor, and recover production processing
unified
UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents
unified
UC-ACCESS-19 — Restrict physical access and maintain environmental safeguards
unified
UC-ACCESS-20 — Ensure complete, accurate, and authorized data processing
unified
UC-ACCESS-21 — Manage subservice organizations supporting the system
unified
UC-AI-01 — Maintain and periodically review the AI policy
unified
UC-AI-02 — Define AI roles, responsibilities, and competencies
unified
UC-AI-03 — Document AI system resources and dependencies
unified
UC-AI-04 — Assess impacts and classify AI systems before deployment
unified
UC-AI-05 — Set responsible AI development objectives and requirements
unified
UC-AI-06 — Maintain AI system technical documentation
unified
UC-AI-07 — Verify, validate, and control AI deployment and changes
unified
UC-AI-08 — Log and monitor AI system behavior in operation
unified
UC-AI-09 — Govern AI data quality, provenance, and preparation
unified
UC-AI-10 — Meet transparency obligations for AI systems
unified
UC-AI-11 — Operate AI concern, incident, and external reporting channels
unified
UC-AI-12 — Enforce responsible and lawful use of AI systems
unified
UC-AI-13 — Assign AI value-chain roles and discharge obligations
unified
UC-AI-14 — Manage responsible AI with suppliers and customers
unified
UC-AI-15 — Fulfill general-purpose AI model provider obligations
unified
UC-AI-16 — Ensure human oversight of AI decisions
unified
UC-AI-17 — Define customer data-use and output-rights policies for AI services
unified
UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse
unified
UC-AI-19 — Constrain agent actions and tool use to authorized scope
unified
UC-AI-20 — Prevent harmful, out-of-scope, hallucinated, and over-exposed AI outputs
unified
UC-AI-21 — Commission independent third-party AI evaluations on a quarterly cadence
unified
UC-AI-22 — Prevent leakage of credentials and secrets through AI systems
unified
UC-AI-23 — Prevent misuse of AI systems for cyber offense and catastrophic harm
unified
UC-AI-24 — Operate an AI quality management system
unified
UC-AI-25 — Guide code-generating systems toward secure patterns and safe dependencies
unified
UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software
unified
UC-ASSET-02 — Inventory data and document processing activities and flows
unified
UC-ASSET-03 — Classify, prioritize, and label information and assets
unified
UC-ASSET-04 — Control storage media through use, storage, and destruction
unified
UC-ASSET-05 — Inventory supplier services and assess critical suppliers
unified
UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems
unified
UC-ASSET-07 — Manage assets through their life cycle and recover them at exit
unified
UC-ASSET-08 — Transfer information securely under defined rules and agreements
unified
UC-ASSET-09 — Receive, analyze, and act on threat and vulnerability intelligence
unified
UC-ASSET-10 — Assess and track changes and exceptions for risk impact
unified
UC-ASSET-11 — Improve security plans and processes from operational lessons
unified
UC-ASSET-12 — Operate scheduled processing, backup, and availability monitoring
unified
UC-AUDIT-01 — Maintain an independent internal audit function
unified
UC-AUDIT-02 — Establish a board-approved internal audit mandate and charter
unified
UC-AUDIT-03 — Ensure board oversight and support of internal audit
unified
UC-AUDIT-04 — Uphold integrity and ethical conduct in internal auditing
unified
UC-AUDIT-05 — Maintain auditor objectivity and disclose impairments
unified
UC-AUDIT-06 — Ensure auditor competency and continuing development
unified
UC-AUDIT-07 — Exercise due professional care and professional skepticism
unified
UC-AUDIT-08 — Protect confidential information obtained in audit work
unified
UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan
unified
UC-AUDIT-10 — Manage internal audit financial, human, and technology resources
unified
UC-AUDIT-11 — Establish audit methodologies and engagement work programs
unified
UC-AUDIT-12 — Plan engagements with risk-based objectives, scope, and criteria
unified
UC-AUDIT-13 — Gather and analyze evidence to develop engagement findings
unified
UC-AUDIT-14 — Evaluate findings and develop recommendations and action plans
unified
UC-AUDIT-15 — Document and supervise engagement work
unified
UC-AUDIT-16 — Communicate final engagement results to stakeholders
unified
UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
unified
UC-AUDIT-18 — Communicate with stakeholders on assurance matters
unified
UC-AUDIT-19 — Operate an audit quality assurance and improvement program
unified
UC-AUDIT-20 — Obtain external quality assessments of internal audit
unified
UC-AUDIT-21 — Assess control effectiveness through testing and monitoring
unified
UC-AUDIT-22 — Review risk strategy and performance with leadership
unified
UC-AUDIT-23 — Coordinate independent assurance reviews across providers
unified
UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements
unified
UC-AUDIT-25 — Maintain quality records and information for internal control
unified
UC-AUDIT-26 — Authorize systems and internal connections before operation
unified
UC-AUDIT-27 — Govern expanded internal audit ERM responsibilities
unified
UC-BCDR-01 — Maintain business continuity and disaster recovery plans
unified
UC-BCDR-02 — Establish and govern an ICT operational resilience framework
unified
UC-BCDR-03 — Back up data and verify restorability
unified
UC-BCDR-04 — Provide redundant and alternate processing, storage, and telecom
unified
UC-BCDR-05 — Manage capacity to meet availability requirements
unified
UC-BCDR-06 — Resolve operational incidents and eliminate root causes
unified
UC-BCDR-07 — Execute recovery plans to restore systems and operations
unified
UC-BCDR-08 — Declare recovery complete and set post-incident norms
unified
UC-BCDR-09 — Communicate recovery status to stakeholders
unified
UC-BCDR-10 — Test recovery capabilities and train contingency personnel
unified
UC-BCDR-11 — Sustain operations via safe modes and alternate mechanisms
unified
UC-BCDR-12 — Operate IT services according to defined procedures
unified
UC-BCDR-13 — Operate continuous security protection services
unified
UC-BCDR-14 — Embed control activities in business processes
unified
UC-BCDR-16 — Participate in cyber threat intelligence sharing