Unified records
Page 2 of 3. 289 records.
Browse the catalog · First JSON page
unified
UC-CONFIG-01 — Harden systems to approved secure configuration baselines
unified
UC-CONFIG-02 — Authorize, test, and approve changes before production
unified
UC-CONFIG-03 — Separate environments and protect production data in testing
unified
UC-CONFIG-04 — Build security and privacy into software design and upkeep
unified
UC-CONFIG-05 — Permit only authorized software installation and use
unified
UC-CONFIG-06 — Verify authenticity and integrity of hardware and software
unified
UC-CONFIG-07 — Perform controlled, timely maintenance of systems and hardware
unified
UC-CONFIG-08 — Control maintenance tools, personnel, and remote sessions
unified
UC-CONFIG-09 — Document configuration management policy, plan, and procedures
unified
UC-CONFIG-10 — Map where information resides and how data is processed
unified
UC-CRYPTO-01 — Encrypt data at rest and in transit
unified
UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modules
unified
UC-CRYPTO-03 — Manage cryptographic keys and certificates across their lifecycle
unified
UC-CRYPTO-04 — Protect data in use from unauthorized access
unified
UC-DATA-01 — Process personal data only under a documented lawful basis
unified
UC-DATA-02 — Obtain and honor consent for collection, use, and disclosure
unified
UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessary
unified
UC-DATA-04 — Restrict processing of special categories of personal data
unified
UC-DATA-05 — Provide privacy notices and transparency to data subjects
unified
UC-DATA-06 — Provide data subjects access to their personal data
unified
UC-DATA-07 — Keep personal data accurate and honor correction requests
unified
UC-DATA-08 — Execute deletion and other rights requests within deadlines
unified
UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it
unified
UC-DATA-10 — Protect physical media containing sensitive data
unified
UC-DATA-11 — Control data flows, leakage, and cross-border transfers
unified
UC-DATA-12 — De-identify, mask, or pseudonymize personal data
unified
UC-DATA-13 — Safeguard personal information with reasonable security
unified
UC-DATA-14 — Maintain and provide an accounting of disclosures
unified
UC-DATA-15 — Record and notify unauthorized disclosures of personal data
unified
UC-DATA-16 — Bind third parties handling personal data to privacy commitments
unified
UC-DATA-17 — Resolve privacy inquiries, complaints, and disputes
unified
UC-DATA-18 — Govern automated matching of PII under formal agreements
unified
UC-FIN-01 — Deploy financial control activities through policies
unified
UC-FIN-02 — Review financial results and the period-end close
unified
UC-FIN-03 — Perform and review account reconciliations
unified
UC-FIN-04 — Authorize transactions with attributable approvals
unified
UC-FIN-05 — Segregate incompatible financial duties
unified
UC-FIN-06 — Validate completeness and accuracy of system inputs
unified
UC-FIN-07 — Control automated processing and resolve exceptions
unified
UC-FIN-08 — Control interface transfers and output delivery
unified
UC-FIN-09 — Ensure quality of information used in reporting
unified
UC-FIN-10 — Safeguard assets and stored financial data
unified
UC-GOV-01 — Establish and maintain the enterprise governance framework
unified
UC-GOV-02 — Understand organizational context and stakeholder expectations
unified
UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations
unified
UC-GOV-04 — Set tone at the top: integrity, ethics, and risk-aware culture
unified
UC-GOV-05 — Ensure board-level oversight of risk and internal control
unified
UC-GOV-06 — Define security roles, responsibilities, and authorities
unified
UC-GOV-07 — Hold individuals accountable for control responsibilities
unified
UC-GOV-08 — Segregate conflicting duties and areas of responsibility
unified
UC-GOV-09 — Appoint accountable security leadership (CISO)
unified
UC-GOV-10 — Attract, develop, and retain competent personnel
unified
UC-GOV-11 — Allocate adequate resources and budget for security
unified
UC-GOV-12 — Align strategy and business objectives with mission and risk
unified
UC-GOV-13 — Govern the technology investment portfolio for value
unified
UC-GOV-14 — Establish and maintain approved security policies and procedures
unified
UC-GOV-15 — Operate a management-approved information security program
unified
UC-GOV-16 — Select and tailor a risk-based control baseline
unified
UC-GOV-17 — Establish enterprise risk management strategy and appetite
unified
UC-GOV-18 — Document and approve system security and privacy plans
unified
UC-GOV-19 — Maintain enterprise security and privacy architecture
unified
UC-GOV-20 — Govern data as an asset with accountable oversight bodies
unified
UC-GOV-21 — Communicate and report risk and control information
unified
UC-GOV-22 — Assess control effectiveness and authorize systems
unified
UC-GOV-23 — Maintain contacts with authorities and special interest groups
unified
UC-GOV-24 — Notify regulators of incidents and file required certifications
unified
UC-GOV-25 — Operate a privacy program with accountable leadership
unified
UC-GOV-26 — Enforce personal-data processing principles and minimization
unified
UC-GOV-27 — Manage privacy complaints and account for disclosures
unified
UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies
unified
UC-GOV-30 — Maintain asset, media, and physical protection policies
unified
UC-GOV-31 — Maintain access control, identity, and personnel security policies
unified
UC-GOV-32 — Maintain security awareness and cyber-hygiene policies
unified
UC-GOV-33 — Maintain logging, monitoring, and system integrity policies
unified
UC-GOV-34 — Maintain business continuity and contingency planning policy
unified
UC-GOV-35 — Maintain incident response policy and procedures
unified
UC-GOV-36 — Maintain communications security and cryptography policies
unified
UC-GOV-37 — Operate insider-threat and threat-awareness programs
unified
UC-GOV-38 — Assign and maintain Three Lines accountability by risk activity
unified
UC-HR-01 — Screen personnel commensurate with position risk
unified
UC-HR-02 — Formalize security responsibilities in employment terms
unified
UC-HR-03 — Secure termination and transfer of personnel
unified
UC-HR-04 — Enforce a formal disciplinary process for violations
unified
UC-HR-05 — Hold third-party personnel to equivalent security terms
unified
UC-HR-06 — Embed security and competence in HR practices
unified
UC-HR-07 — Secure remote working arrangements
unified
UC-IR-01 — Maintain an approved incident response plan
unified
UC-IR-02 — Train responders and test the incident response capability
unified
UC-IR-03 — Provide channels to report events and obtain response help
unified
UC-IR-04 — Triage, categorize, and escalate reported security events
unified
UC-IR-05 — Assess and validate incident scope, impact, and magnitude
unified
UC-IR-06 — Respond to, contain, and eradicate declared incidents
unified
UC-IR-07 — Investigate incidents and preserve evidence and records
unified
UC-IR-08 — Notify authorities and affected parties within deadlines
unified
UC-IR-09 — Recover from incidents using defined initiation criteria
unified
UC-IR-10 — Learn from incidents and communicate corrective actions
unified
UC-IR-11 — Respond to information spillage with defined procedures
unified
UC-LOG-01 — Log security-relevant events across all systems
unified
UC-LOG-02 — Record complete audit content with synchronized clocks
unified
UC-LOG-03 — Protect audit logs and retain them for required periods