unified
UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems
Define, communicate, and require acknowledgment of acceptable-use rules for information and associated assets. Protect user endpoint devices with enforced safeguards such as encryption, screen locking, and centralized management, and protect organizational assets used off premises against loss, theft, and observation. Permit use of or connection to external systems only under established terms and conditions consistent with the trust relationship, including restrictions on processing organizational information and on portable storage.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Asset Management & Inventory
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-ASSET-06
- title
- Govern acceptable use of endpoints, off-site, and external systems
- statement
- Define, communicate, and require acknowledgment of acceptable-use rules for information and associated assets. Protect user endpoint devices with enforced safeguards such as encryption, screen locking, and centralized management, and protect organizational assets used off premises against loss, theft, and observation. Permit use of or connection to external systems only under established terms and conditions consistent with the trust relationship, including restrictions on processing organizational information and on portable storage.
- domain
- Asset Management & Inventory
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- AC-20
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.5.10
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.7.9
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.1
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems maps_to A.8.1 — User endpoint devices
- framework
- iso-27001
- control_id
- A.8.1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems mitigates Uncontrolled copying to removable media / unmanaged software installs
- strength
- primary
- rationale
- Acceptable-use rules, portable-storage restrictions, and centrally-managed endpoints prevent uncontrolled copying and unmanaged installs.
- UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems maps_to A.7.9 — Security of assets off-premises
- framework
- iso-27001
- control_id
- A.7.9
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems mitigates Incomplete asset inventory and classification
- strength
- related
- rationale
- Defining, communicating, and acknowledging acceptable-use rules closes the missing acceptable-use dimension of the gap.
- UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems mitigates Use of unlicensed, counterfeit or pirated software
- strength
- primary
- rationale
- Acceptable-use enforcement and locked-down centrally-managed endpoints prevent installation of unlicensed/pirated software.
- Endpoint, Media & Information Handling Custody operates UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems
- UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems maps_to A.5.10 — Acceptable use of information and other associated assets
- framework
- iso-27001
- control_id
- A.5.10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 SoA Review & Controls Assessment oversees UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems
- UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems maps_to AC-20 — Use of External Systems
- framework
- nist-800-53
- control_id
- AC-20
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems mitigates Theft of equipment, media or unattended devices
- strength
- primary
- rationale
- Endpoint encryption plus off-premises loss/theft protection directly reduces exposure from stolen or unattended devices.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems