unified
UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
Findings, recommendations, and management action plans - including improvements identified from security tests and exercises, and those coordinated with suppliers and third parties - are tracked in a follow-up process, and implementation is confirmed through evidence-based verification before closure. When management has accepted a level of risk that may exceed the organization's risk appetite, the matter is discussed with senior management and, if unresolved, escalated to the board. Follow-up logs and escalation records are retained.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Compliance, Audit & Assurance
- type
- detective
- category
- administrative
Details
- unified_id
- UC-AUDIT-17
- title
- Follow up on findings and escalate risk acceptance
- statement
- Findings, recommendations, and management action plans - including improvements identified from security tests and exercises, and those coordinated with suppliers and third parties - are tracked in a follow-up process, and implementation is confirmed through evidence-based verification before closure. When management has accepted a level of risk that may exceed the organization's risk appetite, the matter is discussed with senior management and, if unresolved, escalated to the board. Follow-up logs and escalation records are retained.
- domain
- Compliance, Audit & Assurance
- control_type
- detective
- control_category
- administrative
- members
- framework
- iia-2024
- control_id
- Std 15.2
- coverage
- full
- relationship
- superset_of
- framework
- iia-2024
- control_id
- Std 11.5
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- ID.IM-02
- coverage
- partial
- delta
- ID.IM-02's security-test-and-exercise-driven improvement is an operations outcome only partially covered by audit follow-up; its operational home is the improvement objective (UC-ASSET-11)
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-AUDIT-17 — Follow up on findings and escalate risk acceptance maps_to Std 15.2 — Confirming the Implementation of Recommendations or Action Plans
- framework
- iia-2024
- control_id
- Std 15.2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2024 edition
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Control Assessment & POA&M Remediation operates UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
- SOX Deficiency Remediation oversees UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
- ISMS Internal Audit & Management Review operates UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
- Finding Remediation & Action-Plan Monitoring tests UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
- UC-AUDIT-17 — Follow up on findings and escalate risk acceptance maps_to Std 11.5 — Communicating the Acceptance of Risks
- framework
- iia-2024
- control_id
- Std 11.5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2024 edition
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Policy Exception & Risk Acceptance oversees UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
- Control Remediation Retest and Closure tests UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
- Internal Audit Engagement Lifecycle tests UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
- UC-AUDIT-17 — Follow up on findings and escalate risk acceptance mitigates Inadequate board and management oversight of risk and control
- strength
- related
- rationale
- Escalating risk acceptance beyond appetite to senior management and the board is a governance safeguard supporting oversight.
- Regulatory Exam & External Audit Management oversees UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
- Year-End Deficiency Aggregation & Severity Evaluation oversees UC-AUDIT-17 — Follow up on findings and escalate risk acceptance
- UC-AUDIT-17 — Follow up on findings and escalate risk acceptance maps_to ID.IM-02 — Improvement: Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties
- framework
- nist-csf-2
- control_id
- ID.IM-02
- coverage
- partial
- delta
- ID.IM-02's security-test-and-exercise-driven improvement is an operations outcome only partially covered by audit follow-up; its operational home is the improvement objective (UC-ASSET-11)
- relationship
- intersects_with
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AUDIT-17 — Follow up on findings and escalate risk acceptance mitigates Environmental regulatory non-compliance
- strength
- related
- rationale