unified
UC-AUDIT-22 — Review risk strategy and performance with leadership
Leadership periodically reviews the cybersecurity and risk management strategy and program performance against defined metrics, targets, and conformance requirements. Review outcomes are used to adjust strategy, direction, and program activities to ensure coverage of organizational requirements and risks. Performance and conformance monitoring follows a defined cadence with documented results and assigned follow-up actions.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Compliance, Audit & Assurance
- type
- detective
- category
- administrative
Details
- unified_id
- UC-AUDIT-22
- title
- Review risk strategy and performance with leadership
- statement
- Leadership periodically reviews the cybersecurity and risk management strategy and program performance against defined metrics, targets, and conformance requirements. Review outcomes are used to adjust strategy, direction, and program activities to ensure coverage of organizational requirements and risks. Performance and conformance monitoring follows a defined cadence with documented results and assigned follow-up actions.
- domain
- Compliance, Audit & Assurance
- control_type
- detective
- control_category
- administrative
- members
- framework
- nist-csf-2
- control_id
- GV.OV-02
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.OV-03
- coverage
- full
- relationship
- superset_of
- framework
- cobit-2019
- control_id
- MEA01
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-AUDIT-22 — Review risk strategy and performance with leadership mitigates Client selection, sponsorship and exposure-limit breaches
- strength
- related
- rationale
- UC-AUDIT-22 — Review risk strategy and performance with leadership maps_to MEA01 — Managed Performance and Conformance Monitoring
- framework
- cobit-2019
- control_id
- MEA01
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISMS Internal Audit & Management Review operates UC-AUDIT-22 — Review risk strategy and performance with leadership
- UC-AUDIT-22 — Review risk strategy and performance with leadership maps_to GV.OV-02 — Oversight: The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks
- framework
- nist-csf-2
- control_id
- GV.OV-02
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-AUDIT-22 — Review risk strategy and performance with leadership
- UC-AUDIT-22 — Review risk strategy and performance with leadership mitigates Inadequate board and management oversight of risk and control
- strength
- primary
- rationale
- Leadership periodically reviewing risk/cyber strategy and program performance against metrics and adjusting direction is the operative oversight mechanism.
- IT Governance Objective Review (COBIT) oversees UC-AUDIT-22 — Review risk strategy and performance with leadership
- CSF 2.0 Profile & Maturity Assessment oversees UC-AUDIT-22 — Review risk strategy and performance with leadership
- Quarterly Board & Audit-Committee GRC Reporting oversees UC-AUDIT-22 — Review risk strategy and performance with leadership
- UC-AUDIT-22 — Review risk strategy and performance with leadership maps_to GV.OV-03 — Oversight: Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed
- framework
- nist-csf-2
- control_id
- GV.OV-03
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.