unified
UC-DATA-13 — Safeguard personal information with reasonable security
Identify the statutory, regulatory, and contractual requirements that apply to the personal information the organization holds, and implement reasonable administrative, technical, and physical safeguards appropriate to its volume and sensitivity. Assign responsibility for PII protection, verify the safeguards periodically, and remediate identified gaps.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Data Protection & Privacy
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-DATA-13
- title
- Safeguard personal information with reasonable security
- statement
- Identify the statutory, regulatory, and contractual requirements that apply to the personal information the organization holds, and implement reasonable administrative, technical, and physical safeguards appropriate to its volume and sensitivity. Assign responsibility for PII protection, verify the safeguards periodically, and remediate identified gaps.
- domain
- Data Protection & Privacy
- control_type
- preventive
- control_category
- administrative
- members
- framework
- iso-27001
- control_id
- A.5.34
- coverage
- full
- relationship
- superset_of
- framework
- ccpa
- control_id
- CCPA-1798.150
- coverage
- full
- relationship
- superset_of
- framework
- hipaa
- control_id
- HIPAA-164.312(c)
- coverage
- partial
- relationship
- intersects_with
- delta
- the electronic mechanism to authenticate that ePHI has not been altered or destroyed is the specific integrity-verification arm
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-DATA-13 — Safeguard personal information with reasonable security maps_to CCPA-1798.150 — Reasonable security procedures; private right of action for breaches
- framework
- ccpa
- control_id
- CCPA-1798.150
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- CCPA (2018) as amended by CPRA (2020)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Privacy Safeguards & Notice Management operates UC-DATA-13 — Safeguard personal information with reasonable security
- UC-DATA-13 — Safeguard personal information with reasonable security maps_to A.5.34 — Privacy and protection of personal identifiable information (PII)
- framework
- iso-27001
- control_id
- A.5.34
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-DATA-13 — Safeguard personal information with reasonable security maps_to HIPAA-164.312(c) — Integrity controls protecting ePHI from improper alteration or destruction
- framework
- hipaa
- control_id
- HIPAA-164.312(c)
- coverage
- partial
- relationship
- intersects_with
- delta
- the electronic mechanism to authenticate that ePHI has not been altered or destroyed is the specific integrity-verification arm
- source_version
- 45 CFR Parts 160/164 (Security, Privacy, Breach Notification)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-DATA-13 — Safeguard personal information with reasonable security
- UC-DATA-13 — Safeguard personal information with reasonable security mitigates Unauthorized disclosure / breach of sensitive information
- strength
- primary
- rationale
- Implementing reasonable admin/technical/physical safeguards sized to data volume/sensitivity directly reduces unauthorized disclosure/breach.
- UC-DATA-13 — Safeguard personal information with reasonable security mitigates Excessive collection, purpose creep and secondary use
- strength
- primary
- rationale
- PII-protection requirements include data-minimization and purpose-limitation, directly addressing over-collection and purpose creep.
- UC-DATA-13 — Safeguard personal information with reasonable security mitigates Re-identification and unanticipated revelation from data
- strength
- related
- rationale