unified
UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations
Identify, document, and keep current all legal, statutory, regulatory, and contractual requirements relevant to information security and privacy — including privacy and civil-liberties obligations — and define and assign the organization's approach to meeting each. Assess and document applicability determinations, including any regulatory exemptions claimed, and file the notices required to support those determinations. Review the obligations register at planned intervals and upon regulatory or business change.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-03
- title
- Identify and manage legal, regulatory, and contractual obligations
- statement
- Identify, document, and keep current all legal, statutory, regulatory, and contractual requirements relevant to information security and privacy — including privacy and civil-liberties obligations — and define and assign the organization's approach to meeting each. Assess and document applicability determinations, including any regulatory exemptions claimed, and file the notices required to support those determinations. Review the obligations register at planned intervals and upon regulatory or business change.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- iso-27001
- control_id
- A.5.31
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.OC-03
- coverage
- full
- relationship
- superset_of
- framework
- nydfs-500
- control_id
- 500.19
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- Obligation Implementation & Adoption operates UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations
- Compliance Monitoring & Attestation operates UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations
- UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations mitigates Litigation, investigation and enforcement exposure
- strength
- primary
- rationale
- Maintaining a current register of legal/regulatory/contractual obligations and assigning how each is met reduces enforcement and litigation exposure.
- UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations maps_to A.5.31 — Legal, statutory, regulatory and contractual requirements
- framework
- iso-27001
- control_id
- A.5.31
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Regulatory Obligation Implementation operates UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations
- Regulatory Impact Analysis & Obligation Mapping oversees UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations
- UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations mitigates Climate transition risk — carbon pricing and stranded assets
- strength
- related
- rationale
- Regulatory Change Intake & Impact Assessment operates UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations
- Regulatory Horizon Scanning & Triage oversees UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations
- EU AI Act Obligation Impact Analysis oversees UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations
- UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations maps_to 500.19 — Exemptions
- framework
- nydfs-500
- control_id
- 500.19
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Requirement Applicability & Control Mapping operates UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations
- UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations maps_to GV.OC-03 — Organizational Context: Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed
- framework
- nist-csf-2
- control_id
- GV.OC-03
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.