unified

UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations

Identify, document, and keep current all legal, statutory, regulatory, and contractual requirements relevant to information security and privacy — including privacy and civil-liberties obligations — and define and assign the organization's approach to meeting each. Assess and document applicability determinations, including any regulatory exemptions claimed, and file the notices required to support those determinations. Review the obligations register at planned intervals and upon regulatory or business change.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Governance, Policy & Oversight
type
preventive
category
administrative

Details

unified_id
UC-GOV-03
title
Identify and manage legal, regulatory, and contractual obligations
statement
Identify, document, and keep current all legal, statutory, regulatory, and contractual requirements relevant to information security and privacy — including privacy and civil-liberties obligations — and define and assign the organization's approach to meeting each. Assess and document applicability determinations, including any regulatory exemptions claimed, and file the notices required to support those determinations. Review the obligations register at planned intervals and upon regulatory or business change.
domain
Governance, Policy & Oversight
control_type
preventive
control_category
administrative
members
  • framework
    iso-27001
    control_id
    A.5.31
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    GV.OC-03
    coverage
    full
    relationship
    superset_of
  • framework
    nydfs-500
    control_id
    500.19
    coverage
    full
    relationship
    superset_of
guidance

    Source

    No record-specific source URL is provided.

    Connections