unified

UC-GOV-05 — Ensure board-level oversight of risk and internal control

The board of directors (or equivalent governing body), demonstrating independence from management and appropriate expertise, oversees the development and performance of internal control and the cybersecurity risk management program, approving the risk strategy and material policies. The board periodically reviews risk-management outcomes, program effectiveness, and management reporting, and directs adjustments to strategy and direction; oversight activities and decisions are documented in minutes and supporting materials.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Governance, Policy & Oversight
type
preventive
category
administrative

Details

unified_id
UC-GOV-05
title
Ensure board-level oversight of risk and internal control
statement
The board of directors (or equivalent governing body), demonstrating independence from management and appropriate expertise, oversees the development and performance of internal control and the cybersecurity risk management program, approving the risk strategy and material policies. The board periodically reviews risk-management outcomes, program effectiveness, and management reporting, and directs adjustments to strategy and direction; oversight activities and decisions are documented in minutes and supporting materials.
domain
Governance, Policy & Oversight
control_type
preventive
control_category
administrative
members
  • framework
    soc2
    control_id
    CC1.2
    coverage
    full
    relationship
    superset_of
  • framework
    coso-ic
    control_id
    P2
    coverage
    full
    relationship
    superset_of
  • framework
    coso-erm
    control_id
    E1
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    GV.OV-01
    coverage
    full
    relationship
    superset_of
  • framework
    nis2
    control_id
    NIS2-Art20
    coverage
    partial
    delta
    management body members must approve measures and complete cybersecurity training
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections