unified
UC-GOV-05 — Ensure board-level oversight of risk and internal control
The board of directors (or equivalent governing body), demonstrating independence from management and appropriate expertise, oversees the development and performance of internal control and the cybersecurity risk management program, approving the risk strategy and material policies. The board periodically reviews risk-management outcomes, program effectiveness, and management reporting, and directs adjustments to strategy and direction; oversight activities and decisions are documented in minutes and supporting materials.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-05
- title
- Ensure board-level oversight of risk and internal control
- statement
- The board of directors (or equivalent governing body), demonstrating independence from management and appropriate expertise, oversees the development and performance of internal control and the cybersecurity risk management program, approving the risk strategy and material policies. The board periodically reviews risk-management outcomes, program effectiveness, and management reporting, and directs adjustments to strategy and direction; oversight activities and decisions are documented in minutes and supporting materials.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- soc2
- control_id
- CC1.2
- coverage
- full
- relationship
- superset_of
- framework
- coso-ic
- control_id
- P2
- coverage
- full
- relationship
- superset_of
- framework
- coso-erm
- control_id
- E1
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.OV-01
- coverage
- full
- relationship
- superset_of
- framework
- nis2
- control_id
- NIS2-Art20
- coverage
- partial
- delta
- management body members must approve measures and complete cybersecurity training
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- Quarterly Board & Audit-Committee GRC Reporting oversees UC-GOV-05 — Ensure board-level oversight of risk and internal control
- Risk Appetite Definition & Board Reporting oversees UC-GOV-05 — Ensure board-level oversight of risk and internal control
- UC-GOV-05 — Ensure board-level oversight of risk and internal control maps_to E1 — Exercises Board Risk Oversight
- framework
- coso-erm
- control_id
- E1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-05 — Ensure board-level oversight of risk and internal control maps_to CC1.2 — The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.
- framework
- soc2
- control_id
- CC1.2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-05 — Ensure board-level oversight of risk and internal control mitigates Inadequate board and management oversight of risk and control
- strength
- primary
- rationale
- Board independence, expertise, and oversight of the control and risk program is the direct control against inadequate board oversight.
- UC-GOV-05 — Ensure board-level oversight of risk and internal control maps_to P2 — The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.
- framework
- coso-ic
- control_id
- P2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2013
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-05 — Ensure board-level oversight of risk and internal control maps_to GV.OV-01 — Oversight: Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction
- framework
- nist-csf-2
- control_id
- GV.OV-01
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-05 — Ensure board-level oversight of risk and internal control maps_to NIS2-Art20 — Governance and management body accountability / training
- framework
- nis2
- control_id
- NIS2-Art20
- coverage
- partial
- delta
- management body members must approve measures and complete cybersecurity training
- relationship
- intersects_with
- source_version
- Directive (EU) 2022/2555
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Trust Services Readiness tests UC-GOV-05 — Ensure board-level oversight of risk and internal control
- UC-GOV-05 — Ensure board-level oversight of risk and internal control mitigates Ineffective ICFR / undisclosed material weakness
- strength
- related
- rationale
- Board/audit-committee oversight of internal control provides challenge that helps surface ICFR material weaknesses.
- Board Risk & Internal Control Oversight Cycle operates UC-GOV-05 — Ensure board-level oversight of risk and internal control