unified
UC-GOV-11 — Allocate adequate resources and budget for security
Allocate and manage funding, personnel, and other resources commensurate with the organization's cybersecurity risk strategy, roles, responsibilities, and policies, ensuring security and privacy requirements are addressed in capital planning, budgeting, and investment decisions. Periodically evaluate resource allocation and utilization for adequacy and optimization, and adjust budgets as priorities and risks change.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-11
- title
- Allocate adequate resources and budget for security
- statement
- Allocate and manage funding, personnel, and other resources commensurate with the organization's cybersecurity risk strategy, roles, responsibilities, and policies, ensuring security and privacy requirements are addressed in capital planning, budgeting, and investment decisions. Periodically evaluate resource allocation and utilization for adequacy and optimization, and adjust budgets as priorities and risks change.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- PM-3
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.RR-03
- coverage
- full
- relationship
- superset_of
- framework
- cobit-2019
- control_id
- EDM04
- coverage
- partial
- delta
- governance of optimization across all enterprise IT resources (people, technology, infrastructure), beyond security-scoped budget and personnel
- relationship
- intersects_with
- framework
- cobit-2019
- control_id
- APO06
- coverage
- partial
- delta
- full IT financial management including cost transparency and allocation models
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- Technology Investment & Project Risk Governance operates UC-GOV-11 — Allocate adequate resources and budget for security
- UC-GOV-11 — Allocate adequate resources and budget for security mitigates Weak internal control environment enabling fraud and error
- strength
- related
- rationale
- Resourcing controls commensurate with risk enables the control environment to function.
- UC-GOV-11 — Allocate adequate resources and budget for security maps_to APO06 — Managed Budget and Costs
- framework
- cobit-2019
- control_id
- APO06
- coverage
- partial
- delta
- full IT financial management including cost transparency and allocation models
- relationship
- intersects_with
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-GOV-11 — Allocate adequate resources and budget for security
- CSF 2.0 Profile & Maturity Assessment oversees UC-GOV-11 — Allocate adequate resources and budget for security
- UC-GOV-11 — Allocate adequate resources and budget for security mitigates Core process breakdown and inability to scale
- strength
- related
- rationale
- UC-GOV-11 — Allocate adequate resources and budget for security maps_to EDM04 — Ensured Resource Optimization
- framework
- cobit-2019
- control_id
- EDM04
- coverage
- partial
- delta
- governance of optimization across all enterprise IT resources (people, technology, infrastructure), beyond security-scoped budget and personnel
- relationship
- intersects_with
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-11 — Allocate adequate resources and budget for security maps_to PM-3 — Information Security and Privacy Resources
- framework
- nist-800-53
- control_id
- PM-3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- IT Governance Objective Review (COBIT) oversees UC-GOV-11 — Allocate adequate resources and budget for security
- UC-GOV-11 — Allocate adequate resources and budget for security maps_to GV.RR-03 — Roles, Responsibilities, and Authorities: Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies
- framework
- nist-csf-2
- control_id
- GV.RR-03
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.