unified
UC-GOV-14 — Establish and maintain approved security policies and procedures
Establish, approve, publish, and maintain the organization's information-security policy suite as a governed whole: a top-level policy plus the topic-specific policies, each with an accountable owner, board/management approval, planned review cycles, and communication to relevant parties. Domain-specific policy content is governed by its own unified control; this objective owns the suite-level lifecycle (inventory, approval chain, review cadence, communication, exceptions).
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-14
- title
- Establish and maintain approved security policies and procedures
- statement
- Establish, approve, publish, and maintain the organization's information-security policy suite as a governed whole: a top-level policy plus the topic-specific policies, each with an accountable owner, board/management approval, planned review cycles, and communication to relevant parties. Domain-specific policy content is governed by its own unified control; this objective owns the suite-level lifecycle (inventory, approval chain, review cadence, communication, exceptions).
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- iso-27001
- control_id
- A.5.1
- coverage
- partial
- delta
- Policies must also be acknowledged by relevant personnel and interested parties
- relationship
- intersects_with
- framework
- iso-27001
- control_id
- A.5.37
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.PO-01
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- GV.PO-02
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC5.3
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PL-1
- coverage
- full
- relationship
- superset_of
- framework
- nydfs-500
- control_id
- 500.3
- coverage
- full
- relationship
- superset_of
- framework
- nis2
- control_id
- NIS2-Art21a
- coverage
- full
- relationship
- superset_of
- framework
- hipaa
- control_id
- HIPAA-164.316
- coverage
- full
- relationship
- superset_of
- framework
- pci-dss
- control_id
- PCI-Req12
- coverage
- partial
- delta
- also requires awareness, screening, third-party management, and incident response program elements
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-GOV-14 — Establish and maintain approved security policies and procedures maps_to A.5.37 — Documented operating procedures
- framework
- iso-27001
- control_id
- A.5.37
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-14 — Establish and maintain approved security policies and procedures mitigates Litigation, investigation and enforcement exposure
- strength
- related
- rationale
- Maintaining policies required by HIPAA/PCI/regulators reduces enforcement exposure for missing governance documentation.
- Annual Policy Review operates UC-GOV-14 — Establish and maintain approved security policies and procedures
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-GOV-14 — Establish and maintain approved security policies and procedures
- UC-GOV-14 — Establish and maintain approved security policies and procedures mitigates Missing or insufficient security and privacy policies
- strength
- primary
- rationale
- Establishing, approving, and maintaining the security policy suite directly remedies missing approved policies.
- UC-GOV-14 — Establish and maintain approved security policies and procedures maps_to GV.PO-01 — Policy: Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced
- framework
- nist-csf-2
- control_id
- GV.PO-01
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-14 — Establish and maintain approved security policies and procedures maps_to CC5.3 — The entity deploys control activities through policies that establish what is expected and in procedures that put policies into action.
- framework
- soc2
- control_id
- CC5.3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Regulatory Obligation Implementation operates UC-GOV-14 — Establish and maintain approved security policies and procedures
- UC-GOV-14 — Establish and maintain approved security policies and procedures maps_to PL-1 — Policy and Procedures
- framework
- nist-800-53
- control_id
- PL-1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Policy Change operates UC-GOV-14 — Establish and maintain approved security policies and procedures
- UC-GOV-14 — Establish and maintain approved security policies and procedures maps_to PCI-Req12 — Support information security with organizational policies and programs
- framework
- pci-dss
- control_id
- PCI-Req12
- coverage
- partial
- delta
- also requires awareness, screening, third-party management, and incident response program elements
- relationship
- intersects_with
- source_version
- v4.0.1
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Policy Lifecycle Management oversees UC-GOV-14 — Establish and maintain approved security policies and procedures
- UC-GOV-14 — Establish and maintain approved security policies and procedures maps_to GV.PO-02 — Policy: Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission
- framework
- nist-csf-2
- control_id
- GV.PO-02
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-14 — Establish and maintain approved security policies and procedures maps_to NIS2-Art21a — Policies on risk analysis and information system security
- framework
- nis2
- control_id
- NIS2-Art21a
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Directive (EU) 2022/2555
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-GOV-14 — Establish and maintain approved security policies and procedures
- UC-GOV-14 — Establish and maintain approved security policies and procedures maps_to A.5.1 — Policies for information security
- framework
- iso-27001
- control_id
- A.5.1
- coverage
- partial
- delta
- Policies must also be acknowledged by relevant personnel and interested parties
- relationship
- intersects_with
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-14 — Establish and maintain approved security policies and procedures maps_to HIPAA-164.316 — Policies and procedures and documentation requirements
- framework
- hipaa
- control_id
- HIPAA-164.316
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 45 CFR Parts 160/164 (Security, Privacy, Breach Notification)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Trust Services Readiness tests UC-GOV-14 — Establish and maintain approved security policies and procedures
- UC-GOV-14 — Establish and maintain approved security policies and procedures maps_to 500.3 — Cybersecurity policy
- framework
- nydfs-500
- control_id
- 500.3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.