unified

UC-GOV-14 — Establish and maintain approved security policies and procedures

Establish, approve, publish, and maintain the organization's information-security policy suite as a governed whole: a top-level policy plus the topic-specific policies, each with an accountable owner, board/management approval, planned review cycles, and communication to relevant parties. Domain-specific policy content is governed by its own unified control; this objective owns the suite-level lifecycle (inventory, approval chain, review cadence, communication, exceptions).

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Governance, Policy & Oversight
type
preventive
category
administrative

Details

unified_id
UC-GOV-14
title
Establish and maintain approved security policies and procedures
statement
Establish, approve, publish, and maintain the organization's information-security policy suite as a governed whole: a top-level policy plus the topic-specific policies, each with an accountable owner, board/management approval, planned review cycles, and communication to relevant parties. Domain-specific policy content is governed by its own unified control; this objective owns the suite-level lifecycle (inventory, approval chain, review cadence, communication, exceptions).
domain
Governance, Policy & Oversight
control_type
preventive
control_category
administrative
members
  • framework
    iso-27001
    control_id
    A.5.1
    coverage
    partial
    delta
    Policies must also be acknowledged by relevant personnel and interested parties
    relationship
    intersects_with
  • framework
    iso-27001
    control_id
    A.5.37
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    GV.PO-01
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    GV.PO-02
    coverage
    full
    relationship
    superset_of
  • framework
    soc2
    control_id
    CC5.3
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    PL-1
    coverage
    full
    relationship
    superset_of
  • framework
    nydfs-500
    control_id
    500.3
    coverage
    full
    relationship
    superset_of
  • framework
    nis2
    control_id
    NIS2-Art21a
    coverage
    full
    relationship
    superset_of
  • framework
    hipaa
    control_id
    HIPAA-164.316
    coverage
    full
    relationship
    superset_of
  • framework
    pci-dss
    control_id
    PCI-Req12
    coverage
    partial
    delta
    also requires awareness, screening, third-party management, and incident response program elements
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections