unified
UC-GOV-15 — Operate a management-approved information security program
Establish, implement, and maintain an organization-wide information security program, documented in a program plan approved by senior management and based on the organization's risk assessment. Define the program's scope, security objectives, protective functions (identify, protect, detect, respond, recover), supporting management processes, and coordination among organizational entities, and review and update the program plan at planned intervals and after significant change.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-15
- title
- Operate a management-approved information security program
- statement
- Establish, implement, and maintain an organization-wide information security program, documented in a program plan approved by senior management and based on the organization's risk assessment. Define the program's scope, security objectives, protective functions (identify, protect, detect, respond, recover), supporting management processes, and coordination among organizational entities, and review and update the program plan at planned intervals and after significant change.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- PM-1
- coverage
- full
- relationship
- superset_of
- framework
- nydfs-500
- control_id
- 500.2
- coverage
- partial
- delta
- Program's core functions must also include fulfilling applicable regulatory reporting obligations
- relationship
- intersects_with
- framework
- cobit-2019
- control_id
- APO13
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-GOV-15 — Operate a management-approved information security program maps_to 500.2 — Cybersecurity program
- framework
- nydfs-500
- control_id
- 500.2
- coverage
- partial
- delta
- Program's core functions must also include fulfilling applicable regulatory reporting obligations
- relationship
- intersects_with
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 SoA Review & Controls Assessment oversees UC-GOV-15 — Operate a management-approved information security program
- ISMS Internal Audit & Management Review tests UC-GOV-15 — Operate a management-approved information security program
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-GOV-15 — Operate a management-approved information security program
- UC-GOV-15 — Operate a management-approved information security program maps_to APO13 — Managed Security
- framework
- cobit-2019
- control_id
- APO13
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-15 — Operate a management-approved information security program mitigates Missing or insufficient security and privacy policies
- strength
- primary
- rationale
- A management-approved, org-wide security program supplies the coordinated guidance whose absence leaves controls inconsistent.
- UC-GOV-15 — Operate a management-approved information security program maps_to PM-1 — Information Security Program Plan
- framework
- nist-800-53
- control_id
- PM-1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Cybersecurity Assurance Review tests UC-GOV-15 — Operate a management-approved information security program
- UC-GOV-15 — Operate a management-approved information security program mitigates Organizational change and transformation failure
- strength
- related
- rationale
- Information Security Program Governance Review operates UC-GOV-15 — Operate a management-approved information security program