unified
UC-GOV-16 — Select and tailor a risk-based control baseline
Select and document a baseline of security and privacy controls — including general controls over technology — responsive to assessed risks, and tailor it to the organization's environment, complexity, and risk appetite, considering an appropriate mix of preventive and detective control types and segregation of duties. Centrally identify, manage, and deploy common controls where appropriate, and document and approve the rationale for all tailoring decisions.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-16
- title
- Select and tailor a risk-based control baseline
- statement
- Select and document a baseline of security and privacy controls — including general controls over technology — responsive to assessed risks, and tailor it to the organization's environment, complexity, and risk appetite, considering an appropriate mix of preventive and detective control types and segregation of duties. Centrally identify, manage, and deploy common controls where appropriate, and document and approve the rationale for all tailoring decisions.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- PL-10
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PL-11
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PL-9
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC5.1
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC5.2
- coverage
- partial
- delta
- developing and operating the specific technology general controls (infrastructure, security management, acquisition/development/maintenance) satisfied by dedicated ITGC companion controls; this UC delivers their selection into the baseline
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-GOV-16 — Select and tailor a risk-based control baseline mitigates Weak internal control environment enabling fraud and error
- strength
- primary
- rationale
- Selecting and tailoring a risk-based control baseline with SoD and a preventive/detective mix directly builds adequate controls.
- Framework Adoption & Cross-Mapping oversees UC-GOV-16 — Select and tailor a risk-based control baseline
- Regulatory Obligation Implementation operates UC-GOV-16 — Select and tailor a risk-based control baseline
- UC-GOV-16 — Select and tailor a risk-based control baseline mitigates Ineffective ICFR / undisclosed material weakness
- strength
- related
- rationale
- Baseline general controls over technology support reliable financial reporting.
- ISO 27001 SoA Review & Controls Assessment oversees UC-GOV-16 — Select and tailor a risk-based control baseline
- UC-GOV-16 — Select and tailor a risk-based control baseline maps_to PL-11 — Baseline Tailoring
- framework
- nist-800-53
- control_id
- PL-11
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Type II Interim Testing tests UC-GOV-16 — Select and tailor a risk-based control baseline
- SOC 2 Trust Services Readiness tests UC-GOV-16 — Select and tailor a risk-based control baseline
- NIST RMF System Authorization (ATO) Cycle oversees UC-GOV-16 — Select and tailor a risk-based control baseline
- Control Library Lifecycle oversees UC-GOV-16 — Select and tailor a risk-based control baseline
- UC-GOV-16 — Select and tailor a risk-based control baseline maps_to PL-9 — Central Management
- framework
- nist-800-53
- control_id
- PL-9
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-16 — Select and tailor a risk-based control baseline maps_to CC5.2 — The entity also selects and develops general control activities over technology to support the achievement of objectives.
- framework
- soc2
- control_id
- CC5.2
- coverage
- partial
- delta
- developing and operating the specific technology general controls (infrastructure, security management, acquisition/development/maintenance) satisfied by dedicated ITGC companion controls; this UC delivers their selection into the baseline
- relationship
- intersects_with
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-16 — Select and tailor a risk-based control baseline maps_to PL-10 — Baseline Selection
- framework
- nist-800-53
- control_id
- PL-10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-GOV-16 — Select and tailor a risk-based control baseline
- UC-GOV-16 — Select and tailor a risk-based control baseline maps_to CC5.1 — The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.
- framework
- soc2
- control_id
- CC5.1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.