unified
UC-GOV-19 — Maintain enterprise security and privacy architecture
Establish and maintain an enterprise architecture, including security and privacy architectures, that describes how systems, information flows, and protections align with the organization's mission and strategy and address security and privacy risks. Review and update the architecture at defined intervals and reflect it in system security plans, solution designs, and acquisition decisions.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-19
- title
- Maintain enterprise security and privacy architecture
- statement
- Establish and maintain an enterprise architecture, including security and privacy architectures, that describes how systems, information flows, and protections align with the organization's mission and strategy and address security and privacy risks. Review and update the architecture at defined intervals and reflect it in system security plans, solution designs, and acquisition decisions.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- PL-8
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PM-7
- coverage
- full
- relationship
- superset_of
- framework
- cobit-2019
- control_id
- APO03
- coverage
- partial
- delta
- EA vision and multi-domain (business/data/application/technology) reference architecture plus enterprise-architecture services, beyond security/privacy architecture
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- Security Control Assessment & POA&M Remediation tests UC-GOV-19 — Maintain enterprise security and privacy architecture
- UC-GOV-19 — Maintain enterprise security and privacy architecture mitigates Strategic misalignment and execution failure
- strength
- related
- rationale
- Enterprise architecture aligns technology to an existing strategy, supporting execution, but does not set or correct the strategy itself; UC-GOV-12 is the operative alignment control.
- Security & Privacy Architecture Review Board operates UC-GOV-19 — Maintain enterprise security and privacy architecture
- UC-GOV-19 — Maintain enterprise security and privacy architecture maps_to PL-8 — Security and Privacy Architectures
- framework
- nist-800-53
- control_id
- PL-8
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-19 — Maintain enterprise security and privacy architecture maps_to PM-7 — Enterprise Architecture
- framework
- nist-800-53
- control_id
- PM-7
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-19 — Maintain enterprise security and privacy architecture maps_to APO03 — Managed Enterprise Architecture
- framework
- cobit-2019
- control_id
- APO03
- coverage
- partial
- delta
- EA vision and multi-domain (business/data/application/technology) reference architecture plus enterprise-architecture services, beyond security/privacy architecture
- relationship
- intersects_with
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.