unified

UC-GOV-22 — Assess control effectiveness and authorize systems

Maintain a documented assessment and authorization policy with procedures, defined performance measures, and quality monitoring to regularly evaluate whether security policies, standards, and risk-management measures are implemented, complied with, and effective — including managers' reviews of compliance within their areas of responsibility. Feed assessment results into a formal, risk-based authorization process in which a senior official explicitly accepts residual risk before systems operate and at defined intervals thereafter, and track findings to closure.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Governance, Policy & Oversight
type
detective
category
administrative

Details

unified_id
UC-GOV-22
title
Assess control effectiveness and authorize systems
statement
Maintain a documented assessment and authorization policy with procedures, defined performance measures, and quality monitoring to regularly evaluate whether security policies, standards, and risk-management measures are implemented, complied with, and effective — including managers' reviews of compliance within their areas of responsibility. Feed assessment results into a formal, risk-based authorization process in which a senior official explicitly accepts residual risk before systems operate and at defined intervals thereafter, and track findings to closure.
domain
Governance, Policy & Oversight
control_type
detective
control_category
administrative
members
  • framework
    nist-800-53
    control_id
    PM-6
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    CA-1
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    PM-10
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.5.36
    coverage
    full
    relationship
    superset_of
  • framework
    nis2
    control_id
    NIS2-Art21f
    coverage
    full
    relationship
    superset_of
  • framework
    cobit-2019
    control_id
    APO11
    coverage
    partial
    delta
    embedding quality management practices across processes, projects, and deliverables
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections