unified
UC-GOV-22 — Assess control effectiveness and authorize systems
Maintain a documented assessment and authorization policy with procedures, defined performance measures, and quality monitoring to regularly evaluate whether security policies, standards, and risk-management measures are implemented, complied with, and effective — including managers' reviews of compliance within their areas of responsibility. Feed assessment results into a formal, risk-based authorization process in which a senior official explicitly accepts residual risk before systems operate and at defined intervals thereafter, and track findings to closure.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- detective
- category
- administrative
Details
- unified_id
- UC-GOV-22
- title
- Assess control effectiveness and authorize systems
- statement
- Maintain a documented assessment and authorization policy with procedures, defined performance measures, and quality monitoring to regularly evaluate whether security policies, standards, and risk-management measures are implemented, complied with, and effective — including managers' reviews of compliance within their areas of responsibility. Feed assessment results into a formal, risk-based authorization process in which a senior official explicitly accepts residual risk before systems operate and at defined intervals thereafter, and track findings to closure.
- domain
- Governance, Policy & Oversight
- control_type
- detective
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- PM-6
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- CA-1
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PM-10
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.5.36
- coverage
- full
- relationship
- superset_of
- framework
- nis2
- control_id
- NIS2-Art21f
- coverage
- full
- relationship
- superset_of
- framework
- cobit-2019
- control_id
- APO11
- coverage
- partial
- delta
- embedding quality management practices across processes, projects, and deliverables
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-GOV-22 — Assess control effectiveness and authorize systems maps_to A.5.36 — Compliance with policies, rules and standards for information security
- framework
- iso-27001
- control_id
- A.5.36
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-22 — Assess control effectiveness and authorize systems mitigates Improper business or market practices
- strength
- related
- rationale
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-GOV-22 — Assess control effectiveness and authorize systems
- UC-GOV-22 — Assess control effectiveness and authorize systems maps_to PM-6 — Measures of Performance
- framework
- nist-800-53
- control_id
- PM-6
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-22 — Assess control effectiveness and authorize systems maps_to APO11 — Managed Quality
- framework
- cobit-2019
- control_id
- APO11
- coverage
- partial
- delta
- embedding quality management practices across processes, projects, and deliverables
- relationship
- intersects_with
- source_version
- 2019
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-22 — Assess control effectiveness and authorize systems maps_to CA-1 — Policy and Procedures
- framework
- nist-800-53
- control_id
- CA-1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-22 — Assess control effectiveness and authorize systems mitigates Lack of independent audit and compliance review
- strength
- primary
- rationale
- Regularly assessing control effectiveness and tracking findings to closure detects and challenges deficiencies that would otherwise persist.
- UC-GOV-22 — Assess control effectiveness and authorize systems maps_to PM-10 — Authorization Process
- framework
- nist-800-53
- control_id
- PM-10
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Control Assessment & POA&M Remediation operates UC-GOV-22 — Assess control effectiveness and authorize systems
- UC-GOV-22 — Assess control effectiveness and authorize systems maps_to NIS2-Art21f — Policies and procedures to assess the effectiveness of cybersecurity risk-management measures
- framework
- nis2
- control_id
- NIS2-Art21f
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Directive (EU) 2022/2555
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.