unified
UC-GOV-24 — Notify regulators of incidents and file required certifications
Maintain documented procedures to notify supervisory and regulatory bodies of reportable cybersecurity events within mandated regulatory timelines, including any staged early-warning, detailed-notification, and final-report deadlines, and to submit required periodic compliance certifications and filings. Handle regulatory submissions and related materials confidentially, and retain evidence of all notifications, certifications, and supporting records.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- corrective
- category
- administrative
Details
- unified_id
- UC-GOV-24
- title
- Notify regulators of incidents and file required certifications
- statement
- Maintain documented procedures to notify supervisory and regulatory bodies of reportable cybersecurity events within mandated regulatory timelines, including any staged early-warning, detailed-notification, and final-report deadlines, and to submit required periodic compliance certifications and filings. Handle regulatory submissions and related materials confidentially, and retain evidence of all notifications, certifications, and supporting records.
- domain
- Governance, Policy & Oversight
- control_type
- corrective
- control_category
- administrative
- members
- framework
- nydfs-500
- control_id
- 500.17
- coverage
- full
- relationship
- superset_of
- framework
- nis2
- control_id
- NIS2-Art23
- coverage
- partial
- delta
- staged deadlines (early warning 24h, notification 72h, final report within one month); Art 23 also requires notifying service recipients of significant incidents and threat remedies
- relationship
- intersects_with
- framework
- nydfs-500
- control_id
- 500.18
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-GOV-24 — Notify regulators of incidents and file required certifications mitigates Litigation, investigation and enforcement exposure
- strength
- primary
- rationale
- Notifying regulators within mandated timelines and filing required certifications avoids penalties for late or missing regulatory reporting.
- UC-GOV-24 — Notify regulators of incidents and file required certifications mitigates Brand and reputational crisis
- strength
- related
- rationale
- Timely, proper incident notification limits the reputational fallout of mishandled disclosure.
- UC-GOV-24 — Notify regulators of incidents and file required certifications maps_to 500.17 — Notices to superintendent (incident notification and annual certification)
- framework
- nydfs-500
- control_id
- 500.17
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-24 — Notify regulators of incidents and file required certifications maps_to NIS2-Art23 — Reporting obligations (early warning 24h, incident notification 72h, final report 1 month)
- framework
- nis2
- control_id
- NIS2-Art23
- coverage
- partial
- delta
- staged deadlines (early warning 24h, notification 72h, final report within one month); Art 23 also requires notifying service recipients of significant incidents and threat remedies
- relationship
- intersects_with
- source_version
- Directive (EU) 2022/2555
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-24 — Notify regulators of incidents and file required certifications maps_to 500.18 — Confidentiality
- framework
- nydfs-500
- control_id
- 500.18
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Incident Management Lifecycle operates UC-GOV-24 — Notify regulators of incidents and file required certifications
- Regulatory Compliance Attestation Cycle oversees UC-GOV-24 — Notify regulators of incidents and file required certifications