unified
UC-GOV-30 — Maintain asset, media, and physical protection policies
Establish, document, and disseminate policies and procedures for asset management, media protection, and physical and environmental protection — including maintenance of a complete asset inventory, secure handling, marking, storage, and sanitization of media, and data retention limits with secure disposal of nonpublic information no longer required for business or legal purposes. Review and update these policies and procedures at defined intervals and upon significant change.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-30
- title
- Maintain asset, media, and physical protection policies
- statement
- Establish, document, and disseminate policies and procedures for asset management, media protection, and physical and environmental protection — including maintenance of a complete asset inventory, secure handling, marking, storage, and sanitization of media, and data retention limits with secure disposal of nonpublic information no longer required for business or legal purposes. Review and update these policies and procedures at defined intervals and upon significant change.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- MP-1
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PE-1
- coverage
- full
- relationship
- superset_of
- framework
- nydfs-500
- control_id
- 500.13
- coverage
- partial
- delta
- Inventory must track owner, location, classification, support expiration, RTO, plus update frequency
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- Security Control Assessment & POA&M Remediation tests UC-GOV-30 — Maintain asset, media, and physical protection policies
- Policy Lifecycle Management oversees UC-GOV-30 — Maintain asset, media, and physical protection policies
- Security Policy Suite Review operates UC-GOV-30 — Maintain asset, media, and physical protection policies
- UC-GOV-30 — Maintain asset, media, and physical protection policies mitigates Litigation, investigation and enforcement exposure
- strength
- related
- rationale
- Retention limits and secure disposal of nonpublic data reduce over-retention and legal exposure.
- UC-GOV-30 — Maintain asset, media, and physical protection policies mitigates Missing or insufficient security and privacy policies
- strength
- primary
- rationale
- Establishing asset-management, media-protection, and physical-protection policies remedies missing policies for this domain.
- UC-GOV-30 — Maintain asset, media, and physical protection policies maps_to MP-1 — Policy and Procedures
- framework
- nist-800-53
- control_id
- MP-1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-30 — Maintain asset, media, and physical protection policies maps_to PE-1 — Policy and Procedures
- framework
- nist-800-53
- control_id
- PE-1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-30 — Maintain asset, media, and physical protection policies maps_to 500.13 — Asset management and data retention limitations
- framework
- nydfs-500
- control_id
- 500.13
- coverage
- partial
- delta
- Inventory must track owner, location, classification, support expiration, RTO, plus update frequency
- relationship
- intersects_with
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.