unified
UC-GOV-32 — Maintain security awareness and cyber-hygiene policies
Establish, document, and disseminate policies and procedures for security awareness, training, and basic cyber-hygiene practices applicable to all personnel, defining required content, frequency, audiences, and completion tracking. Review and update the policy and program requirements at defined intervals and in response to changes in threats and incidents.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-32
- title
- Maintain security awareness and cyber-hygiene policies
- statement
- Establish, document, and disseminate policies and procedures for security awareness, training, and basic cyber-hygiene practices applicable to all personnel, defining required content, frequency, audiences, and completion tracking. Review and update the policy and program requirements at defined intervals and in response to changes in threats and incidents.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- AT-1
- coverage
- full
- relationship
- superset_of
- framework
- nis2
- control_id
- NIS2-Art21g
- coverage
- partial
- delta
- actual delivery of hygiene practices and training to all personnel
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- Security Control Assessment & POA&M Remediation tests UC-GOV-32 — Maintain security awareness and cyber-hygiene policies
- Policy Lifecycle Management oversees UC-GOV-32 — Maintain security awareness and cyber-hygiene policies
- UC-GOV-32 — Maintain security awareness and cyber-hygiene policies maps_to NIS2-Art21g — Basic cyber hygiene practices and cybersecurity training
- framework
- nis2
- control_id
- NIS2-Art21g
- coverage
- partial
- delta
- actual delivery of hygiene practices and training to all personnel
- relationship
- intersects_with
- source_version
- Directive (EU) 2022/2555
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-32 — Maintain security awareness and cyber-hygiene policies mitigates Missing or insufficient security and privacy policies
- strength
- primary
- rationale
- Establishing security-awareness and cyber-hygiene policies remedies missing policy for training content, cadence, and tracking.
- Security Policy Suite Review operates UC-GOV-32 — Maintain security awareness and cyber-hygiene policies
- UC-GOV-32 — Maintain security awareness and cyber-hygiene policies maps_to AT-1 — Policy and Procedures
- framework
- nist-800-53
- control_id
- AT-1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.