unified
UC-HR-06 — Embed security and competence in HR practices
Human resources processes incorporate cybersecurity at each stage, from recruiting and onboarding through role change and separation, with defined security checkpoints. The organization defines competence requirements for roles, attracts and develops qualified personnel through training and performance evaluation, and plans for succession and contingency in security-relevant positions.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Human Resources / Personnel Security
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-HR-06
- title
- Embed security and competence in HR practices
- statement
- Human resources processes incorporate cybersecurity at each stage, from recruiting and onboarding through role change and separation, with defined security checkpoints. The organization defines competence requirements for roles, attracts and develops qualified personnel through training and performance evaluation, and plans for succession and contingency in security-relevant positions.
- domain
- Human Resources / Personnel Security
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-csf-2
- control_id
- GV.RR-04
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC1.4
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-HR-06 — Embed security and competence in HR practices mitigates Inadequate security awareness and training
- strength
- related
- rationale
- Developing personnel through training and embedding cybersecurity across HR stages builds a security-aware workforce; enabler, not the dedicated awareness-training control.
- UC-HR-06 — Embed security and competence in HR practices mitigates Critical talent loss, scarcity and succession gaps
- strength
- primary
- rationale
- Succession/contingency planning for security-relevant roles plus attracting and developing scarce skills directly reduces key-talent loss and knowledge-transfer gaps.
- ISO 27001 Stage 1 ISMS Documentation Review tests UC-HR-06 — Embed security and competence in HR practices
- SOC 2 Trust Services Readiness tests UC-HR-06 — Embed security and competence in HR practices
- UC-HR-06 — Embed security and competence in HR practices mitigates Missing role-based and ongoing security/privacy training
- strength
- related
- rationale
- Defining role competence requirements enables the role-based training and development that closes gaps for staff in security-relevant roles.
- UC-HR-06 — Embed security and competence in HR practices maps_to GV.RR-04 — Roles, Responsibilities, and Authorities: Cybersecurity is included in human resources practices
- framework
- nist-csf-2
- control_id
- GV.RR-04
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Joiner-Mover-Leaver Access Lifecycle operates UC-HR-06 — Embed security and competence in HR practices
- Employee Onboarding operates UC-HR-06 — Embed security and competence in HR practices
- UC-HR-06 — Embed security and competence in HR practices maps_to CC1.4 — The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.
- framework
- soc2
- control_id
- CC1.4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.