unified
UC-LOG-06 — Evaluate events and declare incidents against defined criteria
Define written criteria for declaring a security incident, including thresholds that identify a reportable personal-data breach. Evaluate analyzed events against those criteria, declare incidents and initiate the response process when criteria are met, and record the assessment and rationale for every evaluated event. For reportable personal-data breaches, notify the competent regulator within the mandated statutory window with the prescribed content, and document all breaches, their effects, and remediation regardless of whether notification was required.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Logging, Monitoring & Detection
- type
- detective
- category
- administrative
Details
- unified_id
- UC-LOG-06
- title
- Evaluate events and declare incidents against defined criteria
- statement
- Define written criteria for declaring a security incident, including thresholds that identify a reportable personal-data breach. Evaluate analyzed events against those criteria, declare incidents and initiate the response process when criteria are met, and record the assessment and rationale for every evaluated event. For reportable personal-data breaches, notify the competent regulator within the mandated statutory window with the prescribed content, and document all breaches, their effects, and remediation regardless of whether notification was required.
- domain
- Logging, Monitoring & Detection
- control_type
- detective
- control_category
- administrative
- members
- framework
- nist-csf-2
- control_id
- DE.AE-08
- coverage
- full
- relationship
- superset_of
- framework
- soc2
- control_id
- CC7.3
- coverage
- full
- relationship
- superset_of
- framework
- gdpr
- control_id
- GDPR-Art33
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-LOG-06 — Evaluate events and declare incidents against defined criteria maps_to DE.AE-08 — Adverse Event Analysis: Incidents are declared when adverse events meet the defined incident criteria
- framework
- nist-csf-2
- control_id
- DE.AE-08
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-LOG-06 — Evaluate events and declare incidents against defined criteria mitigates Attacks by capable, motivated threat actors
- strength
- related
- rationale
- Declaring incidents when criteria are met triggers the response that contains and limits attack impact.
- UC-LOG-06 — Evaluate events and declare incidents against defined criteria maps_to GDPR-Art33 — Notification of a personal data breach to the supervisory authority
- framework
- gdpr
- control_id
- GDPR-Art33
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Regulation (EU) 2016/679
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Privacy Breach Assessment & Notification operates UC-LOG-06 — Evaluate events and declare incidents against defined criteria
- Cybersecurity Incident Response operates UC-LOG-06 — Evaluate events and declare incidents against defined criteria
- UC-LOG-06 — Evaluate events and declare incidents against defined criteria maps_to CC7.3 — The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives (security incidents) and, if so, takes actions to prevent or address such failures.
- framework
- soc2
- control_id
- CC7.3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Trust Services Readiness tests UC-LOG-06 — Evaluate events and declare incidents against defined criteria
- UC-LOG-06 — Evaluate events and declare incidents against defined criteria mitigates No security monitoring or supervision of privileged activity
- strength
- primary
- rationale
- Defined criteria to evaluate events, declare incidents, and initiate response supply the escalation process for detected breaches that was absent.
- UC-LOG-06 — Evaluate events and declare incidents against defined criteria mitigates Data exfiltration and theft of information by attackers
- strength
- related
- rationale
- Declaring data-breach incidents against defined thresholds and notifying regulators/individuals reduces the impact of data theft.