{"aliases":{"wf:D07":"wf:D06","wf:D08":"wf:D06","wf:D09":"wf:D06","wf:D12":"wf:A15","wf:D13":"wf:A15","wf:D14":"wf:A15","wf:D15":"wf:A15","wf:D16":"wf:A15","wf:D17":"wf:A15","wf:D18":"wf:A15","wf:D19":"wf:A15","wf:D20":"wf:A15"},"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"metadata","limitations":["Source membership describes catalog relationships, not applicability to an organization.","Risk ratings are catalog examples, not assessments of an organization's risk.","Mapping coverage describes a documented relationship, not implementation, certification or legal compliance.","Guidance informs controls; it does not establish coverage of mandatory requirements.","Source catalogs may be selective. Missing records or mappings do not establish that a requirement is absent.","Missing source citations, dates and versions remain null. Source content retains its existing rights; this catalog grants no additional reuse rights."],"provenance":{"mapping":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"sourceVersions":{"aiuc-1":"July 15, 2026 release (quarterly update cadence)","ccpa":"CCPA (2018) as amended by CPRA (2020)","cobit-2019":"2019","coso-erm":"2017","coso-ic":"2013","dora":"Regulation (EU) 2022/2554","eu-ai-act":"Regulation (EU) 2024/1689","gdpr":"Regulation (EU) 2016/679","hipaa":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)","iia-2024":"2024 edition","iia-pos-2026-erm":"2026","iia-pos-2026-three-lines":"2026","iso-27001":"2022","iso-31000":"2018","iso-42001":"2023","nis2":"Directive (EU) 2022/2555","nist-800-53":"Rev. 5","nist-ai-agent-identity":"February 2026 draft concept paper","nist-ai-tevv-athlon":"NIST AI 200-2 ipd (Initial Public Draft), August 2026","nist-csf-2":"2.0","nydfs-500":"23 NYCRR 500, Second Amendment","pci-dss":"v4.0.1","soc1":"SSAE 18 (current AICPA SOC suite)","soc2":"2017 TSC","sox":"SOX §302/§404 (2002), PCAOB AS 2201"},"sources":{"aiuc-1":{"amendmentState":"quarterly standard updates; next release scheduled 2026-10-15","authority":"framework","effectiveDate":null,"note":"AIUC certification standard for deployed AI agents and systems. The July 15, 2026 release has 51 live requirements: 43 mandatory and 8 optional. E007 and E014 are retained as withdrawn placeholders. Numbered sub-controls (for example A008.1) are not modeled. Requirement status, frequency and source links were verified against the official pages on 2026-09-10. The community navigator still uses its April 2026 snapshot: its 51 rows include E007 and E014 and omit A008 and B010. Applicability depends on the agent capabilities and audit scope.","publicationDate":"2025-07 (initial); 2026-07-15 (current release)","reviewedAt":"2026-09-10","sourceUrl":"https://www.aiuc-1.com/","standard":"aiuc-1","title":"AIUC-1 — AI agent security, safety and reliability standard (requirement level)","version":"July 15, 2026 release (quarterly update cadence)"},"ccpa":{"amendmentState":"CPRA amendments; CPPA regulations","authority":"mandatory","effectiveDate":"2023-01-01 (CPRA operative)","note":null,"publicationDate":"2018-06-28","reviewedAt":null,"sourceUrl":null,"standard":"ccpa","title":"CCPA/CPRA — California Consumer Privacy","version":"CCPA (2018) as amended by CPRA (2020)"},"cobit-2019":{"amendmentState":"none","authority":"framework","effectiveDate":null,"note":null,"publicationDate":"2018-11","reviewedAt":null,"sourceUrl":null,"standard":"cobit-2019","title":"COBIT 2019 Governance & Management Objectives","version":"2019"},"coso-erm":{"amendmentState":"none","authority":"framework","effectiveDate":null,"note":null,"publicationDate":"2017-09","reviewedAt":null,"sourceUrl":null,"standard":"coso-erm","title":"COSO ERM – Integrating with Strategy and Performance (2017)","version":"2017"},"coso-ic":{"amendmentState":"none","authority":"framework","effectiveDate":null,"note":null,"publicationDate":"2013-05","reviewedAt":null,"sourceUrl":null,"standard":"coso-ic","title":"COSO Internal Control – Integrated Framework (2013)","version":"2013"},"dora":{"amendmentState":"none","authority":"mandatory","effectiveDate":"2025-01-17","note":null,"publicationDate":"2022-12-27","reviewedAt":null,"sourceUrl":null,"standard":"dora","title":"EU DORA — Digital Operational Resilience Act","version":"Regulation (EU) 2022/2554"},"eu-ai-act":{"amendmentState":"none","authority":"mandatory","effectiveDate":"2024-08-01 (staged application 2025-2027)","note":null,"publicationDate":"2024-07-12","reviewedAt":null,"sourceUrl":null,"standard":"eu-ai-act","title":"EU AI Act — principal obligation areas (Chapters II, III, V and IX)","version":"Regulation (EU) 2024/1689"},"gdpr":{"amendmentState":"none","authority":"mandatory","effectiveDate":"2018-05-25","note":null,"publicationDate":"2016-05-04","reviewedAt":null,"sourceUrl":null,"standard":"gdpr","title":"EU GDPR — General Data Protection Regulation","version":"Regulation (EU) 2016/679"},"hipaa":{"amendmentState":"Omnibus Final Rule (2013)","authority":"mandatory","effectiveDate":"2005-04-20 (Security Rule)","note":null,"publicationDate":"2003-02-20 (Security Rule)","reviewedAt":null,"sourceUrl":null,"standard":"hipaa","title":"HIPAA — Security, Privacy & Breach Notification","version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"iia-2024":{"amendmentState":"none","authority":"mandatory","effectiveDate":"2025-01-09","note":null,"publicationDate":"2024-01-09","reviewedAt":null,"sourceUrl":null,"standard":"iia-2024","title":"IIA 2024 Global Internal Audit Standards","version":"2024 edition"},"iia-pos-2026-erm":{"amendmentState":"none","authority":"guidance","effectiveDate":null,"note":"Local reviewed paper: The Role of the Internal Audit Function in Enterprise Risk Management","publicationDate":"2026","reviewedAt":null,"sourceUrl":null,"standard":"iia-pos-2026-erm","title":"The Role of the Internal Audit Function in Enterprise Risk Management","version":"2026"},"iia-pos-2026-three-lines":{"amendmentState":"none","authority":"guidance","effectiveDate":null,"note":"Local reviewed paper: Three Lines Model: Assurance and Advice in Support of Effective Governance","publicationDate":"2026","reviewedAt":null,"sourceUrl":null,"standard":"iia-pos-2026-three-lines","title":"Three Lines Model: Assurance and Advice in Support of Effective Governance","version":"2026"},"iso-27001":{"amendmentState":"Amd 1:2024","authority":"framework","effectiveDate":null,"note":null,"publicationDate":"2022-10-25","reviewedAt":null,"sourceUrl":null,"standard":"iso-27001","title":"ISO/IEC 27001:2022 Annex A","version":"2022"},"iso-31000":{"amendmentState":"none","authority":"framework","effectiveDate":null,"note":null,"publicationDate":"2018-02","reviewedAt":null,"sourceUrl":null,"standard":"iso-31000","title":"ISO 31000:2018 Risk Management (principles/framework/process)","version":"2018"},"iso-42001":{"amendmentState":"none","authority":"framework","effectiveDate":null,"note":null,"publicationDate":"2023-12-18","reviewedAt":null,"sourceUrl":null,"standard":"iso-42001","title":"ISO/IEC 42001:2023 Annex A (AI Management System)","version":"2023"},"nis2":{"amendmentState":"supplemented by Implementing Regulation (EU) 2024/2690 (digital-sector entities)","authority":"mandatory","effectiveDate":"2024-10-18 (transposition deadline 2024-10-17)","note":null,"publicationDate":"2022-12-27","reviewedAt":null,"sourceUrl":null,"standard":"nis2","title":"EU NIS2 Directive","version":"Directive (EU) 2022/2555"},"nist-800-53":{"amendmentState":"Release 5.2.0 (2025-08-27)","authority":"framework","effectiveDate":null,"note":null,"publicationDate":"2020-09-23","reviewedAt":null,"sourceUrl":null,"standard":"nist-800-53","title":"NIST SP 800-53 Rev 5 — Security and Privacy Controls","version":"Rev. 5"},"nist-ai-agent-identity":{"amendmentState":"Initial concept paper; comments closed 2026-04-02; project reviewing comments as of 2026-09-10","authority":"guidance","effectiveDate":null,"note":"Draft concept paper seeking input on a proposed NCCoE project. The seven selected topics below summarize questions and areas of exploration, not final requirements or a completed implementation guide. NIST-AGI identifiers are local catalog references, not NIST control numbers. The project focuses on enterprise agents; external agents from untrusted sources are outside its initial scope. The NIST AI Agent Standards Initiative, launched 2026-02-17, is a standards-development program rather than a certifiable standard: https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative","publicationDate":"2026-02-05","relatedSources":[{"publicationDate":"2026-02-17","sourceUrl":"https://www.nist.gov/artificial-intelligence/ai-agent-standards-initiative","status":"Standards-development initiative","title":"AI Agent Standards Initiative"},{"publicationDate":"2026-08-27","sourceUrl":"https://www.nist.gov/blogs/cybersecurity-insights/back-future-why-agentic-ai-needs-strong-identity-foundation","status":"NIST explanatory blog","title":"Back to the Future: Why Agentic AI Needs a Strong Identity Foundation"}],"reviewedAt":"2026-09-10","sourceUrl":"https://www.nccoe.nist.gov/sites/default/files/2026-02/accelerating-the-adoption-of-software-and-ai-agent-identity-and-authorization-concept-paper.pdf","standard":"nist-ai-agent-identity","title":"NIST NCCoE: Software and AI Agent Identity and Authorization","version":"February 2026 draft concept paper"},"nist-ai-tevv-athlon":{"amendmentState":"Initial public draft; public comments close 2026-10-06","authority":"guidance","effectiveDate":null,"note":"Initial public draft of a general AI evaluation framework, applicable to agentic systems. These six selected topics cover evaluation design and agent security testing; they are not a complete crosswalk of the publication. NIST-TEVV identifiers are local catalog references, not NIST control numbers. The confidentiality, injection, and tool-abuse topics relate to the lethal trifecta, but the draft does not prescribe an architecture that makes that combination safe or a required testing frequency.","publicationDate":"2026-08-07","reviewedAt":"2026-09-10","sourceUrl":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf","standard":"nist-ai-tevv-athlon","title":"NIST AI 200-2: TEVV-Athlon Framework for Evaluating AI Systems","version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"nist-csf-2":{"amendmentState":"none","authority":"framework","effectiveDate":null,"note":null,"publicationDate":"2024-02-26","reviewedAt":null,"sourceUrl":null,"standard":"nist-csf-2","title":"NIST Cybersecurity Framework 2.0","version":"2.0"},"nydfs-500":{"amendmentState":"Second Amendment (2023)","authority":"mandatory","effectiveDate":"2023-11-01 (phased through 2025-11-01)","note":null,"publicationDate":"2023-11-01","reviewedAt":null,"sourceUrl":null,"standard":"nydfs-500","title":"NYDFS Part 500 — NY Cybersecurity Regulation","version":"23 NYCRR 500, Second Amendment"},"pci-dss":{"amendmentState":"v4.0 retired 2024-12-31","authority":"mandatory","effectiveDate":"2025-03-31 (future-dated requirements)","note":null,"publicationDate":"2024-06-11","reviewedAt":null,"sourceUrl":null,"standard":"pci-dss","title":"PCI DSS v4.0.1","version":"v4.0.1"},"soc1":{"amendmentState":"subsequent SSAE amendments (SSAE 19-22)","authority":"framework","effectiveDate":"2017-05-01 (SSAE 18)","note":"Illustrative control-objective taxonomy: SSAE 18 / ISAE 3402 publish no universal SOC 1 control catalog — objectives and controls are defined per service organization in each report.","publicationDate":"2016-04 (SSAE 18)","reviewedAt":null,"sourceUrl":null,"standard":"soc1","title":"SOC 1 (SSAE 18 / ISAE 3402) — service-org ICFR control objectives","version":"SSAE 18 (current AICPA SOC suite)"},"soc2":{"amendmentState":"revised points of focus (2022)","authority":"framework","effectiveDate":null,"note":null,"publicationDate":"2017","reviewedAt":null,"sourceUrl":null,"standard":"soc2","title":"AICPA SOC 2 Trust Services Criteria (2017, rev. 2022)","version":"2017 TSC"},"sox":{"amendmentState":"current SEC/PCAOB requirements","authority":"mandatory","effectiveDate":null,"note":"Illustrative ICFR control taxonomy: SOX §404 and PCAOB AS 2201 publish no universal control list — controls are defined by each registrant's own risk assessment.","publicationDate":"2002-07-30","reviewedAt":null,"sourceUrl":null,"standard":"sox","title":"SOX 404 / PCAOB AS 2201 — ICFR control taxonomy","version":"SOX §302/§404 (2002), PCAOB AS 2201"}}},"schemaVersion":1}
