{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"AI Governance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-25","description":"Configure code-generating AI systems with secure-by-default guidance: steer generated code toward parameterized queries and safe frameworks for common vulnerability classes, established authentication and authorization libraries, secure session and cookie settings, input validation and safe error handling, and logging that excludes secrets; require pinned, verified dependency specifications so hallucinated or typosquatted packages are not introduced; and test the guidance against a vulnerability benchmark on change. Retain system-prompt and policy configurations and benchmark results as evidence.","details":{"control_category":"technical","control_type":"preventive","domain":"AI Governance","guidance":[],"members":[{"control_id":"B010","coverage":"full","framework":"aiuc-1","relationship":"equal"}],"statement":"Configure code-generating AI systems with secure-by-default guidance: steer generated code toward parameterized queries and safe frameworks for common vulnerability classes, established authentication and authorization libraries, secure session and cookie settings, input validation and safe error handling, and logging that excludes secrets; require pinned, verified dependency specifications so hallucinated or typosquatted packages are not introduced; and test the guidance against a vulnerability benchmark on change. Retain system-prompt and policy configurations and benchmark results as evidence.","title":"Guide code-generating systems toward secure patterns and safe dependencies","unified_id":"UC-AI-25"},"id":"uc:UC-AI-25","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AI-25","sourceIds":["aiuc-1"],"sourceUrl":null,"title":"UC-AI-25 — Guide code-generating systems toward secure patterns and safe dependencies","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:12a9f0c66a8f67e68815d7b85bd3ea19fe7a31b0c571551b1da17d52629ce157","properties":{"control_id":"B010","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-25-21e48906.json","sourceId":"uc:UC-AI-25","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b010-a075f8e3.json","targetId":"ctrl:aiuc-1:B010","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5c3c9a588f4dde7c6fd82e5253243b4c08407e5bfc73c632832f13f2b274825c","properties":{"rationale":"Secure-by-default guidance and pinned, verified dependency specification for code-generating systems directly counter insecure generated code and hallucinated packages.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-25-21e48906.json","sourceId":"uc:UC-AI-25","targetDetailPath":"/data/v1/records/risk-ai-insecure-generated-code-ec50f0f9.json","targetId":"risk:ai-insecure-generated-code","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5dc3789e10cc1ea60882e166959040d5d271f5f4aa78e439993e91908cec1678","properties":{},"sourceDetailPath":"/data/v1/records/wf-c66-26a4ed19.json","sourceId":"wf:C66","targetDetailPath":"/data/v1/records/uc-uc-ai-25-21e48906.json","targetId":"uc:UC-AI-25","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f6728b5a66c4a5e07bdbb22f6529aa5a679042c9930a2638026587b52c4b8ae9","properties":{"rationale":"Guidance to reference secret managers rather than hardcode credentials keeps secrets out of generated code.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-25-21e48906.json","sourceId":"uc:UC-AI-25","targetDetailPath":"/data/v1/records/risk-ai-secrets-credential-leakage-abf1bf77.json","targetId":"risk:ai-secrets-credential-leakage","type":"mitigates"}],"schemaVersion":1}
