{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Asset Management & Inventory","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ASSET-03","description":"Classify information and associated assets under a documented scheme based on sensitivity, criticality, and business impact, and prioritize assets and protections accordingly. Apply labels and markings, including on physical media, that identify the classification and any distribution or handling limitations. Identify confidential information at creation or receipt and keep classifications and priorities current through periodic review.","details":{"control_category":"administrative","control_type":"preventive","domain":"Asset Management & Inventory","guidance":[],"members":[{"control_id":"MP-3","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"ID.AM-05","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"A.5.12","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"A.5.13","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"C1.1","coverage":"partial","delta":"also requires retaining and protecting confidential information per commitments","framework":"soc2","relationship":"intersects_with"}],"statement":"Classify information and associated assets under a documented scheme based on sensitivity, criticality, and business impact, and prioritize assets and protections accordingly. Apply labels and markings, including on physical media, that identify the classification and any distribution or handling limitations. Identify confidential information at creation or receipt and keep classifications and priorities current through periodic review.","title":"Classify, prioritize, and label information and assets","unified_id":"UC-ASSET-03"},"id":"uc:UC-ASSET-03","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ASSET-03","sourceIds":["iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"UC-ASSET-03 — Classify, prioritize, and label information and assets","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:01dcbab9f8a9080a570c60b89567964277e2b0bf259a308fbd22f7bb7c492dfc","properties":{"control_id":"ID.AM-05","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","sourceId":"uc:UC-ASSET-03","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-id-am-05-7a0a0226.json","targetId":"ctrl:nist-csf-2:ID.AM-05","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0cc13bd9a438aebb2a3925b8fa606ed37316076ba3fddfcb5a20e794a1e66c93","properties":{},"sourceDetailPath":"/data/v1/records/wf-d21-5f7f687f.json","sourceId":"wf:D21","targetDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","targetId":"uc:UC-ASSET-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:22b18eefbfe2be7c988d0b42b405a97fd092c6a8f9f6dfd40a29a68645341239","properties":{"rationale":"Classifying and labelling information/assets directly remediates the missing classification/labelling this risk names in its title and description.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","sourceId":"uc:UC-ASSET-03","targetDetailPath":"/data/v1/records/risk-asset-inventory-gap-e18c7e73.json","targetId":"risk:asset-inventory-gap","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:23c9f00c486336bf33a43a03852482c4d0114e4d6a808dbb0c0a7f77120de34e","properties":{"rationale":"Marking media by classification drives correct secure-disposal handling of sensitive media before release.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","sourceId":"uc:UC-ASSET-03","targetDetailPath":"/data/v1/records/risk-data-residual-media-disposal-92de3d1d.json","targetId":"risk:data-residual-media-disposal","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3165ad3f02bcdb9746b97d6edcc165a99e985acca005200d7abf6cd12495da6a","properties":{"control_id":"A.5.13","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","sourceId":"uc:UC-ASSET-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-13-b1e84751.json","targetId":"ctrl:iso-27001:A.5.13","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:36569c96d581a0f13c86b5cebcc2272b76c64149dd4942b9c22b3145bcbefe45","properties":{"control_id":"A.5.12","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","sourceId":"uc:UC-ASSET-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-12-eb4887b2.json","targetId":"ctrl:iso-27001:A.5.12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:54b7d332942ab117fce6604bab2f7463c370f5fdf41f7a96ff1b02b2d3edf26c","properties":{"rationale":"Identifying and labelling proprietary/confidential info enforces handling restrictions that reduce trade-secret loss.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","sourceId":"uc:UC-ASSET-03","targetDetailPath":"/data/v1/records/risk-compliance-ip-infringement-337b44a1.json","targetId":"risk:compliance-ip-infringement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:75a4ab21603b03325650582b39de6c6f1d26ff5ea644a6df928dbdbc615b62b0","properties":{"control_id":"MP-3","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","sourceId":"uc:UC-ASSET-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-mp-3-d8526201.json","targetId":"ctrl:nist-800-53:MP-3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8d4309770271c414ad94e93c51ef5e25bf569a7362e4fd2b05bc4ab301888a3c","properties":{},"sourceDetailPath":"/data/v1/records/wf-c7-acbef2ee.json","sourceId":"wf:C7","targetDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","targetId":"uc:UC-ASSET-03","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c3830f0a941486428e1158125fc1bccab5c816455ed9c8efda00001e7009dbf3","properties":{"rationale":"Prioritizing protection by criticality directs stronger physical safeguards to high-value assets, reducing theft impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","sourceId":"uc:UC-ASSET-03","targetDetailPath":"/data/v1/records/risk-phys-theft-of-equipment-media-c64433e7.json","targetId":"risk:phys-theft-of-equipment-media","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cdb17b52b9023dd9ad533147a7982ac9abc5cc12289b34097aaadb95c40a3d4f","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","targetId":"uc:UC-ASSET-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e6898673f73ec6c2c52ac2d0a6b02ae79c6b507573fb96d6f74d5fd137d5ff6e","properties":{"control_id":"C1.1","coverage":"partial","delta":"also requires retaining and protecting confidential information per commitments","framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","sourceId":"uc:UC-ASSET-03","targetDetailPath":"/data/v1/records/ctrl-soc2-c1-1-d20576fd.json","targetId":"ctrl:soc2:C1.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb69b1d6af44a17e9e721a4affbaab8a9494a8712cd1d267c37880774d5bb867","properties":{},"sourceDetailPath":"/data/v1/records/wf-c38-485b6728.json","sourceId":"wf:C38","targetDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","targetId":"uc:UC-ASSET-03","type":"operates"}],"schemaVersion":1}
