{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Asset Management & Inventory","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ASSET-05","description":"Maintain an inventory of services provided by suppliers, including the systems and data each service touches and the internal owner of the relationship. Assess critical suppliers for security and risk before acquisition or engagement, record the results, and reassess when services, dependencies, or risk profiles change.","details":{"control_category":"administrative","control_type":"preventive","domain":"Asset Management & Inventory","guidance":[],"members":[{"control_id":"ID.AM-04","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"ID.RA-10","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"}],"statement":"Maintain an inventory of services provided by suppliers, including the systems and data each service touches and the internal owner of the relationship. Assess critical suppliers for security and risk before acquisition or engagement, record the results, and reassess when services, dependencies, or risk profiles change.","title":"Inventory supplier services and assess critical suppliers","unified_id":"UC-ASSET-05"},"id":"uc:UC-ASSET-05","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ASSET-05","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"UC-ASSET-05 — Inventory supplier services and assess critical suppliers","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2b39dea1f41ec6925635527ba42fbef030af39116ebf1171db3972580797c7de","properties":{"control_id":"ID.RA-10","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-05-11852f6d.json","sourceId":"uc:UC-ASSET-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-id-ra-10-47db8a41.json","targetId":"ctrl:nist-csf-2:ID.RA-10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:30f758b6275b12c5b575bf448212126e4e9f0abd24d0dd5cf1c6aaf60de5afd7","properties":{"rationale":"Supplier-service inventory records only the processor/sub-processor leg, a partial contribution; the authoritative data inventory, RoPA, and flow diagrams (UC-02) are the operative defense for this privacy risk.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-05-11852f6d.json","sourceId":"uc:UC-ASSET-05","targetDetailPath":"/data/v1/records/risk-data-inventory-flows-unmapped-fd7746f8.json","targetId":"risk:data-inventory-flows-unmapped","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3dbf1faba31192e4d2aff6be799b992b03f5ea2762d01f60ef51ecc5978f72db","properties":{},"sourceDetailPath":"/data/v1/records/wf-r6-824a647c.json","sourceId":"wf:R6","targetDetailPath":"/data/v1/records/uc-uc-asset-05-11852f6d.json","targetId":"uc:UC-ASSET-05","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:57622f962958f6be0fc2f989352c6a70d6a164134b44f6ffb370449ad54e188e","properties":{},"sourceDetailPath":"/data/v1/records/wf-g26-08681202.json","sourceId":"wf:G26","targetDetailPath":"/data/v1/records/uc-uc-asset-05-11852f6d.json","targetId":"uc:UC-ASSET-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:65ff119b731cae232898293d57fb816aae89dd398d87fa64c3dcb050706c03ec","properties":{},"sourceDetailPath":"/data/v1/records/wf-g13-0f34ff59.json","sourceId":"wf:G13","targetDetailPath":"/data/v1/records/uc-uc-asset-05-11852f6d.json","targetId":"uc:UC-ASSET-05","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:89ac9934e02b94d186d7d3aacf3e4b76d735a25f9a5b593c2107733ccc296ccb","properties":{"rationale":"Supplier-service inventory with named internal owners extends asset accountability to third-party services.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-05-11852f6d.json","sourceId":"uc:UC-ASSET-05","targetDetailPath":"/data/v1/records/risk-asset-inventory-gap-e18c7e73.json","targetId":"risk:asset-inventory-gap","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d9b69705c011d2d14749b33df793db6de84a3e9315aed4708cf15516c0f1df49","properties":{"control_id":"ID.AM-04","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-05-11852f6d.json","sourceId":"uc:UC-ASSET-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-id-am-04-da242629.json","targetId":"ctrl:nist-csf-2:ID.AM-04","type":"maps_to"}],"schemaVersion":1}
