{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Asset Management & Inventory","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ASSET-06","description":"Define, communicate, and require acknowledgment of acceptable-use rules for information and associated assets. Protect user endpoint devices with enforced safeguards such as encryption, screen locking, and centralized management, and protect organizational assets used off premises against loss, theft, and observation. Permit use of or connection to external systems only under established terms and conditions consistent with the trust relationship, including restrictions on processing organizational information and on portable storage.","details":{"control_category":"administrative","control_type":"preventive","domain":"Asset Management & Inventory","guidance":[],"members":[{"control_id":"AC-20","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.5.10","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"A.7.9","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"A.8.1","coverage":"full","framework":"iso-27001","relationship":"superset_of"}],"statement":"Define, communicate, and require acknowledgment of acceptable-use rules for information and associated assets. Protect user endpoint devices with enforced safeguards such as encryption, screen locking, and centralized management, and protect organizational assets used off premises against loss, theft, and observation. Permit use of or connection to external systems only under established terms and conditions consistent with the trust relationship, including restrictions on processing organizational information and on portable storage.","title":"Govern acceptable use of endpoints, off-site, and external systems","unified_id":"UC-ASSET-06"},"id":"uc:UC-ASSET-06","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ASSET-06","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0193ee372df87471f989640b9a67875fec12d77ca2480b3c725772ea14d52169","properties":{"control_id":"A.8.1","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-1-12f14999.json","targetId":"ctrl:iso-27001:A.8.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0f7fc9418e610b233e1597b8914139fa8016890e22f9cc78cb8b6d3876663f2b","properties":{"rationale":"Acceptable-use rules, portable-storage restrictions, and centrally-managed endpoints prevent uncontrolled copying and unmanaged installs.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/risk-asset-uncontrolled-copying-removable-media-4a9604c7.json","targetId":"risk:asset-uncontrolled-copying-removable-media","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:18457278e43b410f52161ca8640e0370690eb4a499175ad48b54070e4905c372","properties":{"control_id":"A.7.9","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-9-43947bba.json","targetId":"ctrl:iso-27001:A.7.9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:31d4766507f616a18e21915b3fccc99dee4b9c5f6529addfa16349a82f9f69f5","properties":{"rationale":"Defining, communicating, and acknowledging acceptable-use rules closes the missing acceptable-use dimension of the gap.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/risk-asset-inventory-gap-e18c7e73.json","targetId":"risk:asset-inventory-gap","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:413bff0a4c011bdb77bc0343e3367618e8409e48951a34b61d0b11c6ce200ac6","properties":{"rationale":"Acceptable-use enforcement and locked-down centrally-managed endpoints prevent installation of unlicensed/pirated software.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/risk-tech-unlicensed-counterfeit-software-91025350.json","targetId":"risk:tech-unlicensed-counterfeit-software","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4b1b9368e99e381c022fb46fef6daccb8f0d969705a80b44c0d69393f19219a0","properties":{},"sourceDetailPath":"/data/v1/records/wf-c39-df8b318a.json","sourceId":"wf:C39","targetDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","targetId":"uc:UC-ASSET-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6211dca87613b36dc26a16c224980c7d5e044c31c777bf4c86c9880d1a51ee8e","properties":{"control_id":"A.5.10","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-10-2d5f0877.json","targetId":"ctrl:iso-27001:A.5.10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6aab0c7e7d5c5a6bfe31b20a571849612638f9dacf4c7ffdc72526a0c1ba393c","properties":{},"sourceDetailPath":"/data/v1/records/wf-c7-acbef2ee.json","sourceId":"wf:C7","targetDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","targetId":"uc:UC-ASSET-06","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6af614e2df6e6cbc6408a920bff22a8f313e53b22bf9fd40b97a28f4fb1e3822","properties":{"control_id":"AC-20","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-20-6e822026.json","targetId":"ctrl:nist-800-53:AC-20","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:87f8aba456988e9f7f78a19678e920f244d2739690420bda661c830acbcd574a","properties":{"rationale":"Endpoint encryption plus off-premises loss/theft protection directly reduces exposure from stolen or unattended devices.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/risk-phys-theft-of-equipment-media-c64433e7.json","targetId":"risk:phys-theft-of-equipment-media","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fc1c7dc5df8a4a933a01e0b19e219545912229998e9307c8b7dd3ec1df0e922b","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","targetId":"uc:UC-ASSET-06","type":"tests"}],"schemaVersion":1}
