{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Risk Assessment & Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ASSET-10","description":"Manage changes and exceptions to the environment and to security requirements through a process that assesses risk impact before approval. Record each change or exception with its assessment, approver, owner, and expiry or review date, and track open items to closure.","details":{"control_category":"administrative","control_type":"preventive","domain":"Risk Assessment & Management","guidance":[],"members":[{"control_id":"ID.RA-07","coverage":"full","framework":"nist-csf-2","relationship":"equal"}],"statement":"Manage changes and exceptions to the environment and to security requirements through a process that assesses risk impact before approval. Record each change or exception with its assessment, approver, owner, and expiry or review date, and track open items to closure.","title":"Assess and track changes and exceptions for risk impact","unified_id":"UC-ASSET-10"},"id":"uc:UC-ASSET-10","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ASSET-10","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"UC-ASSET-10 — Assess and track changes and exceptions for risk impact","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:00ddc579a64ca8f05b272db05bb2e820e1c2445c5de372adfcb22b9ce5bab162","properties":{},"sourceDetailPath":"/data/v1/records/wf-c13-1ffe161d.json","sourceId":"wf:C13","targetDetailPath":"/data/v1/records/uc-uc-asset-10-bbda2a79.json","targetId":"uc:UC-ASSET-10","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4ec6630df08c5ab168ab44645fd41a8871e501f0529c34b79ebb0185897aa741","properties":{},"sourceDetailPath":"/data/v1/records/wf-g14-215df6e0.json","sourceId":"wf:G14","targetDetailPath":"/data/v1/records/uc-uc-asset-10-bbda2a79.json","targetId":"uc:UC-ASSET-10","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7681da994aaa0f9683b6639a0b444940f026f2d011fb9fade6de551f02768aaa","properties":{"control_id":"ID.RA-07","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-10-bbda2a79.json","sourceId":"uc:UC-ASSET-10","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-id-ra-07-2a084fae.json","targetId":"ctrl:nist-csf-2:ID.RA-07","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:768cfe87026c49224518b28664b9257316a11f7bd99f9a818cc6178b8c8e0e0b","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-10-bbda2a79.json","sourceId":"uc:UC-ASSET-10","targetDetailPath":"/data/v1/records/risk-strategic-ma-integration-a958c14e.json","targetId":"risk:strategic-ma-integration","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d992594f5cca715ae32ca0517b346d2c49e88b3e77dd1b1642d63829bde8e660","properties":{"rationale":"Assessing and expiring exceptions to security requirements reduces lingering security gaps that attackers exploit, shrinking attack surface.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-10-bbda2a79.json","sourceId":"uc:UC-ASSET-10","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"}],"schemaVersion":1}
