{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Incident Management & Response","type":"corrective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ASSET-11","description":"Identify improvements from the execution of operational processes, procedures, and activities, and track them to implementation. Establish, communicate, maintain, and improve incident response and other cybersecurity plans that affect operations, updating them after exercises, incidents, and significant organizational or technical change.","details":{"control_category":"administrative","control_type":"corrective","domain":"Incident Management & Response","guidance":[],"members":[{"control_id":"ID.IM-03","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"ID.IM-04","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"}],"statement":"Identify improvements from the execution of operational processes, procedures, and activities, and track them to implementation. Establish, communicate, maintain, and improve incident response and other cybersecurity plans that affect operations, updating them after exercises, incidents, and significant organizational or technical change.","title":"Improve security plans and processes from operational lessons","unified_id":"UC-ASSET-11"},"id":"uc:UC-ASSET-11","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ASSET-11","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"UC-ASSET-11 — Improve security plans and processes from operational lessons","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5db466de5a68a2dd57f8ab1550f17a800103f6022a0e9a9015105f029d409d4e","properties":{},"sourceDetailPath":"/data/v1/records/wf-g7-9762f11b.json","sourceId":"wf:G7","targetDetailPath":"/data/v1/records/uc-uc-asset-11-714d9672.json","targetId":"uc:UC-ASSET-11","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:740e58e14751893cb5175bc1472c681f44be6a30ad1ff7dca82623e3b780ddc5","properties":{},"sourceDetailPath":"/data/v1/records/wf-c3-4a88b225.json","sourceId":"wf:C3","targetDetailPath":"/data/v1/records/uc-uc-asset-11-714d9672.json","targetId":"uc:UC-ASSET-11","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8321a47cdb8c384917780541f5cbcdd12c53d581dffe9522292f4ccfe97c7d2c","properties":{"control_id":"ID.IM-04","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-11-714d9672.json","sourceId":"uc:UC-ASSET-11","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-id-im-04-93704ca6.json","targetId":"ctrl:nist-csf-2:ID.IM-04","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b0cbcb81f4d7a7638860eb26508a2f09872633ab9036cbb4cdfa083e233d15a4","properties":{},"sourceDetailPath":"/data/v1/records/wf-c14-c6170cdd.json","sourceId":"wf:C14","targetDetailPath":"/data/v1/records/uc-uc-asset-11-714d9672.json","targetId":"uc:UC-ASSET-11","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:be2b2fe7f2eb6dae8e3680057e08a439df259ada2933b5eafe7ab233e03ef554","properties":{"rationale":"Improving IR/cyber plans after exercises and incidents is a second-order feedback loop presupposing the base procedures UC-IR-01/02 establish and test; it contributes but is not the operative defense against their absence.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-11-714d9672.json","sourceId":"uc:UC-ASSET-11","targetDetailPath":"/data/v1/records/risk-ir-no-response-procedures-90eb7ba1.json","targetId":"risk:ir-no-response-procedures","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e088459e8c3e1cc9f24c506361f017e5214a5f82b874bb1a67f662f3eea303d4","properties":{"control_id":"ID.IM-03","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-11-714d9672.json","sourceId":"uc:UC-ASSET-11","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-id-im-03-11553f88.json","targetId":"ctrl:nist-csf-2:ID.IM-03","type":"maps_to"}],"schemaVersion":1}
