{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-17","description":"Findings, recommendations, and management action plans - including improvements identified from security tests and exercises, and those coordinated with suppliers and third parties - are tracked in a follow-up process, and implementation is confirmed through evidence-based verification before closure. When management has accepted a level of risk that may exceed the organization's risk appetite, the matter is discussed with senior management and, if unresolved, escalated to the board. Follow-up logs and escalation records are retained.","details":{"control_category":"administrative","control_type":"detective","domain":"Compliance, Audit & Assurance","guidance":[],"members":[{"control_id":"Std 15.2","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"Std 11.5","coverage":"full","framework":"iia-2024","relationship":"superset_of"},{"control_id":"ID.IM-02","coverage":"partial","delta":"ID.IM-02's security-test-and-exercise-driven improvement is an operations outcome only partially covered by audit follow-up; its operational home is the improvement objective (UC-ASSET-11)","framework":"nist-csf-2","relationship":"intersects_with"}],"statement":"Findings, recommendations, and management action plans - including improvements identified from security tests and exercises, and those coordinated with suppliers and third parties - are tracked in a follow-up process, and implementation is confirmed through evidence-based verification before closure. When management has accepted a level of risk that may exceed the organization's risk appetite, the matter is discussed with senior management and, if unresolved, escalated to the board. Follow-up logs and escalation records are retained.","title":"Follow up on findings and escalate risk acceptance","unified_id":"UC-AUDIT-17"},"id":"uc:UC-AUDIT-17","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-17","sourceIds":["iia-2024","nist-csf-2"],"sourceUrl":null,"title":"UC-AUDIT-17 — Follow up on findings and escalate risk acceptance","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0807fab30b092f16c47bb7fad2daaae5f3c584607fa7f54c2f6b3b3f41a299ed","properties":{"control_id":"Std 15.2","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","sourceId":"uc:UC-AUDIT-17","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-15-2-3508a7c4.json","targetId":"ctrl:iia-2024:Std 15.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:16d524156c00161ea7e56db66b4f804f054edd942abdf093cf2de43b4c0e0f92","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","targetId":"uc:UC-AUDIT-17","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1d91d30656aa69c195e6359265a95d445cc7626eb4b45a349e69b6eab0da234c","properties":{},"sourceDetailPath":"/data/v1/records/wf-s3-0d4673bb.json","sourceId":"wf:S3","targetDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","targetId":"uc:UC-AUDIT-17","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1f5e6e3ef31d711591300f8333a8d8a43e3ab33422eedfb367446e0322e6c4dd","properties":{},"sourceDetailPath":"/data/v1/records/wf-c16-5cfe940e.json","sourceId":"wf:C16","targetDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","targetId":"uc:UC-AUDIT-17","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:290590ddc4fe885488f35afa162f6411c71a383d04b351ce30f5dd4922722850","properties":{},"sourceDetailPath":"/data/v1/records/wf-a4-1cfdd4d5.json","sourceId":"wf:A4","targetDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","targetId":"uc:UC-AUDIT-17","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:40b7e7552fdade6da60676efc49f543fc3d21b1f06fbcd18b9879e16873cfce8","properties":{"control_id":"Std 11.5","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","sourceId":"uc:UC-AUDIT-17","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-11-5-961b30d0.json","targetId":"ctrl:iia-2024:Std 11.5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4de2d177e0abba737d6b95765bcecc5e40aed137ee41021eb545c3f7fb5c8f4c","properties":{},"sourceDetailPath":"/data/v1/records/wf-g14-215df6e0.json","sourceId":"wf:G14","targetDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","targetId":"uc:UC-AUDIT-17","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:56b1a00a8942c03a19470534621c90ddf3c2f69540d53d91bf5a469ca50f004c","properties":{},"sourceDetailPath":"/data/v1/records/wf-d03-64dbfded.json","sourceId":"wf:D03","targetDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","targetId":"uc:UC-AUDIT-17","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8b2ccdfc9c53ac3b2a8175deb6d3eb7a6e52cf45f43e9e77f59aada842f0990c","properties":{},"sourceDetailPath":"/data/v1/records/wf-a2-163f5a6d.json","sourceId":"wf:A2","targetDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","targetId":"uc:UC-AUDIT-17","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9a07b7df090f88c1acbdeb515c47b435bb1c3d0e9def6b260cdd330d2d8bdecd","properties":{"rationale":"Escalating risk acceptance beyond appetite to senior management and the board is a governance safeguard supporting oversight.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","sourceId":"uc:UC-AUDIT-17","targetDetailPath":"/data/v1/records/risk-gov-oversight-failure-d98ffc12.json","targetId":"risk:gov-oversight-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b4efd24ec95319b65514666cc29309023becea19e0369864e64f04cbb2738b4d","properties":{},"sourceDetailPath":"/data/v1/records/wf-g33-6008159c.json","sourceId":"wf:G33","targetDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","targetId":"uc:UC-AUDIT-17","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cd597d768ec220b63cce472a5beb783b2ee046dc0a3bfc86523e136ca92e7717","properties":{},"sourceDetailPath":"/data/v1/records/wf-s16-ff1d0766.json","sourceId":"wf:S16","targetDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","targetId":"uc:UC-AUDIT-17","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ed8c02be773f95db7121d2d0ba24c793e8aa97b1d264d562e150d331bdf58ec8","properties":{"control_id":"ID.IM-02","coverage":"partial","delta":"ID.IM-02's security-test-and-exercise-driven improvement is an operations outcome only partially covered by audit follow-up; its operational home is the improvement objective (UC-ASSET-11)","framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","sourceId":"uc:UC-AUDIT-17","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-id-im-02-043092cd.json","targetId":"ctrl:nist-csf-2:ID.IM-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f7149a6dd56e17c0751c470c0143e0644d3945c9721f4e91e858bf7824282533","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-17-94dc7e0c.json","sourceId":"uc:UC-AUDIT-17","targetDetailPath":"/data/v1/records/risk-compliance-environmental-regulatory-5adf55ce.json","targetId":"risk:compliance-environmental-regulatory","type":"mitigates"}],"schemaVersion":1}
