{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-22","description":"Leadership periodically reviews the cybersecurity and risk management strategy and program performance against defined metrics, targets, and conformance requirements. Review outcomes are used to adjust strategy, direction, and program activities to ensure coverage of organizational requirements and risks. Performance and conformance monitoring follows a defined cadence with documented results and assigned follow-up actions.","details":{"control_category":"administrative","control_type":"detective","domain":"Compliance, Audit & Assurance","guidance":[],"members":[{"control_id":"GV.OV-02","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GV.OV-03","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"MEA01","coverage":"full","framework":"cobit-2019","relationship":"superset_of"}],"statement":"Leadership periodically reviews the cybersecurity and risk management strategy and program performance against defined metrics, targets, and conformance requirements. Review outcomes are used to adjust strategy, direction, and program activities to ensure coverage of organizational requirements and risks. Performance and conformance monitoring follows a defined cadence with documented results and assigned follow-up actions.","title":"Review risk strategy and performance with leadership","unified_id":"UC-AUDIT-22"},"id":"uc:UC-AUDIT-22","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-22","sourceIds":["cobit-2019","nist-csf-2"],"sourceUrl":null,"title":"UC-AUDIT-22 — Review risk strategy and performance with leadership","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:15bfd3ee8584c7ef9b65268ff9c9ee6c761a56e968c10f282c5a0c3827f73eb2","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-22-2a70149b.json","sourceId":"uc:UC-AUDIT-22","targetDetailPath":"/data/v1/records/risk-compliance-selection-exposure-limits-8640d0d6.json","targetId":"risk:compliance-selection-exposure-limits","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:370cdf65e7c075f535cb8de2c18981945e047981f1fb17ea8691fdd1d54baef6","properties":{"control_id":"MEA01","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-22-2a70149b.json","sourceId":"uc:UC-AUDIT-22","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-mea01-d0c28364.json","targetId":"ctrl:cobit-2019:MEA01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4bde47f051fc342b2775a938985e32c5291436fa9a3c1d345163b4af1bab572e","properties":{},"sourceDetailPath":"/data/v1/records/wf-c16-5cfe940e.json","sourceId":"wf:C16","targetDetailPath":"/data/v1/records/uc-uc-audit-22-2a70149b.json","targetId":"uc:UC-AUDIT-22","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6faf3d3528c52dcfcd7674b4a957807f6442281522504461f3d09ccd761aebcd","properties":{"control_id":"GV.OV-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-22-2a70149b.json","sourceId":"uc:UC-AUDIT-22","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-ov-02-d7467a40.json","targetId":"ctrl:nist-csf-2:GV.OV-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:869f4f79a79d5a5acff41f8328988b52d1e2da7f9a44c0635aa3b3d5fbbbc462","properties":{},"sourceDetailPath":"/data/v1/records/wf-d05-2302db1f.json","sourceId":"wf:D05","targetDetailPath":"/data/v1/records/uc-uc-audit-22-2a70149b.json","targetId":"uc:UC-AUDIT-22","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:930f418d6fb2fb0993099447e2b1630c944872e34a3115b916f946cc9a9b576b","properties":{"rationale":"Leadership periodically reviewing risk/cyber strategy and program performance against metrics and adjusting direction is the operative oversight mechanism.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-22-2a70149b.json","sourceId":"uc:UC-AUDIT-22","targetDetailPath":"/data/v1/records/risk-gov-oversight-failure-d98ffc12.json","targetId":"risk:gov-oversight-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b603542f3ae416b72f46e901540d3878678cf32b7a61f142a595aca2bec1b590","properties":{},"sourceDetailPath":"/data/v1/records/wf-g15-1231bc14.json","sourceId":"wf:G15","targetDetailPath":"/data/v1/records/uc-uc-audit-22-2a70149b.json","targetId":"uc:UC-AUDIT-22","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:db17795d8928def27e40f164b3e5bb0112f6480b19ab19b8fda37f100006b6f9","properties":{},"sourceDetailPath":"/data/v1/records/wf-c2-a1078981.json","sourceId":"wf:C2","targetDetailPath":"/data/v1/records/uc-uc-audit-22-2a70149b.json","targetId":"uc:UC-AUDIT-22","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f12b59f934696db4cc3fd528ef9ee0ce74a16bff27fb09bb754fa758d3beef67","properties":{},"sourceDetailPath":"/data/v1/records/wf-g10-3ef59294.json","sourceId":"wf:G10","targetDetailPath":"/data/v1/records/uc-uc-audit-22-2a70149b.json","targetId":"uc:UC-AUDIT-22","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fd08aeac6a3d3eaf25170c4b641c66c9bedd6ea71171f26cc7a31c3fcf341f52","properties":{"control_id":"GV.OV-03","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-22-2a70149b.json","sourceId":"uc:UC-AUDIT-22","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-ov-03-fc445da9.json","targetId":"ctrl:nist-csf-2:GV.OV-03","type":"maps_to"}],"schemaVersion":1}
