{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-23","description":"The organization plans and obtains independent reviews of its approach to managing and implementing information security - including people, processes, and technologies - at planned intervals, after significant changes, and where required by applicable law or regulation. Before relying on another provider's work, each reliance decision assesses and records the provider's independence and objectivity, competence and methodology rigor, evidence quality and reperformance capability, and recency against the covered risk's cadence, together with the resulting reliance level and rationale. Assurance activities are coordinated across internal and external providers to ensure coverage, minimize duplication, and support reliance on others' work. Material reliance limitations, assurance gaps, and duplication remain visible to management and the board. Results are reported to management and the board and drive corrective actions.","details":{"control_category":"administrative","control_type":"detective","domain":"Compliance, Audit & Assurance","guidance":[{"propositionId":"IIA-POS-TLM-03","propositionTitle":"Assurance Coordination and Reliance","source":"iia-pos-2026-three-lines","sourcePages":"Three Lines pp. 15–16, 18–19","sourceTitle":"Three Lines Model: Assurance and Advice in Support of Effective Governance"}],"members":[{"control_id":"A.5.35","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"CCPA-1798.185","coverage":"partial","delta":"risk-assessment submission obligations handled under risk management controls","framework":"ccpa","relationship":"intersects_with"},{"control_id":"MEA04","coverage":"full","framework":"cobit-2019","relationship":"superset_of"},{"control_id":"Std 9.5","coverage":"full","framework":"iia-2024","relationship":"superset_of"}],"statement":"The organization plans and obtains independent reviews of its approach to managing and implementing information security - including people, processes, and technologies - at planned intervals, after significant changes, and where required by applicable law or regulation. Before relying on another provider's work, each reliance decision assesses and records the provider's independence and objectivity, competence and methodology rigor, evidence quality and reperformance capability, and recency against the covered risk's cadence, together with the resulting reliance level and rationale. Assurance activities are coordinated across internal and external providers to ensure coverage, minimize duplication, and support reliance on others' work. Material reliance limitations, assurance gaps, and duplication remain visible to management and the board. Results are reported to management and the board and drive corrective actions.","title":"Coordinate independent assurance reviews across providers","unified_id":"UC-AUDIT-23"},"id":"uc:UC-AUDIT-23","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-23","sourceIds":["ccpa","cobit-2019","iia-2024","iia-pos-2026-three-lines","iso-27001"],"sourceUrl":null,"title":"UC-AUDIT-23 — Coordinate independent assurance reviews across providers","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:083eb07ca149e8112ed6cf7541a60e05026915716647852270d94d91d25914e5","properties":{"rationale":"Planning and obtaining independent reviews of information security at intervals and after change (ISO A.5.35) is the independent-review control this risk lacks.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","sourceId":"uc:UC-AUDIT-23","targetDetailPath":"/data/v1/records/risk-compliance-no-independent-audit-9e1acf0f.json","targetId":"risk:compliance-no-independent-audit","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:10ab744fc2f05812744d0be837bb31e3211af44a5d3e5027b8455f310249bb3a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c16-5cfe940e.json","sourceId":"wf:C16","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:48303bab97616f0e5f1342e26f5dd1bca6d01ba43e99eaa60d8ee32cec2458af","properties":{},"sourceDetailPath":"/data/v1/records/wf-g33-6008159c.json","sourceId":"wf:G33","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6a3558ec7e9a10fd979fb2146dad124e9e35ecb0607b2fe082cd69dd44934bc9","properties":{},"sourceDetailPath":"/data/v1/records/wf-c17-334c380f.json","sourceId":"wf:C17","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6e8ccc435a5fcf927ce307de1a1e12e8921071d5f9e7484da8836b088cd51f71","properties":{},"sourceDetailPath":"/data/v1/records/wf-d05-2302db1f.json","sourceId":"wf:D05","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:75a79039f825fe12949becc0699504543d81d39d52729d9e782eea75558bc642","properties":{"control_id":"MEA04","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","sourceId":"uc:UC-AUDIT-23","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-mea04-4181ede5.json","targetId":"ctrl:cobit-2019:MEA04","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:85201cd31f0ee0e6db246c32a2fc40ce83139071e77d05dea752549461bcd912","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","sourceId":"uc:UC-AUDIT-23","targetDetailPath":"/data/v1/records/risk-ai-highrisk-critical-infra-a7a37365.json","targetId":"risk:ai-highrisk-critical-infra","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9ae7358f763b8260c0f6fe9fa493cc2557b41b004c96ffa66e0f0b76d399a7dd","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9faf8a94071e8116b366bb45920bf621cc6c6119423787e39bfe5790e13c6009","properties":{},"sourceDetailPath":"/data/v1/records/wf-a1-f09c8201.json","sourceId":"wf:A1","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a092db43ec68d7cc5bf48c7b8adcbc0c9aeff13ff38233c27c9ff01bc82eaab7","properties":{"control_id":"CCPA-1798.185","coverage":"partial","delta":"risk-assessment submission obligations handled under risk management controls","framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","sourceId":"uc:UC-AUDIT-23","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-185-1b524211.json","targetId":"ctrl:ccpa:CCPA-1798.185","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:be5aeb5693e3be70bce1e031c4ec9c7937b924cdf5a63cc744b28e91df38b3f7","properties":{"control_id":"Std 9.5","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","sourceId":"uc:UC-AUDIT-23","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-9-5-0fb8f00f.json","targetId":"ctrl:iia-2024:Std 9.5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c3e2e4095692ac831fe61e17f631e6439562fa229cca872fb0423ed8b6e53842","properties":{"control_id":"A.5.35","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","sourceId":"uc:UC-AUDIT-23","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-35-9b5c5f1a.json","targetId":"ctrl:iso-27001:A.5.35","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c7e7cd6a2b9b5bf85a122d9970f37b1ec15b114f5b816136f898d82252b7ae92","properties":{"control_id":"IIA-POS-TLM-03","coverage":"guidance","delta":null,"framework":"iia-pos-2026-three-lines","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Three Lines pp. 15–16, 18–19","source_version":"2026"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","sourceId":"uc:UC-AUDIT-23","targetDetailPath":"/data/v1/records/ctrl-iia-pos-2026-three-lines-iia-pos-tlm-03-95334e6e.json","targetId":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-03","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f9caea0220c0f389ba0f63c3e49c48ade41cc55cfbf31a8af1df6c617bbedd4e","properties":{},"sourceDetailPath":"/data/v1/records/wf-g2-bd9bee15.json","sourceId":"wf:G2","targetDetailPath":"/data/v1/records/uc-uc-audit-23-124d94d5.json","targetId":"uc:UC-AUDIT-23","type":"tests"}],"schemaVersion":1}
