{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Compliance, Audit & Assurance","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-26","description":"A senior accountable official formally authorizes each system to operate before production use, based on the assessed security and privacy risk to organizational operations, assets, and individuals, and reauthorizes on a defined frequency or after significant change. Internal system connections are authorized prior to establishment and documented, including interface characteristics, security and privacy requirements, and the information communicated. Authorization decisions and connection documentation are retained.","details":{"control_category":"administrative","control_type":"preventive","domain":"Compliance, Audit & Assurance","guidance":[],"members":[{"control_id":"CA-6","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"CA-9","coverage":"partial","delta":"periodic review of each internal connection's continued need and termination when no longer required (CA-9(c)-(d))","framework":"nist-800-53","relationship":"intersects_with"}],"statement":"A senior accountable official formally authorizes each system to operate before production use, based on the assessed security and privacy risk to organizational operations, assets, and individuals, and reauthorizes on a defined frequency or after significant change. Internal system connections are authorized prior to establishment and documented, including interface characteristics, security and privacy requirements, and the information communicated. Authorization decisions and connection documentation are retained.","title":"Authorize systems and internal connections before operation","unified_id":"UC-AUDIT-26"},"id":"uc:UC-AUDIT-26","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-AUDIT-26","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-AUDIT-26 — Authorize systems and internal connections before operation","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2764e936a870e056cf27912720b627f30ca6a54d59efd44df22189fdf25516cf","properties":{"rationale":"The authorization gate forces security/privacy risk to be assessed before operation, contributing to catching unlawful processing, but the operative lawful-basis/consent/DPIA controls directly prevent illegal data processing.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-26-3a91d068.json","sourceId":"uc:UC-AUDIT-26","targetDetailPath":"/data/v1/records/risk-tech-illegal-data-processing-859983e3.json","targetId":"risk:tech-illegal-data-processing","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2d2df9d16137b2dd228e5367f18dd95faa12697b6258692b36e58b77487e5217","properties":{"control_id":"CA-9","coverage":"partial","delta":"periodic review of each internal connection's continued need and termination when no longer required (CA-9(c)-(d))","framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-26-3a91d068.json","sourceId":"uc:UC-AUDIT-26","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ca-9-211af7b4.json","targetId":"ctrl:nist-800-53:CA-9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:341e107dcb633adc24bf392f61a1f3c46838d85e478551e155f98a93a2bfb887","properties":{"control_id":"CA-6","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-26-3a91d068.json","sourceId":"uc:UC-AUDIT-26","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ca-6-ca91dd32.json","targetId":"ctrl:nist-800-53:CA-6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b7caeed24da4e8e13deb2ffd4774086bfed35722f82b3844ef0bfa8aa2abaa79","properties":{},"sourceDetailPath":"/data/v1/records/wf-c24-000b9f1d.json","sourceId":"wf:C24","targetDetailPath":"/data/v1/records/uc-uc-audit-26-3a91d068.json","targetId":"uc:UC-AUDIT-26","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e956d7c0c0a232e3f93b04e9035118e5d4aa77ac7f0195f32b78164a5751de2e","properties":{},"sourceDetailPath":"/data/v1/records/wf-c8-5634a289.json","sourceId":"wf:C8","targetDetailPath":"/data/v1/records/uc-uc-audit-26-3a91d068.json","targetId":"uc:UC-AUDIT-26","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ff37d12965458a338a9f729a715c02966dfd4deec003c4428b559f0b677d3cae","properties":{"rationale":"The pre-operation authorization decision forces privacy requirements to be assessed before a system or internal connection is used.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-26-3a91d068.json","sourceId":"uc:UC-AUDIT-26","targetDetailPath":"/data/v1/records/risk-data-privacy-program-noncompliance-ec6178fa.json","targetId":"risk:data-privacy-program-noncompliance","type":"mitigates"}],"schemaVersion":1}
