{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Business Continuity & Disaster Recovery","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-BCDR-02","description":"Establish a documented ICT risk management framework covering identification, protection, detection, response, recovery, and learning for critical ICT services, with a defined digital operational resilience strategy and risk tolerance. The management body approves the framework, assigns clear roles and responsibilities for ICT risk, allocates supporting budget, reviews the framework at least annually, and remains accountable for its effectiveness.","details":{"control_category":"administrative","control_type":"preventive","domain":"Business Continuity & Disaster Recovery","guidance":[],"members":[{"control_id":"DORA-Ch2","coverage":"partial","delta":"detailed protection, backup, and recovery capabilities implemented via companion controls","framework":"dora","relationship":"intersects_with"},{"control_id":"DORA-Art5","coverage":"full","framework":"dora","relationship":"superset_of"}],"statement":"Establish a documented ICT risk management framework covering identification, protection, detection, response, recovery, and learning for critical ICT services, with a defined digital operational resilience strategy and risk tolerance. The management body approves the framework, assigns clear roles and responsibilities for ICT risk, allocates supporting budget, reviews the framework at least annually, and remains accountable for its effectiveness.","title":"Establish and govern an ICT operational resilience framework","unified_id":"UC-BCDR-02"},"id":"uc:UC-BCDR-02","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-BCDR-02","sourceIds":["dora"],"sourceUrl":null,"title":"UC-BCDR-02 — Establish and govern an ICT operational resilience framework","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:34442316db48f111db9f970498059929690de3050b20fcf535d7a55c5ad0f887","properties":{"control_id":"DORA-Art5","coverage":"full","delta":null,"framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-02-2a51c24c.json","sourceId":"uc:UC-BCDR-02","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art5-3d1842f7.json","targetId":"ctrl:dora:DORA-Art5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5471ca0c7cf01ea72d5ed6a32d4530a092810cff89582f846be3c055c2f80315","properties":{"rationale":"the framework requires a defined resilience/recovery strategy, driving plans to exist","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-02-2a51c24c.json","sourceId":"uc:UC-BCDR-02","targetDetailPath":"/data/v1/records/risk-bcdr-no-tested-continuity-plan-d4d9e7a9.json","targetId":"risk:bcdr-no-tested-continuity-plan","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ab09fdd190f6cccbc1b587f3d1c1f50feab2ec3ed9a3c01937de1dd3cf6522c0","properties":{},"sourceDetailPath":"/data/v1/records/wf-g16-694f4e2b.json","sourceId":"wf:G16","targetDetailPath":"/data/v1/records/uc-uc-bcdr-02-2a51c24c.json","targetId":"uc:UC-BCDR-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b3bfaef213094c94a8d4b5b1d32b765d8d25c6a7c1bf939b43b5927b5e690830","properties":{"control_id":"DORA-Ch2","coverage":"partial","delta":"detailed protection, backup, and recovery capabilities implemented via companion controls","framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-02-2a51c24c.json","sourceId":"uc:UC-BCDR-02","targetDetailPath":"/data/v1/records/ctrl-dora-dora-ch2-891a747a.json","targetId":"ctrl:dora:DORA-Ch2","type":"maps_to"}],"schemaVersion":1}
