{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Business Continuity & Disaster Recovery","type":"corrective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-BCDR-06","description":"Log, classify, and prioritize operational and security incidents and service requests, respond within defined service levels, and escalate by severity until service is restored. Classify and report major ICT incidents to regulators, customers, and affected parties within required timeframes. Perform root-cause analysis of significant and recurring incidents, and track underlying problems through to permanent resolution.","details":{"control_category":"administrative","control_type":"corrective","domain":"Business Continuity & Disaster Recovery","guidance":[],"members":[{"control_id":"DSS02","coverage":"full","framework":"cobit-2019","relationship":"superset_of"},{"control_id":"DSS03","coverage":"full","framework":"cobit-2019","relationship":"superset_of"},{"control_id":"DORA-Art17-23","coverage":"partial","delta":"major-incident report clocks: initial 24h, intermediate 72h, final 1 month","framework":"dora","relationship":"intersects_with"}],"statement":"Log, classify, and prioritize operational and security incidents and service requests, respond within defined service levels, and escalate by severity until service is restored. Classify and report major ICT incidents to regulators, customers, and affected parties within required timeframes. Perform root-cause analysis of significant and recurring incidents, and track underlying problems through to permanent resolution.","title":"Resolve operational incidents and eliminate root causes","unified_id":"UC-BCDR-06"},"id":"uc:UC-BCDR-06","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-BCDR-06","sourceIds":["cobit-2019","dora"],"sourceUrl":null,"title":"UC-BCDR-06 — Resolve operational incidents and eliminate root causes","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:20e4b2a31e5517b32fa223ea9b1b8fd79f1f9756c4fd2ee3519a688b1e5e002f","properties":{"control_id":"DSS02","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss02-af5bca5d.json","targetId":"ctrl:cobit-2019:DSS02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:25fdc78599966b3c35b4a301474a3d8a4d7073c9d219ea65459dba52b7850ef4","properties":{"rationale":"incident response restores and problem management drives permanent fixes for recurring equipment faults","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/risk-tech-hardware-equipment-failure-25948451.json","targetId":"risk:tech-hardware-equipment-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5cf49ff3f7e015288403566f84e98c82474a60673fae3931772be04b75b4d8ec","properties":{"rationale":"incident response restores service within SLAs and root-cause problem resolution reduces outage duration and recurrence","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/risk-bcdr-it-resilience-outage-18dfc108.json","targetId":"risk:bcdr-it-resilience-outage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7424483991072df36e59cd4612f8fd1b705a42b41bd7c4eb5e452b390e2d9672","properties":{"rationale":"logging, escalating, and root-causing incidents directly resolves and prevents recurring software failures","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/risk-tech-software-system-failure-2e2c5364.json","targetId":"risk:tech-software-system-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8b9de4df2b9b11f4758d16caba3a14418486d52562080438d56995febeaf4511","properties":{"control_id":"DORA-Art17-23","coverage":"partial","delta":"major-incident report clocks: initial 24h, intermediate 72h, final 1 month","framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art17-23-9aa7977f.json","targetId":"ctrl:dora:DORA-Art17-23","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9f4c9e165d71a26a8ae4396e5317ceb0d2d2a2e344201e8ad906a161ee1f775f","properties":{},"sourceDetailPath":"/data/v1/records/wf-c3-4a88b225.json","sourceId":"wf:C3","targetDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","targetId":"uc:UC-BCDR-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a823227bef104ee8b1ec5e45cf9214e64c74bbba8b49797e77874e3716a32f26","properties":{"rationale":"severity-based incident response contains and escalates a ransomware event toward restoration","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/risk-sdlc-ransomware-32ab67f4.json","targetId":"risk:sdlc-ransomware","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bfb7de3a8015b3a23a00a22565f5ec4ed0ddcdd12489f4bb54574cd8ddbc7472","properties":{"control_id":"DSS03","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss03-2540740f.json","targetId":"ctrl:cobit-2019:DSS03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d0efb67e45137161ae9555ed37f5b450841d2a542b5fa69f548eae823032d61c","properties":{},"sourceDetailPath":"/data/v1/records/wf-g7-9762f11b.json","sourceId":"wf:G7","targetDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","targetId":"uc:UC-BCDR-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fb1605fa71e8c698225f13730978a2d1108c3677adb1265b2e61f81525255a57","properties":{"rationale":"incident detection and escalation mitigate an ongoing denial-of-service event","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/risk-net-denial-of-service-934ccd7f.json","targetId":"risk:net-denial-of-service","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fdb80f611ab2725bcc785362922bc7bee39deb4409fb99d59e8a1653639a67c8","properties":{},"sourceDetailPath":"/data/v1/records/wf-c80-7d360115.json","sourceId":"wf:C80","targetDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","targetId":"uc:UC-BCDR-06","type":"operates"}],"schemaVersion":1}
