{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Data Protection & Privacy","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-13","description":"Identify the statutory, regulatory, and contractual requirements that apply to the personal information the organization holds, and implement reasonable administrative, technical, and physical safeguards appropriate to its volume and sensitivity. Assign responsibility for PII protection, verify the safeguards periodically, and remediate identified gaps.","details":{"control_category":"administrative","control_type":"preventive","domain":"Data Protection & Privacy","guidance":[],"members":[{"control_id":"A.5.34","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"CCPA-1798.150","coverage":"full","framework":"ccpa","relationship":"superset_of"},{"control_id":"HIPAA-164.312(c)","coverage":"partial","delta":"the electronic mechanism to authenticate that ePHI has not been altered or destroyed is the specific integrity-verification arm","framework":"hipaa","relationship":"intersects_with"}],"statement":"Identify the statutory, regulatory, and contractual requirements that apply to the personal information the organization holds, and implement reasonable administrative, technical, and physical safeguards appropriate to its volume and sensitivity. Assign responsibility for PII protection, verify the safeguards periodically, and remediate identified gaps.","title":"Safeguard personal information with reasonable security","unified_id":"UC-DATA-13"},"id":"uc:UC-DATA-13","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-DATA-13","sourceIds":["ccpa","hipaa","iso-27001"],"sourceUrl":null,"title":"UC-DATA-13 — Safeguard personal information with reasonable security","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1e2bd6679be011acc04c51bd48e6fb98b29fe6f75a52aeecd0e358286263f14d","properties":{"control_id":"CCPA-1798.150","coverage":"full","delta":null,"framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","sourceId":"uc:UC-DATA-13","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-150-da298199.json","targetId":"ctrl:ccpa:CCPA-1798.150","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2865d6ac583d94f616703bc2f0c20a1747ead3d85b199ce0bc173599f4f10455","properties":{},"sourceDetailPath":"/data/v1/records/wf-r11-a48dfcd0.json","sourceId":"wf:R11","targetDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","targetId":"uc:UC-DATA-13","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4d7f38c258495a76082e22f9523b4b80ddc1f72f3d737dc66980a67bb415cca7","properties":{"control_id":"A.5.34","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","sourceId":"uc:UC-DATA-13","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-34-58b0337f.json","targetId":"ctrl:iso-27001:A.5.34","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5669fd2d5b3ff1530dbbda7eb8167298deb5f15a16531065fa2675fca1094b91","properties":{"control_id":"HIPAA-164.312(c)","coverage":"partial","delta":"the electronic mechanism to authenticate that ePHI has not been altered or destroyed is the specific integrity-verification arm","framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","sourceId":"uc:UC-DATA-13","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-312-c-7002cebd.json","targetId":"ctrl:hipaa:HIPAA-164.312(c)","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b4afee5e0589649b274ce743fe2fe4681eafa401c0640c827db767ab9cff898e","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","targetId":"uc:UC-DATA-13","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b9f010e652a86ba096c55275dae7215b6d336e955a7220132db8747e27fd35c9","properties":{"rationale":"Implementing reasonable admin/technical/physical safeguards sized to data volume/sensitivity directly reduces unauthorized disclosure/breach.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","sourceId":"uc:UC-DATA-13","targetDetailPath":"/data/v1/records/risk-data-breach-unauthorized-disclosure-3b1c296c.json","targetId":"risk:data-breach-unauthorized-disclosure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bb610d04c71da3f279147ee116490166020dfc381a936ab40d1bddb6767a0c60","properties":{"rationale":"PII-protection requirements include data-minimization and purpose-limitation, directly addressing over-collection and purpose creep.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","sourceId":"uc:UC-DATA-13","targetDetailPath":"/data/v1/records/risk-data-excessive-collection-purpose-creep-4a691595.json","targetId":"risk:data-excessive-collection-purpose-creep","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c8ca93910cdaab4b8e5eb6137031ced2d72703c1b8870a0749d54ba253b04841","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","sourceId":"uc:UC-DATA-13","targetDetailPath":"/data/v1/records/risk-data-reidentification-inference-d4b31f45.json","targetId":"risk:data-reidentification-inference","type":"mitigates"}],"schemaVersion":1}
