{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-02","description":"Identify and document the organization's mission, its internal and external stakeholders and their needs and expectations, the critical objectives, capabilities, and services that stakeholders depend on, and the outcomes, capabilities, and services the organization itself depends on. Use this business context to scope and prioritize risk management activities, communicate it to those who need it, and refresh it when the business environment changes.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"GV.OC-01","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GV.OC-02","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GV.OC-04","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GV.OC-05","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"E6","coverage":"full","framework":"coso-erm","relationship":"superset_of"}],"statement":"Identify and document the organization's mission, its internal and external stakeholders and their needs and expectations, the critical objectives, capabilities, and services that stakeholders depend on, and the outcomes, capabilities, and services the organization itself depends on. Use this business context to scope and prioritize risk management activities, communicate it to those who need it, and refresh it when the business environment changes.","title":"Understand organizational context and stakeholder expectations","unified_id":"UC-GOV-02"},"id":"uc:UC-GOV-02","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-02","sourceIds":["coso-erm","nist-csf-2"],"sourceUrl":null,"title":"UC-GOV-02 — Understand organizational context and stakeholder expectations","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:16b62358f23f39f467e56cb2a6b785c4a041fad9841094febf3f691ff8ff1938","properties":{"rationale":"Documenting mission and stakeholder needs is a foundational input to strategy alignment, but the operative alignment control is strategy-setting (UC-GOV-12), not context documentation alone.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-02-70e0507c.json","sourceId":"uc:UC-GOV-02","targetDetailPath":"/data/v1/records/risk-strategic-misalignment-execution-d9c0675b.json","targetId":"risk:strategic-misalignment-execution","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:43d27e45fc8caa426a008f594ca755a6448f3561e41aa575a8493318bab01c91","properties":{},"sourceDetailPath":"/data/v1/records/wf-d05-2302db1f.json","sourceId":"wf:D05","targetDetailPath":"/data/v1/records/uc-uc-gov-02-70e0507c.json","targetId":"uc:UC-GOV-02","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4b17855269bbd4488104aa2c7cfbd789f2636af703e79e9f6f2717babac70a27","properties":{"control_id":"E6","coverage":"full","delta":null,"framework":"coso-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-02-70e0507c.json","sourceId":"uc:UC-GOV-02","targetDetailPath":"/data/v1/records/ctrl-coso-erm-e6-bd22ee90.json","targetId":"ctrl:coso-erm:E6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:60e0faa4bd4a32d89b900ff53c9128403a83cb7ccb847b348c652d50a1b4b360","properties":{},"sourceDetailPath":"/data/v1/records/wf-g20-9d0df1c7.json","sourceId":"wf:G20","targetDetailPath":"/data/v1/records/uc-uc-gov-02-70e0507c.json","targetId":"uc:UC-GOV-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:638ab94765d0a75186b8cdd1796600dc3e3548804af16ad3f6dc9026f02ba644","properties":{"rationale":"Identifying stakeholder needs and expectations lets the organization meet them, sustaining trust.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-02-70e0507c.json","sourceId":"uc:UC-GOV-02","targetDetailPath":"/data/v1/records/risk-reputational-stakeholder-trust-23d21e70.json","targetId":"risk:reputational-stakeholder-trust","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:656e86110ec583b19eabcda6fccbe612add0b5c24ed0d100da8008278799d7f9","properties":{"control_id":"GV.OC-04","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-02-70e0507c.json","sourceId":"uc:UC-GOV-02","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-oc-04-da71308a.json","targetId":"ctrl:nist-csf-2:GV.OC-04","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:94cc44daedf36c4b5a72d35dcee5accba8bf3d6378566132d6e8a1a89f620bbb","properties":{},"sourceDetailPath":"/data/v1/records/wf-c2-a1078981.json","sourceId":"wf:C2","targetDetailPath":"/data/v1/records/uc-uc-gov-02-70e0507c.json","targetId":"uc:UC-GOV-02","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ab11deef560959ed5089d4a0e6196a1f1682284a086ad1b1ba26f194f35a2db9","properties":{"control_id":"GV.OC-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-02-70e0507c.json","sourceId":"uc:UC-GOV-02","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-oc-02-84d81944.json","targetId":"ctrl:nist-csf-2:GV.OC-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cb7df1cca18494a8571d27b8326691cfe00fd83420dff3ea92da8b8d3112733f","properties":{"control_id":"GV.OC-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-02-70e0507c.json","sourceId":"uc:UC-GOV-02","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-oc-01-e996c461.json","targetId":"ctrl:nist-csf-2:GV.OC-01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e67dec9567d8df830720e2d7930464088961e8c5e8c404ecf50d261f79b9afdf","properties":{"control_id":"GV.OC-05","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-02-70e0507c.json","sourceId":"uc:UC-GOV-02","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-oc-05-abe265e5.json","targetId":"ctrl:nist-csf-2:GV.OC-05","type":"maps_to"}],"schemaVersion":1}
