{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-04","description":"Leadership defines and demonstrates commitment to integrity, core ethical values, and the desired risk-aware culture through an adopted code of conduct, consistent leadership behavior, and periodic evaluation of adherence with timely remediation of deviations. Organizational leadership is responsible and accountable for cybersecurity and internal-control risk and fosters a culture that is ethical, risk-aware, and continually improving, with expectations communicated to all personnel and business partners.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"CC1.1","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"P1","coverage":"full","framework":"coso-ic","relationship":"superset_of"},{"control_id":"E3","coverage":"full","framework":"coso-erm","relationship":"superset_of"},{"control_id":"E4","coverage":"full","framework":"coso-erm","relationship":"superset_of"},{"control_id":"GV.RR-01","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"ELC-CE","coverage":"partial","delta":"also spans board oversight, organizational structure, competence, and HR policy elements","framework":"sox","relationship":"intersects_with"}],"statement":"Leadership defines and demonstrates commitment to integrity, core ethical values, and the desired risk-aware culture through an adopted code of conduct, consistent leadership behavior, and periodic evaluation of adherence with timely remediation of deviations. Organizational leadership is responsible and accountable for cybersecurity and internal-control risk and fosters a culture that is ethical, risk-aware, and continually improving, with expectations communicated to all personnel and business partners.","title":"Set tone at the top: integrity, ethics, and risk-aware culture","unified_id":"UC-GOV-04"},"id":"uc:UC-GOV-04","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-04","sourceIds":["coso-erm","coso-ic","nist-csf-2","soc2","sox"],"sourceUrl":null,"title":"UC-GOV-04 — Set tone at the top: integrity, ethics, and risk-aware culture","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2474df81197fea9038d7c242b4ccd27c39ee5cfeb8fd73d2855f9224389aa0fb","properties":{"control_id":"CC1.1","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/ctrl-soc2-cc1-1-ad48e3c3.json","targetId":"ctrl:soc2:CC1.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2c558266782b12fd6905d4d56005d685307a30c7549139825214167ec1df62c0","properties":{},"sourceDetailPath":"/data/v1/records/wf-c2-a1078981.json","sourceId":"wf:C2","targetDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","targetId":"uc:UC-GOV-04","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3f20ac84d57f6fc3147a14ecb7f441b37893c6231eb7e5cfe210b41db70ae38c","properties":{"rationale":"Tone at the top, ethics, and an adopted code of conduct are the control-environment foundation the risk names as poor.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4efa7d9e4b72a7a5cb24975d635877780620644632caa229ee42ad89a0c6db3a","properties":{"rationale":"Demonstrated integrity and core values counter the perceived values-misalignment that erodes stakeholder trust.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/risk-reputational-stakeholder-trust-23d21e70.json","targetId":"risk:reputational-stakeholder-trust","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:55d98f71337b6a07fdde1ba619995d8b78c179bbbb0d05e658965b71a4099f89","properties":{"rationale":"Leadership demonstrating integrity and a risk-aware culture directly addresses the unclear tone at the top driving oversight failure.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/risk-gov-oversight-failure-d98ffc12.json","targetId":"risk:gov-oversight-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5868785f2387ea5e5baf5f8d80fdbe1d23749713f245e3a69e8790c3536e9c2e","properties":{"control_id":"P1","coverage":"full","delta":null,"framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p1-f41d97ed.json","targetId":"ctrl:coso-ic:P1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:63ebbbc35c597cf5bba4e4837a4cc9c058bcb3a4ba923205f09d8b39c4d950f0","properties":{"rationale":"An ethical culture, code of conduct, and disciplinary follow-through deter the rationalization leg of insider fraud.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/risk-fraud-internal-misappropriation-d235cd10.json","targetId":"risk:fraud-internal-misappropriation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:65c095cf3ce978ff7a07fc0cb45cf636cf2fc931ce86429df16da655bc187122","properties":{"rationale":"Consistent ethical leadership behavior reduces executive-misconduct triggers of brand crises.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/risk-reputational-brand-crisis-4d7c293d.json","targetId":"risk:reputational-brand-crisis","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6a20749cb73b502e120b867a0eb43ceb15880a94cd08bb1d3c37fe138ee1f457","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","targetId":"uc:UC-GOV-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7602e9e128eb62424718cbc8cf526d493b7abc77813bba8f60dea1776af06cb4","properties":{"control_id":"ELC-CE","coverage":"partial","delta":"also spans board oversight, organizational structure, competence, and HR policy elements","framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/ctrl-sox-elc-ce-91bb92d0.json","targetId":"ctrl:sox:ELC-CE","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7e110a0b74490294b6ee6827e6121c458c9d8af13275924ac1a29f52002662a1","properties":{"control_id":"GV.RR-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rr-01-011a9146.json","targetId":"ctrl:nist-csf-2:GV.RR-01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c603001a528d70a17b5fe3b4f5ed80da81ceda943633e35695c5ff8c83357621","properties":{},"sourceDetailPath":"/data/v1/records/wf-g18-e2eb9758.json","sourceId":"wf:G18","targetDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","targetId":"uc:UC-GOV-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:de8d6709ab9dabdb8f48b03bd4d7b13076c63669a00fce9accb486fdca9e9713","properties":{"control_id":"E3","coverage":"full","delta":null,"framework":"coso-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/ctrl-coso-erm-e3-2d76e2c2.json","targetId":"ctrl:coso-erm:E3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fc1864e38234f319edeb1291aab138591e799e19c843dbcba7d1b80c5e00e01a","properties":{"control_id":"E4","coverage":"full","delta":null,"framework":"coso-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/ctrl-coso-erm-e4-97e5f081.json","targetId":"ctrl:coso-erm:E4","type":"maps_to"}],"schemaVersion":1}
