{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-05","description":"The board of directors (or equivalent governing body), demonstrating independence from management and appropriate expertise, oversees the development and performance of internal control and the cybersecurity risk management program, approving the risk strategy and material policies. The board periodically reviews risk-management outcomes, program effectiveness, and management reporting, and directs adjustments to strategy and direction; oversight activities and decisions are documented in minutes and supporting materials.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"CC1.2","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"P2","coverage":"full","framework":"coso-ic","relationship":"superset_of"},{"control_id":"E1","coverage":"full","framework":"coso-erm","relationship":"superset_of"},{"control_id":"GV.OV-01","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"NIS2-Art20","coverage":"partial","delta":"management body members must approve measures and complete cybersecurity training","framework":"nis2","relationship":"intersects_with"}],"statement":"The board of directors (or equivalent governing body), demonstrating independence from management and appropriate expertise, oversees the development and performance of internal control and the cybersecurity risk management program, approving the risk strategy and material policies. The board periodically reviews risk-management outcomes, program effectiveness, and management reporting, and directs adjustments to strategy and direction; oversight activities and decisions are documented in minutes and supporting materials.","title":"Ensure board-level oversight of risk and internal control","unified_id":"UC-GOV-05"},"id":"uc:UC-GOV-05","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-05","sourceIds":["coso-erm","coso-ic","nis2","nist-csf-2","soc2"],"sourceUrl":null,"title":"UC-GOV-05 — Ensure board-level oversight of risk and internal control","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:09fed3546986fe04fdec9059b5f846d64b5f3de14be1d43fc8e4e13b53da8c3f","properties":{},"sourceDetailPath":"/data/v1/records/wf-g10-3ef59294.json","sourceId":"wf:G10","targetDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","targetId":"uc:UC-GOV-05","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:21603a251d2391397ab6f7db5f8216489bc66134e16d8f6ad445269634bfc813","properties":{},"sourceDetailPath":"/data/v1/records/wf-g11-62e4fa80.json","sourceId":"wf:G11","targetDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","targetId":"uc:UC-GOV-05","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:35469ce4cb671182840373ba75e324ed800a0a4e4d47d09d3d1e037f6d10f617","properties":{"control_id":"E1","coverage":"full","delta":null,"framework":"coso-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","sourceId":"uc:UC-GOV-05","targetDetailPath":"/data/v1/records/ctrl-coso-erm-e1-2389ffca.json","targetId":"ctrl:coso-erm:E1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:46bb0f25ee9e847f6aa85930a4d80b7a18cedcd6d6d54d06acf3fef21232ab89","properties":{"control_id":"CC1.2","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","sourceId":"uc:UC-GOV-05","targetDetailPath":"/data/v1/records/ctrl-soc2-cc1-2-f5deb30e.json","targetId":"ctrl:soc2:CC1.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5281390054b41163d7d644d1c520e88598f1a899f13fd5818c8d8839e14fa9c3","properties":{"rationale":"Board independence, expertise, and oversight of the control and risk program is the direct control against inadequate board oversight.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","sourceId":"uc:UC-GOV-05","targetDetailPath":"/data/v1/records/risk-gov-oversight-failure-d98ffc12.json","targetId":"risk:gov-oversight-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6e4a82ac5680b85a4a0a1b293996eefad4f8970f2b0ec15e7c53c155b25a3b7d","properties":{"control_id":"P2","coverage":"full","delta":null,"framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","sourceId":"uc:UC-GOV-05","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p2-4f80775c.json","targetId":"ctrl:coso-ic:P2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:922aa7d7cc8072dace637dfcc0e9d478635fe23c723bcbf38784dbaddbcf11cc","properties":{"control_id":"GV.OV-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","sourceId":"uc:UC-GOV-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-ov-01-19ee87a8.json","targetId":"ctrl:nist-csf-2:GV.OV-01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:97bf093cdd524720c56b30141ef55eaacea57cd6de66d78dd5666a1d4622b5ff","properties":{"control_id":"NIS2-Art20","coverage":"partial","delta":"management body members must approve measures and complete cybersecurity training","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","sourceId":"uc:UC-GOV-05","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art20-28d702ac.json","targetId":"ctrl:nis2:NIS2-Art20","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a89c79a6672efc48fb298105e405c7165cc81524aa26b7989eca143a45f465bf","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","targetId":"uc:UC-GOV-05","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d51e0c2cff0f07ea472ce919c8211ae63ac98498cba09607ba2ea89d79975ebe","properties":{"rationale":"Board/audit-committee oversight of internal control provides challenge that helps surface ICFR material weaknesses.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","sourceId":"uc:UC-GOV-05","targetDetailPath":"/data/v1/records/risk-fin-icfr-material-weakness-cdd66323.json","targetId":"risk:fin-icfr-material-weakness","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f4777178aeb214339656c564928a20972f6832c6cbe980d78b1a8b0a2ddcc311","properties":{},"sourceDetailPath":"/data/v1/records/wf-g17-8c15d035.json","sourceId":"wf:G17","targetDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","targetId":"uc:UC-GOV-05","type":"operates"}],"schemaVersion":1}
