{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-09","description":"Designate a qualified senior leader (e.g., a Chief Information Security Officer) with organization-wide responsibility, accountability, authority, and resources to develop, implement, and enforce the information security program, and designate accountable leadership roles for the risk management program. The security leader reports in writing on the program, material cybersecurity risks, and remediation plans to the board or equivalent governing body at least annually.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"PM-2","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PM-29","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"500.4","coverage":"partial","delta":"500.4(c) also requires timely reporting of material cybersecurity issues, not only annual reports","framework":"nydfs-500","relationship":"intersects_with"}],"statement":"Designate a qualified senior leader (e.g., a Chief Information Security Officer) with organization-wide responsibility, accountability, authority, and resources to develop, implement, and enforce the information security program, and designate accountable leadership roles for the risk management program. The security leader reports in writing on the program, material cybersecurity risks, and remediation plans to the board or equivalent governing body at least annually.","title":"Appoint accountable security leadership (CISO)","unified_id":"UC-GOV-09"},"id":"uc:UC-GOV-09","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-09","sourceIds":["nist-800-53","nydfs-500"],"sourceUrl":null,"title":"UC-GOV-09 — Appoint accountable security leadership (CISO)","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:377aea5cc666e9614be5df39392487bbbaee8e5260d8ee58794965c61e28b828","properties":{"rationale":"Accountable security leadership with authority and resources strengthens the control environment.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-09-3b622881.json","sourceId":"uc:UC-GOV-09","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5e5a89828279770e24fbc4e75c1fe79275ee2674d9b9b13fbd01e1bcc2266145","properties":{"control_id":"500.4","coverage":"partial","delta":"500.4(c) also requires timely reporting of material cybersecurity issues, not only annual reports","framework":"nydfs-500","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"23 NYCRR 500, Second Amendment"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-09-3b622881.json","sourceId":"uc:UC-GOV-09","targetDetailPath":"/data/v1/records/ctrl-nydfs-500-500-4-a694a85b.json","targetId":"ctrl:nydfs-500:500.4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:73b0dc90806d089f721c75968f1053e74e1fdca5b6289c50953959dd8cf299c9","properties":{},"sourceDetailPath":"/data/v1/records/wf-c25-a2c9f603.json","sourceId":"wf:C25","targetDetailPath":"/data/v1/records/uc-uc-gov-09-3b622881.json","targetId":"uc:UC-GOV-09","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8ccdc68a64ea996f5340817aa21940a02c866d8332dfc75863c0c64c41aca85e","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-09-3b622881.json","targetId":"uc:UC-GOV-09","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b1a3ec84276079a9708906c1e59eee391f3e5d6dec6a96a7d40d7698db1c9041","properties":{"control_id":"PM-2","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-09-3b622881.json","sourceId":"uc:UC-GOV-09","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-2-f203812f.json","targetId":"ctrl:nist-800-53:PM-2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ba86f9104055ace6802d173be90ab81a780e9f0d75f6ee52eb4a97a2dd8b4c97","properties":{"control_id":"PM-29","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-09-3b622881.json","sourceId":"uc:UC-GOV-09","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-29-d28e7c04.json","targetId":"ctrl:nist-800-53:PM-29","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c6e306deb2e0551c0c17fbced03f4a03384ec3549af7f4578c74d1c3ae01b440","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-09-3b622881.json","sourceId":"uc:UC-GOV-09","targetDetailPath":"/data/v1/records/risk-gov-strategy-innovation-obsolescence-e206f859.json","targetId":"risk:gov-strategy-innovation-obsolescence","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:da810b994507fe4154166339fa6fd20eddfe8eccc5f964deb33f071c859d7cdb","properties":{},"sourceDetailPath":"/data/v1/records/wf-c2-a1078981.json","sourceId":"wf:C2","targetDetailPath":"/data/v1/records/uc-uc-gov-09-3b622881.json","targetId":"uc:UC-GOV-09","type":"oversees"}],"schemaVersion":1}
