{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-11","description":"Allocate and manage funding, personnel, and other resources commensurate with the organization's cybersecurity risk strategy, roles, responsibilities, and policies, ensuring security and privacy requirements are addressed in capital planning, budgeting, and investment decisions. Periodically evaluate resource allocation and utilization for adequacy and optimization, and adjust budgets as priorities and risks change.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"PM-3","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"GV.RR-03","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"EDM04","coverage":"partial","delta":"governance of optimization across all enterprise IT resources (people, technology, infrastructure), beyond security-scoped budget and personnel","framework":"cobit-2019","relationship":"intersects_with"},{"control_id":"APO06","coverage":"partial","delta":"full IT financial management including cost transparency and allocation models","framework":"cobit-2019","relationship":"intersects_with"}],"statement":"Allocate and manage funding, personnel, and other resources commensurate with the organization's cybersecurity risk strategy, roles, responsibilities, and policies, ensuring security and privacy requirements are addressed in capital planning, budgeting, and investment decisions. Periodically evaluate resource allocation and utilization for adequacy and optimization, and adjust budgets as priorities and risks change.","title":"Allocate adequate resources and budget for security","unified_id":"UC-GOV-11"},"id":"uc:UC-GOV-11","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-11","sourceIds":["cobit-2019","nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"UC-GOV-11 — Allocate adequate resources and budget for security","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3fbd82239f6df500432f0929dddfc1afeaf65cab4eacf1becc54aa55906a1cfc","properties":{},"sourceDetailPath":"/data/v1/records/wf-g19-77005a54.json","sourceId":"wf:G19","targetDetailPath":"/data/v1/records/uc-uc-gov-11-a13b60d3.json","targetId":"uc:UC-GOV-11","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:461dd4eca218116bdc0824e8ae26fb2450ca2159955c714ef75a5d97ab523c5f","properties":{"rationale":"Resourcing controls commensurate with risk enables the control environment to function.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-11-a13b60d3.json","sourceId":"uc:UC-GOV-11","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4afb84782e3cec6bd552916b34f8b15f3759125ed7ec2be222c7c91b5a6e3a61","properties":{"control_id":"APO06","coverage":"partial","delta":"full IT financial management including cost transparency and allocation models","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-11-a13b60d3.json","sourceId":"uc:UC-GOV-11","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-apo06-2191e824.json","targetId":"ctrl:cobit-2019:APO06","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:517a80c930b9fb3d6c378ba74c158b481d6eaf25a187161756eae3fe4c0376ac","properties":{},"sourceDetailPath":"/data/v1/records/wf-d05-2302db1f.json","sourceId":"wf:D05","targetDetailPath":"/data/v1/records/uc-uc-gov-11-a13b60d3.json","targetId":"uc:UC-GOV-11","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:56c8b00bf3243e5d460b47444bb4bb31a05c91914ba8c9ff590caad7bcfa5849","properties":{},"sourceDetailPath":"/data/v1/records/wf-c2-a1078981.json","sourceId":"wf:C2","targetDetailPath":"/data/v1/records/uc-uc-gov-11-a13b60d3.json","targetId":"uc:UC-GOV-11","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5f8295b6b9fb0bd1259f10ceb94dbbc5906b983e3bfb3c0121bfb1c8008036ea","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-11-a13b60d3.json","sourceId":"uc:UC-GOV-11","targetDetailPath":"/data/v1/records/risk-ops-core-process-inefficiency-8e830edd.json","targetId":"risk:ops-core-process-inefficiency","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8617482233ffe8bfa5309d39b6d520746dc930ecdc68348f52565c031c767fce","properties":{"control_id":"EDM04","coverage":"partial","delta":"governance of optimization across all enterprise IT resources (people, technology, infrastructure), beyond security-scoped budget and personnel","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-11-a13b60d3.json","sourceId":"uc:UC-GOV-11","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-edm04-7ad4bdc3.json","targetId":"ctrl:cobit-2019:EDM04","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9235844036fdb126301691fccf0f18ac5382e1b510e7cefdb9ecaf8f550dc4eb","properties":{"control_id":"PM-3","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-11-a13b60d3.json","sourceId":"uc:UC-GOV-11","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-3-2989f50e.json","targetId":"ctrl:nist-800-53:PM-3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a0741a6452fe9307ac08545e582683c143e39747a4867875f2a42bccc5abc134","properties":{},"sourceDetailPath":"/data/v1/records/wf-g15-1231bc14.json","sourceId":"wf:G15","targetDetailPath":"/data/v1/records/uc-uc-gov-11-a13b60d3.json","targetId":"uc:UC-GOV-11","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a131a1febde0e725a526468c8b3631b470809c72d7fb40f725eb624149093739","properties":{"control_id":"GV.RR-03","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-11-a13b60d3.json","sourceId":"uc:UC-GOV-11","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rr-03-f8d87e54.json","targetId":"ctrl:nist-csf-2:GV.RR-03","type":"maps_to"}],"schemaVersion":1}
