{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-14","description":"Establish, approve, publish, and maintain the organization's information-security policy suite as a governed whole: a top-level policy plus the topic-specific policies, each with an accountable owner, board/management approval, planned review cycles, and communication to relevant parties. Domain-specific policy content is governed by its own unified control; this objective owns the suite-level lifecycle (inventory, approval chain, review cadence, communication, exceptions).","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"A.5.1","coverage":"partial","delta":"Policies must also be acknowledged by relevant personnel and interested parties","framework":"iso-27001","relationship":"intersects_with"},{"control_id":"A.5.37","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"GV.PO-01","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GV.PO-02","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"CC5.3","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"PL-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"500.3","coverage":"full","framework":"nydfs-500","relationship":"superset_of"},{"control_id":"NIS2-Art21a","coverage":"full","framework":"nis2","relationship":"superset_of"},{"control_id":"HIPAA-164.316","coverage":"full","framework":"hipaa","relationship":"superset_of"},{"control_id":"PCI-Req12","coverage":"partial","delta":"also requires awareness, screening, third-party management, and incident response program elements","framework":"pci-dss","relationship":"intersects_with"}],"statement":"Establish, approve, publish, and maintain the organization's information-security policy suite as a governed whole: a top-level policy plus the topic-specific policies, each with an accountable owner, board/management approval, planned review cycles, and communication to relevant parties. Domain-specific policy content is governed by its own unified control; this objective owns the suite-level lifecycle (inventory, approval chain, review cadence, communication, exceptions).","title":"Establish and maintain approved security policies and procedures","unified_id":"UC-GOV-14"},"id":"uc:UC-GOV-14","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-14","sourceIds":["hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"UC-GOV-14 — Establish and maintain approved security policies and procedures","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:019baf1e5871be1ff90dc2f328e35b55b4739de44e3586df48bf0a46e89df917","properties":{"control_id":"A.5.37","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-37-45e8c067.json","targetId":"ctrl:iso-27001:A.5.37","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0829af2246a85e7e5cc486581d228bba50e080557016bad92e46f06a89d07cae","properties":{"rationale":"Maintaining policies required by HIPAA/PCI/regulators reduces enforcement exposure for missing governance documentation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/risk-compliance-litigation-enforcement-25e7935d.json","targetId":"risk:compliance-litigation-enforcement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0d58933675deb17536728566a874266b15eab2225b772d92e95e86e6300632fc","properties":{},"sourceDetailPath":"/data/v1/records/wf-d49-307550b5.json","sourceId":"wf:D49","targetDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","targetId":"uc:UC-GOV-14","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:10a681e8bcc29f91944411fa2644e4b72af383ae4ec6b4c11fbbea05288cd30d","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","targetId":"uc:UC-GOV-14","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:13f6aa7b3ed4b184eafd7da0757ae79318f89b1a9d20ab92bf53261aceb57e32","properties":{"rationale":"Establishing, approving, and maintaining the security policy suite directly remedies missing approved policies.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:21f10052b8690e16fbe2c599fc6c8f20a3f20b649c0f33b700b905d7a7585a34","properties":{"control_id":"GV.PO-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-po-01-e8b931a8.json","targetId":"ctrl:nist-csf-2:GV.PO-01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:24092cdfb69568d26f2bb13fc48e3fb4256eca15150f7ba2828356c1dcfb477c","properties":{"control_id":"CC5.3","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/ctrl-soc2-cc5-3-46feecd1.json","targetId":"ctrl:soc2:CC5.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:242639094cff3d814b708b23b6a26846f3357325e2e8b12ff07bb70f5bf8b641","properties":{},"sourceDetailPath":"/data/v1/records/wf-r5-c423cac7.json","sourceId":"wf:R5","targetDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","targetId":"uc:UC-GOV-14","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:444741931cea830f3562633d9bd4dff7c4d6117b6e9c71c9bbc8c93227378a41","properties":{"control_id":"PL-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pl-1-3f9145d7.json","targetId":"ctrl:nist-800-53:PL-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:54ae02c655fb37b48ab58ae5bfd03f6ed70d2b65e5cc5a91cc8080c54a182684","properties":{},"sourceDetailPath":"/data/v1/records/wf-d52-3f5d13a3.json","sourceId":"wf:D52","targetDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","targetId":"uc:UC-GOV-14","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5e83cddd96642d47f06584770147e7c8a8b81733d53e3509362bfb8cb0dbed9d","properties":{"control_id":"PCI-Req12","coverage":"partial","delta":"also requires awareness, screening, third-party management, and incident response program elements","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req12-cd77be1e.json","targetId":"ctrl:pci-dss:PCI-Req12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:65efa7cec7ad59e7c84b28f7447572d2dea3e666127e45163d267eae59a1d2b7","properties":{},"sourceDetailPath":"/data/v1/records/wf-g9-d1e65641.json","sourceId":"wf:G9","targetDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","targetId":"uc:UC-GOV-14","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9ac0892a983e372789eaf022b024591dbc8cfc48a702d327eb056a0cdeb8d4c4","properties":{"control_id":"GV.PO-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-po-02-4745ed81.json","targetId":"ctrl:nist-csf-2:GV.PO-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:adb73bf2fed2d22bf663bd2eb79023eb935d60f5669e776a5553e24dfa431eab","properties":{"control_id":"NIS2-Art21a","coverage":"full","delta":null,"framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21a-1dbcc08c.json","targetId":"ctrl:nis2:NIS2-Art21a","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d15fa900a832be74bc553982907d1cc33136427e93e8504fc06518bfa803badd","properties":{},"sourceDetailPath":"/data/v1/records/wf-d05-2302db1f.json","sourceId":"wf:D05","targetDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","targetId":"uc:UC-GOV-14","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e73f053f2b7dcf4dace73dbe38de6cd7a98f53a536143ca373b870fa12085773","properties":{"control_id":"A.5.1","coverage":"partial","delta":"Policies must also be acknowledged by relevant personnel and interested parties","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-1-e30a466c.json","targetId":"ctrl:iso-27001:A.5.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e7d0fd4079f9f307876e9cce5ca8ba86e2eb2bcfdf07139d75ac5c078694489f","properties":{"control_id":"HIPAA-164.316","coverage":"full","delta":null,"framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-316-15412c2a.json","targetId":"ctrl:hipaa:HIPAA-164.316","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ea99e0bc10e1ad122a64a42d4f501db2f9ba24124237d01361bd5841e31090d8","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","targetId":"uc:UC-GOV-14","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ede6aa8750315d3461dc9d4adfb070a10c5ae10cd85f36d7737f381ce566a8fb","properties":{"control_id":"500.3","coverage":"full","delta":null,"framework":"nydfs-500","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"23 NYCRR 500, Second Amendment"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/ctrl-nydfs-500-500-3-7a3150f9.json","targetId":"ctrl:nydfs-500:500.3","type":"maps_to"}],"schemaVersion":1}
