{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-15","description":"Establish, implement, and maintain an organization-wide information security program, documented in a program plan approved by senior management and based on the organization's risk assessment. Define the program's scope, security objectives, protective functions (identify, protect, detect, respond, recover), supporting management processes, and coordination among organizational entities, and review and update the program plan at planned intervals and after significant change.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"PM-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"500.2","coverage":"partial","delta":"Program's core functions must also include fulfilling applicable regulatory reporting obligations","framework":"nydfs-500","relationship":"intersects_with"},{"control_id":"APO13","coverage":"full","framework":"cobit-2019","relationship":"superset_of"}],"statement":"Establish, implement, and maintain an organization-wide information security program, documented in a program plan approved by senior management and based on the organization's risk assessment. Define the program's scope, security objectives, protective functions (identify, protect, detect, respond, recover), supporting management processes, and coordination among organizational entities, and review and update the program plan at planned intervals and after significant change.","title":"Operate a management-approved information security program","unified_id":"UC-GOV-15"},"id":"uc:UC-GOV-15","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-15","sourceIds":["cobit-2019","nist-800-53","nydfs-500"],"sourceUrl":null,"title":"UC-GOV-15 — Operate a management-approved information security program","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:05acd9a2b908becf7c7faf05f0696614f83613fed1e8ea49d4d668726afd2dee","properties":{"control_id":"500.2","coverage":"partial","delta":"Program's core functions must also include fulfilling applicable regulatory reporting obligations","framework":"nydfs-500","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"23 NYCRR 500, Second Amendment"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-15-828b3eec.json","sourceId":"uc:UC-GOV-15","targetDetailPath":"/data/v1/records/ctrl-nydfs-500-500-2-b0b2c5e0.json","targetId":"ctrl:nydfs-500:500.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:334d2f2764e18e6a7946b789e41d7073191fe0c9ecebfe247bad91da8d79198f","properties":{},"sourceDetailPath":"/data/v1/records/wf-c7-acbef2ee.json","sourceId":"wf:C7","targetDetailPath":"/data/v1/records/uc-uc-gov-15-828b3eec.json","targetId":"uc:UC-GOV-15","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:33d51243e984b04bf8fb218c8b2ed38b30dbb83cb52c23a35adca03134ce4b64","properties":{},"sourceDetailPath":"/data/v1/records/wf-c16-5cfe940e.json","sourceId":"wf:C16","targetDetailPath":"/data/v1/records/uc-uc-gov-15-828b3eec.json","targetId":"uc:UC-GOV-15","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5fdc847444684a1d6e3352c37a3c35d5f2e4e3c9569d6057db37b0f8099ea7c3","properties":{},"sourceDetailPath":"/data/v1/records/wf-d05-2302db1f.json","sourceId":"wf:D05","targetDetailPath":"/data/v1/records/uc-uc-gov-15-828b3eec.json","targetId":"uc:UC-GOV-15","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6af6976069665b10d4b3552ac957d6046868428cb13f6aad904d27fc4a1976ab","properties":{"control_id":"APO13","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-15-828b3eec.json","sourceId":"uc:UC-GOV-15","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-apo13-b83b9404.json","targetId":"ctrl:cobit-2019:APO13","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:82d61a87f3f92111745e4f4f4e8a4bd7605a680afaaf7c0d2b54ac3b7a9d75c8","properties":{"rationale":"A management-approved, org-wide security program supplies the coordinated guidance whose absence leaves controls inconsistent.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-15-828b3eec.json","sourceId":"uc:UC-GOV-15","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9997a47e188e19b027e96528a90f062b46042fb0de9fd030d108612c9eb9f133","properties":{"control_id":"PM-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-15-828b3eec.json","sourceId":"uc:UC-GOV-15","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-1-da2f0e02.json","targetId":"ctrl:nist-800-53:PM-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9cf38263f7dcd9d05134c60213463561e06eaabf61b43f7ecb14362142620692","properties":{},"sourceDetailPath":"/data/v1/records/wf-a1-f09c8201.json","sourceId":"wf:A1","targetDetailPath":"/data/v1/records/uc-uc-gov-15-828b3eec.json","targetId":"uc:UC-GOV-15","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b126568f6a7e42ab0ead8f85b1c05e086c34522201c2b1285b94be8dc881f90d","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-15-828b3eec.json","sourceId":"uc:UC-GOV-15","targetDetailPath":"/data/v1/records/risk-gov-organizational-change-resistance-a8383ccb.json","targetId":"risk:gov-organizational-change-resistance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c60e891944141548bf42d6bb9ed8de714c4e01c64d304d2d2b2a9a06bf238385","properties":{},"sourceDetailPath":"/data/v1/records/wf-c25-a2c9f603.json","sourceId":"wf:C25","targetDetailPath":"/data/v1/records/uc-uc-gov-15-828b3eec.json","targetId":"uc:UC-GOV-15","type":"operates"}],"schemaVersion":1}
