{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-17","description":"Establish, document, and communicate a leadership-approved enterprise risk management strategy, including risk management objectives agreed by stakeholders, defined risk appetite and tolerance statements, and a documented risk assessment policy with procedures and a consistent methodology for identifying, analyzing, prioritizing, and responding to risk. Ensure governance activities keep risk-taking optimized within appetite, and review and update the strategy, appetite, and policy at planned intervals.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"PM-9","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"RA-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"GV.RM-01","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"E7","coverage":"full","framework":"coso-erm","relationship":"superset_of"},{"control_id":"EDM03","coverage":"full","framework":"cobit-2019","relationship":"superset_of"},{"control_id":"APO12","coverage":"partial","delta":"operational risk identification, assessment, and response processes","framework":"cobit-2019","relationship":"intersects_with"}],"statement":"Establish, document, and communicate a leadership-approved enterprise risk management strategy, including risk management objectives agreed by stakeholders, defined risk appetite and tolerance statements, and a documented risk assessment policy with procedures and a consistent methodology for identifying, analyzing, prioritizing, and responding to risk. Ensure governance activities keep risk-taking optimized within appetite, and review and update the strategy, appetite, and policy at planned intervals.","title":"Establish enterprise risk management strategy and appetite","unified_id":"UC-GOV-17"},"id":"uc:UC-GOV-17","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-17","sourceIds":["cobit-2019","coso-erm","nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"UC-GOV-17 — Establish enterprise risk management strategy and appetite","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:032867964d8caa1f9119972d8d8336c3580a8e4908cc929807dd69afff643b61","properties":{"control_id":"EDM03","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-17-5ee3266f.json","sourceId":"uc:UC-GOV-17","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-edm03-5708b8c4.json","targetId":"ctrl:cobit-2019:EDM03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1b87a312f8e6957f4535e9ecde50755cfe2f64dea50f38b231f7204c68e6a34a","properties":{"control_id":"PM-9","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-17-5ee3266f.json","sourceId":"uc:UC-GOV-17","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-9-732078be.json","targetId":"ctrl:nist-800-53:PM-9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3a0f2e69c088ac34e68a1248331a1aa1dab5e336e298d9773e3a5d33693336b7","properties":{"rationale":"Establishing the risk-assessment policy, methodology, appetite, and process directly remedies an absent or inadequate risk-assessment process.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-17-5ee3266f.json","sourceId":"uc:UC-GOV-17","targetDetailPath":"/data/v1/records/risk-risk-assessment-inadequate-328128b5.json","targetId":"risk:risk-assessment-inadequate","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7559d0ca4657fd1e817f539117d4e5d7f00bd68021be5ae88b2cc7d9e7389af0","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-17-5ee3266f.json","sourceId":"uc:UC-GOV-17","targetDetailPath":"/data/v1/records/risk-compliance-improper-market-practices-9c55cfe9.json","targetId":"risk:compliance-improper-market-practices","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7d14a14475f8d603e7f0fa784835996afba75b4dafe5e224fef71e09ac5f2c5d","properties":{},"sourceDetailPath":"/data/v1/records/wf-g16-694f4e2b.json","sourceId":"wf:G16","targetDetailPath":"/data/v1/records/uc-uc-gov-17-5ee3266f.json","targetId":"uc:UC-GOV-17","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:81b183c354110d23bb4f0279df5612d5d53707b19186b9b578d40919ad58e69f","properties":{"control_id":"E7","coverage":"full","delta":null,"framework":"coso-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-17-5ee3266f.json","sourceId":"uc:UC-GOV-17","targetDetailPath":"/data/v1/records/ctrl-coso-erm-e7-a3229c35.json","targetId":"ctrl:coso-erm:E7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9a09c37a0f69d4471e942e27d3d1797d72396ff3a35587428d1341c222733407","properties":{"control_id":"RA-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-17-5ee3266f.json","sourceId":"uc:UC-GOV-17","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ra-1-07dc0593.json","targetId":"ctrl:nist-800-53:RA-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a9edce24ec99044ebcc918f2f32a590d00d0b76979d26a83751525cff6d42b33","properties":{"control_id":"APO12","coverage":"partial","delta":"operational risk identification, assessment, and response processes","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-17-5ee3266f.json","sourceId":"uc:UC-GOV-17","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-apo12-9086e034.json","targetId":"ctrl:cobit-2019:APO12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cf87f22b3759f97f8319a1b6b5791ac4c95f90933ae7a4e4167c9ee046088446","properties":{},"sourceDetailPath":"/data/v1/records/wf-g11-62e4fa80.json","sourceId":"wf:G11","targetDetailPath":"/data/v1/records/uc-uc-gov-17-5ee3266f.json","targetId":"uc:UC-GOV-17","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ebe992cd6e7b612ee9c27a81a2c57fb877d1e16d53116b6a1387cbb8d2d03a33","properties":{"control_id":"GV.RM-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-17-5ee3266f.json","sourceId":"uc:UC-GOV-17","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-01-a04dd496.json","targetId":"ctrl:nist-csf-2:GV.RM-01","type":"maps_to"}],"schemaVersion":1}
