{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-19","description":"Establish and maintain an enterprise architecture, including security and privacy architectures, that describes how systems, information flows, and protections align with the organization's mission and strategy and address security and privacy risks. Review and update the architecture at defined intervals and reflect it in system security plans, solution designs, and acquisition decisions.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"PL-8","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PM-7","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"APO03","coverage":"partial","delta":"EA vision and multi-domain (business/data/application/technology) reference architecture plus enterprise-architecture services, beyond security/privacy architecture","framework":"cobit-2019","relationship":"intersects_with"}],"statement":"Establish and maintain an enterprise architecture, including security and privacy architectures, that describes how systems, information flows, and protections align with the organization's mission and strategy and address security and privacy risks. Review and update the architecture at defined intervals and reflect it in system security plans, solution designs, and acquisition decisions.","title":"Maintain enterprise security and privacy architecture","unified_id":"UC-GOV-19"},"id":"uc:UC-GOV-19","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-19","sourceIds":["cobit-2019","nist-800-53"],"sourceUrl":null,"title":"UC-GOV-19 — Maintain enterprise security and privacy architecture","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:05eae0d622bc754d552a2231beca45436e4939d2a119f680fb943330e492f127","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-19-115302cb.json","targetId":"uc:UC-GOV-19","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2aa4fa7bc1af52508f4235d64fa585a41656764a266479b123210712244ba2dd","properties":{"rationale":"Enterprise architecture aligns technology to an existing strategy, supporting execution, but does not set or correct the strategy itself; UC-GOV-12 is the operative alignment control.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-19-115302cb.json","sourceId":"uc:UC-GOV-19","targetDetailPath":"/data/v1/records/risk-strategic-misalignment-execution-d9c0675b.json","targetId":"risk:strategic-misalignment-execution","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:72990f4f4f171507f35400a202b3e2eefbe6143dfafe307117a947e2d1e74e79","properties":{},"sourceDetailPath":"/data/v1/records/wf-c28-1635c493.json","sourceId":"wf:C28","targetDetailPath":"/data/v1/records/uc-uc-gov-19-115302cb.json","targetId":"uc:UC-GOV-19","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b9f23399c0fa8eed2e34b2d08007581d4e7a88f0f685895d240caa9a2430279f","properties":{"control_id":"PL-8","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-19-115302cb.json","sourceId":"uc:UC-GOV-19","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pl-8-a03b2420.json","targetId":"ctrl:nist-800-53:PL-8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c2a59fb96c1d23e176614d4a30113c106aea7d1cb1b015a8092d320feead873c","properties":{"control_id":"PM-7","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-19-115302cb.json","sourceId":"uc:UC-GOV-19","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-7-965b2094.json","targetId":"ctrl:nist-800-53:PM-7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f0150af56262db15849d35b4a2f4499b9160beb986a4920fc1b938b468b1a1fd","properties":{"control_id":"APO03","coverage":"partial","delta":"EA vision and multi-domain (business/data/application/technology) reference architecture plus enterprise-architecture services, beyond security/privacy architecture","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-19-115302cb.json","sourceId":"uc:UC-GOV-19","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-apo03-5d678454.json","targetId":"ctrl:cobit-2019:APO03","type":"maps_to"}],"schemaVersion":1}
