{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-20","description":"Establish data governance: policies and standards for managing data through its life cycle, and formally chartered governance bodies (e.g., a data governance body and, where required, a data integrity board) with defined membership and responsibilities. These bodies oversee data management, data quality and integrity, and the review and approval of data-sharing and matching agreements, and report on data governance at defined intervals.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"APO14","coverage":"partial","delta":"operational data management - data-management strategy, business glossary/metadata, data-quality profiling and cleansing, archiving/backup - beyond governance policy and oversight bodies","framework":"cobit-2019","relationship":"intersects_with"},{"control_id":"PM-23","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PM-24","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Establish data governance: policies and standards for managing data through its life cycle, and formally chartered governance bodies (e.g., a data governance body and, where required, a data integrity board) with defined membership and responsibilities. These bodies oversee data management, data quality and integrity, and the review and approval of data-sharing and matching agreements, and report on data governance at defined intervals.","title":"Govern data as an asset with accountable oversight bodies","unified_id":"UC-GOV-20"},"id":"uc:UC-GOV-20","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-20","sourceIds":["cobit-2019","nist-800-53"],"sourceUrl":null,"title":"UC-GOV-20 — Govern data as an asset with accountable oversight bodies","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0aa6683a8761f30f427b043b69688c089250fe3ee622f55c3d34e2fac9860252","properties":{"rationale":"Overseeing data quality and integrity supports the reliable data underlying financial reporting.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-20-4a468c1a.json","sourceId":"uc:UC-GOV-20","targetDetailPath":"/data/v1/records/risk-fin-icfr-material-weakness-cdd66323.json","targetId":"risk:fin-icfr-material-weakness","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:39dff700e2a0bbdef624f431f6804954b71d44876cada877e7f382362a2cddea","properties":{"control_id":"APO14","coverage":"partial","delta":"operational data management - data-management strategy, business glossary/metadata, data-quality profiling and cleansing, archiving/backup - beyond governance policy and oversight bodies","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-20-4a468c1a.json","sourceId":"uc:UC-GOV-20","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-apo14-ab650d02.json","targetId":"ctrl:cobit-2019:APO14","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:487203ab534ac8c1b60b9ac4aa16278b95af18a66777b5dc85eebdc34019c1b4","properties":{"rationale":"Reviewing and approving data-sharing and matching agreements controls data exposed to third parties.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-20-4a468c1a.json","sourceId":"uc:UC-GOV-20","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:545f2f1c82881f38a269189c568d7e2bc38d1eeff040c232a684f7942057e90c","properties":{"control_id":"PM-23","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-20-4a468c1a.json","sourceId":"uc:UC-GOV-20","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-23-4ebf2cf2.json","targetId":"ctrl:nist-800-53:PM-23","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a95775424e6bb9efd2d860397c677e086315572ac9172c381ef30456afbd8a0f","properties":{},"sourceDetailPath":"/data/v1/records/wf-g21-6aec79d1.json","sourceId":"wf:G21","targetDetailPath":"/data/v1/records/uc-uc-gov-20-4a468c1a.json","targetId":"uc:UC-GOV-20","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d5c5c884c8a9c59593bd692124fe3444ee3063d0e197a5725ad73c73b8c695c3","properties":{"rationale":"Data-governance policies and chartered bodies with defined membership and responsibilities remedy missing data policies and undefined roles.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-20-4a468c1a.json","sourceId":"uc:UC-GOV-20","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f15c084a9cbb50d48990a455a9ba09944832bd0116527c6f245d3b1b66e34581","properties":{"control_id":"PM-24","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-20-4a468c1a.json","sourceId":"uc:UC-GOV-20","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-24-b1650f02.json","targetId":"ctrl:nist-800-53:PM-24","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fbecb4c86da919629b08afe9f03e295de74c3a8bb4c945eed5b019891e038209","properties":{},"sourceDetailPath":"/data/v1/records/wf-g15-1231bc14.json","sourceId":"wf:G15","targetDetailPath":"/data/v1/records/uc-uc-gov-20-4a468c1a.json","targetId":"uc:UC-GOV-20","type":"oversees"}],"schemaVersion":1}
