{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-22","description":"Maintain a documented assessment and authorization policy with procedures, defined performance measures, and quality monitoring to regularly evaluate whether security policies, standards, and risk-management measures are implemented, complied with, and effective — including managers' reviews of compliance within their areas of responsibility. Feed assessment results into a formal, risk-based authorization process in which a senior official explicitly accepts residual risk before systems operate and at defined intervals thereafter, and track findings to closure.","details":{"control_category":"administrative","control_type":"detective","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"PM-6","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"CA-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PM-10","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.5.36","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"NIS2-Art21f","coverage":"full","framework":"nis2","relationship":"superset_of"},{"control_id":"APO11","coverage":"partial","delta":"embedding quality management practices across processes, projects, and deliverables","framework":"cobit-2019","relationship":"intersects_with"}],"statement":"Maintain a documented assessment and authorization policy with procedures, defined performance measures, and quality monitoring to regularly evaluate whether security policies, standards, and risk-management measures are implemented, complied with, and effective — including managers' reviews of compliance within their areas of responsibility. Feed assessment results into a formal, risk-based authorization process in which a senior official explicitly accepts residual risk before systems operate and at defined intervals thereafter, and track findings to closure.","title":"Assess control effectiveness and authorize systems","unified_id":"UC-GOV-22"},"id":"uc:UC-GOV-22","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-22","sourceIds":["cobit-2019","iso-27001","nis2","nist-800-53"],"sourceUrl":null,"title":"UC-GOV-22 — Assess control effectiveness and authorize systems","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:27b6d243991a6ca4120f3985439b0a7f95e65f0f0851cf2c832c625f6b34c549","properties":{"control_id":"A.5.36","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-22-c0b503b4.json","sourceId":"uc:UC-GOV-22","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-36-669a705b.json","targetId":"ctrl:iso-27001:A.5.36","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:513a140b237672d5a5a63a0b5a4d852b46b4a0f9b2d5f12623593bfafdb88983","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-22-c0b503b4.json","sourceId":"uc:UC-GOV-22","targetDetailPath":"/data/v1/records/risk-compliance-improper-market-practices-9c55cfe9.json","targetId":"risk:compliance-improper-market-practices","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:67dd2fc4c66a76dfb624ab150a468d8306a9c567880b097faf8097b944363c0d","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-gov-22-c0b503b4.json","targetId":"uc:UC-GOV-22","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6a776a9cae07741a26f4493bb38ee3d0618efaaf12b4c046084f2fd7d7e7e970","properties":{"control_id":"PM-6","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-22-c0b503b4.json","sourceId":"uc:UC-GOV-22","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-6-575f7251.json","targetId":"ctrl:nist-800-53:PM-6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7f09401880d79a7d47360a60cf925b304d7d26eb19a9b83c74431e9b98b0ebd6","properties":{"control_id":"APO11","coverage":"partial","delta":"embedding quality management practices across processes, projects, and deliverables","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-22-c0b503b4.json","sourceId":"uc:UC-GOV-22","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-apo11-92538e06.json","targetId":"ctrl:cobit-2019:APO11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:85dc497018d994be7c837fb3325bac65b602caea08c4171bb9c5e3b5cbae10ab","properties":{"control_id":"CA-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-22-c0b503b4.json","sourceId":"uc:UC-GOV-22","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ca-1-809e44db.json","targetId":"ctrl:nist-800-53:CA-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8826af7bcd4bdfeaf33eca5b5812a47ee268736e8e2a5e06cf93ef4480ed9ffc","properties":{"rationale":"Regularly assessing control effectiveness and tracking findings to closure detects and challenges deficiencies that would otherwise persist.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-22-c0b503b4.json","sourceId":"uc:UC-GOV-22","targetDetailPath":"/data/v1/records/risk-compliance-no-independent-audit-9e1acf0f.json","targetId":"risk:compliance-no-independent-audit","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8bc5ecdfef9177e5aa57e80f06e67829da032d67ed57e660fa2f4cac76c046eb","properties":{"control_id":"PM-10","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-22-c0b503b4.json","sourceId":"uc:UC-GOV-22","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-10-2556e164.json","targetId":"ctrl:nist-800-53:PM-10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e128b49ab78886cf2d4a9a1a526b51a15308cc2aa1cedac229bdcf6765ac54a5","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-22-c0b503b4.json","targetId":"uc:UC-GOV-22","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:efe87a3d98c9f4d13cec684366522ee57c67f4957369c307119cf4018d4e872d","properties":{"control_id":"NIS2-Art21f","coverage":"full","delta":null,"framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-22-c0b503b4.json","sourceId":"uc:UC-GOV-22","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21f-a9a69314.json","targetId":"ctrl:nis2:NIS2-Art21f","type":"maps_to"}],"schemaVersion":1}
