{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"corrective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-24","description":"Maintain documented procedures to notify supervisory and regulatory bodies of reportable cybersecurity events within mandated regulatory timelines, including any staged early-warning, detailed-notification, and final-report deadlines, and to submit required periodic compliance certifications and filings. Handle regulatory submissions and related materials confidentially, and retain evidence of all notifications, certifications, and supporting records.","details":{"control_category":"administrative","control_type":"corrective","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"500.17","coverage":"full","framework":"nydfs-500","relationship":"superset_of"},{"control_id":"NIS2-Art23","coverage":"partial","delta":"staged deadlines (early warning 24h, notification 72h, final report within one month); Art 23 also requires notifying service recipients of significant incidents and threat remedies","framework":"nis2","relationship":"intersects_with"},{"control_id":"500.18","coverage":"full","framework":"nydfs-500","relationship":"superset_of"}],"statement":"Maintain documented procedures to notify supervisory and regulatory bodies of reportable cybersecurity events within mandated regulatory timelines, including any staged early-warning, detailed-notification, and final-report deadlines, and to submit required periodic compliance certifications and filings. Handle regulatory submissions and related materials confidentially, and retain evidence of all notifications, certifications, and supporting records.","title":"Notify regulators of incidents and file required certifications","unified_id":"UC-GOV-24"},"id":"uc:UC-GOV-24","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-24","sourceIds":["nis2","nydfs-500"],"sourceUrl":null,"title":"UC-GOV-24 — Notify regulators of incidents and file required certifications","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6a395e5bdd2e15e676e1508c2595987a0b3e68accf57e99be3b01eb9e860e818","properties":{"rationale":"Notifying regulators within mandated timelines and filing required certifications avoids penalties for late or missing regulatory reporting.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-24-b737644b.json","sourceId":"uc:UC-GOV-24","targetDetailPath":"/data/v1/records/risk-compliance-litigation-enforcement-25e7935d.json","targetId":"risk:compliance-litigation-enforcement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6f4aee545a5876c856bbabf8c732c3c8e6a772d7fa6fe334a523b19ac7da79fb","properties":{"rationale":"Timely, proper incident notification limits the reputational fallout of mishandled disclosure.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-24-b737644b.json","sourceId":"uc:UC-GOV-24","targetDetailPath":"/data/v1/records/risk-reputational-brand-crisis-4d7c293d.json","targetId":"risk:reputational-brand-crisis","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:709b8253a5475a1ecc520787a7b313cd93a6dfd9f5ba7d459532e88c2b9f68a4","properties":{"control_id":"500.17","coverage":"full","delta":null,"framework":"nydfs-500","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"23 NYCRR 500, Second Amendment"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-24-b737644b.json","sourceId":"uc:UC-GOV-24","targetDetailPath":"/data/v1/records/ctrl-nydfs-500-500-17-25353c71.json","targetId":"ctrl:nydfs-500:500.17","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a94821c88120c0a34de463ab23423da8d500d76388a26aef2a189d9cc82122f8","properties":{"control_id":"NIS2-Art23","coverage":"partial","delta":"staged deadlines (early warning 24h, notification 72h, final report within one month); Art 23 also requires notifying service recipients of significant incidents and threat remedies","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-24-b737644b.json","sourceId":"uc:UC-GOV-24","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art23-93f21077.json","targetId":"ctrl:nis2:NIS2-Art23","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e223584687b5204e754de74a0c4f12c90c4b09f7d942666800c1256ced40aaf2","properties":{"control_id":"500.18","coverage":"full","delta":null,"framework":"nydfs-500","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"23 NYCRR 500, Second Amendment"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-24-b737644b.json","sourceId":"uc:UC-GOV-24","targetDetailPath":"/data/v1/records/ctrl-nydfs-500-500-18-1e1c055e.json","targetId":"ctrl:nydfs-500:500.18","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e74461fd8134725e4382e89324b0401d067f371e2fdb2244355d6a61c95d2265","properties":{},"sourceDetailPath":"/data/v1/records/wf-g7-9762f11b.json","sourceId":"wf:G7","targetDetailPath":"/data/v1/records/uc-uc-gov-24-b737644b.json","targetId":"uc:UC-GOV-24","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f284418a1b6e2607a19c440df6684dab6a0206def8e6889a7704641ad827b848","properties":{},"sourceDetailPath":"/data/v1/records/wf-r1-a5f4fc75.json","sourceId":"wf:R1","targetDetailPath":"/data/v1/records/uc-uc-gov-24-b737644b.json","targetId":"uc:UC-GOV-24","type":"oversees"}],"schemaVersion":1}
