{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-29","description":"Establish, document, and disseminate policies and procedures governing security in system and services acquisition, in-house application development, configuration management, and system maintenance — including secure development standards, evaluation criteria for externally developed applications, and baseline configuration requirements. Review, assess, and update these policies and procedures at least annually under accountable security leadership and after significant changes.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"SA-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"CM-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"MA-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"500.8","coverage":"full","framework":"nydfs-500","relationship":"superset_of"},{"control_id":"NIS2-Art21e","coverage":"partial","delta":"operational vulnerability handling and coordinated disclosure processes","framework":"nis2","relationship":"intersects_with"}],"statement":"Establish, document, and disseminate policies and procedures governing security in system and services acquisition, in-house application development, configuration management, and system maintenance — including secure development standards, evaluation criteria for externally developed applications, and baseline configuration requirements. Review, assess, and update these policies and procedures at least annually under accountable security leadership and after significant changes.","title":"Maintain secure acquisition, development, and maintenance policies","unified_id":"UC-GOV-29"},"id":"uc:UC-GOV-29","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-29","sourceIds":["nis2","nist-800-53","nydfs-500"],"sourceUrl":null,"title":"UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0c5d2f207b498cc309458da0f8f750182a4a9ec79417139ab3dc080ecd9d3b10","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","targetId":"uc:UC-GOV-29","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1a663343145533a04509d71da542b53189545e4574b887ad8979570e55e3f323","properties":{},"sourceDetailPath":"/data/v1/records/wf-g9-d1e65641.json","sourceId":"wf:G9","targetDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","targetId":"uc:UC-GOV-29","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3a829b6ca593c3e21eebcb887c48edae239f0b3035f585ef88ce84c5d2c743b4","properties":{},"sourceDetailPath":"/data/v1/records/wf-c26-0d7976b8.json","sourceId":"wf:C26","targetDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","targetId":"uc:UC-GOV-29","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6d57ed165f46a76bcba83a99aa07a9d70429b63a52da1b10097d9fcd6e2de215","properties":{"control_id":"500.8","coverage":"full","delta":null,"framework":"nydfs-500","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"23 NYCRR 500, Second Amendment"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","sourceId":"uc:UC-GOV-29","targetDetailPath":"/data/v1/records/ctrl-nydfs-500-500-8-68ba80b6.json","targetId":"ctrl:nydfs-500:500.8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8814f4263d4948a6771c5cdeca0d45bbcffbe730f3c4495ff14cbcab2c4bcf36","properties":{"control_id":"SA-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","sourceId":"uc:UC-GOV-29","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sa-1-a187c408.json","targetId":"ctrl:nist-800-53:SA-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e2cc926abdc7649873b87687a8659072360f3dd3f0f646b09684185fe553d3a8","properties":{"rationale":"Establishing secure acquisition, development, configuration, and maintenance policies remedies missing policies for this domain.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","sourceId":"uc:UC-GOV-29","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e9da928f8c41e88d3ce4bf2cc03c0cb2db1fd898571e0cbf2117e60748c7e752","properties":{"control_id":"MA-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","sourceId":"uc:UC-GOV-29","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ma-1-bca9da7c.json","targetId":"ctrl:nist-800-53:MA-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f2d3c58671aec19e31faee03ea3ae74ddbe8bca2ab26be3fb48fbdd0a95b8193","properties":{"rationale":"Evaluation criteria for externally developed applications set security requirements on acquired third-party software.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","sourceId":"uc:UC-GOV-29","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fe15b724b199394d4b56191c1b2742de04428143b9430321f9301dab97f78e16","properties":{"control_id":"CM-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","sourceId":"uc:UC-GOV-29","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-1-1cc86d9d.json","targetId":"ctrl:nist-800-53:CM-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ff531a29006ff50ac533d73cfb7b5ad9408ec7a35f9e0191d02e032942133703","properties":{"control_id":"NIS2-Art21e","coverage":"partial","delta":"operational vulnerability handling and coordinated disclosure processes","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","sourceId":"uc:UC-GOV-29","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21e-ae62ba80.json","targetId":"ctrl:nis2:NIS2-Art21e","type":"maps_to"}],"schemaVersion":1}
