{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-32","description":"Establish, document, and disseminate policies and procedures for security awareness, training, and basic cyber-hygiene practices applicable to all personnel, defining required content, frequency, audiences, and completion tracking. Review and update the policy and program requirements at defined intervals and in response to changes in threats and incidents.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"AT-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"NIS2-Art21g","coverage":"partial","delta":"actual delivery of hygiene practices and training to all personnel","framework":"nis2","relationship":"intersects_with"}],"statement":"Establish, document, and disseminate policies and procedures for security awareness, training, and basic cyber-hygiene practices applicable to all personnel, defining required content, frequency, audiences, and completion tracking. Review and update the policy and program requirements at defined intervals and in response to changes in threats and incidents.","title":"Maintain security awareness and cyber-hygiene policies","unified_id":"UC-GOV-32"},"id":"uc:UC-GOV-32","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-32","sourceIds":["nis2","nist-800-53"],"sourceUrl":null,"title":"UC-GOV-32 — Maintain security awareness and cyber-hygiene policies","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:20932a427a95372b27fc90b544fbd1756924bf884b185ab1e739d5a38ca2f7ad","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-32-948a4756.json","targetId":"uc:UC-GOV-32","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:30b1b3877869e349fd75de8173872eeab37da6983ffe6aa5e2b21976f99e1488","properties":{},"sourceDetailPath":"/data/v1/records/wf-g9-d1e65641.json","sourceId":"wf:G9","targetDetailPath":"/data/v1/records/uc-uc-gov-32-948a4756.json","targetId":"uc:UC-GOV-32","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:46f35c5e592611f58485ac24a04b8f78888403062b9dc107fe469bf4f163a94f","properties":{"control_id":"NIS2-Art21g","coverage":"partial","delta":"actual delivery of hygiene practices and training to all personnel","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-32-948a4756.json","sourceId":"uc:UC-GOV-32","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21g-6280385a.json","targetId":"ctrl:nis2:NIS2-Art21g","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4a760fcc567e20c8fd330ef583b60f81d82c5562637becbcb37567687610101b","properties":{"rationale":"Establishing security-awareness and cyber-hygiene policies remedies missing policy for training content, cadence, and tracking.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-32-948a4756.json","sourceId":"uc:UC-GOV-32","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4b7629b69ae79728771d781567c1e53d132a8b38fcd0331d054068b0061d0a51","properties":{},"sourceDetailPath":"/data/v1/records/wf-c26-0d7976b8.json","sourceId":"wf:C26","targetDetailPath":"/data/v1/records/uc-uc-gov-32-948a4756.json","targetId":"uc:UC-GOV-32","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:61b56f43070bcae1e546729426ac3752644c22a5993d7a1927c9f7881e8bb2e6","properties":{"control_id":"AT-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-32-948a4756.json","sourceId":"uc:UC-GOV-32","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-at-1-393a6d4e.json","targetId":"ctrl:nist-800-53:AT-1","type":"maps_to"}],"schemaVersion":1}
