{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-33","description":"Establish, document, and disseminate policies and procedures for audit logging and accountability and for system and information integrity, and define an organization-wide continuous monitoring strategy specifying metrics, monitoring and assessment frequencies, and how results inform risk decisions. Review and update the policies and the monitoring strategy at defined intervals and upon significant change.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"AU-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SI-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PM-31","coverage":"partial","delta":"implementing the monitoring program - ongoing monitoring, correlation/analysis, response actions, and status reporting - satisfied by the continuous-monitoring companion control (CA-7 home)","framework":"nist-800-53","relationship":"intersects_with"}],"statement":"Establish, document, and disseminate policies and procedures for audit logging and accountability and for system and information integrity, and define an organization-wide continuous monitoring strategy specifying metrics, monitoring and assessment frequencies, and how results inform risk decisions. Review and update the policies and the monitoring strategy at defined intervals and upon significant change.","title":"Maintain logging, monitoring, and system integrity policies","unified_id":"UC-GOV-33"},"id":"uc:UC-GOV-33","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-33","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-GOV-33 — Maintain logging, monitoring, and system integrity policies","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0007c5bad42417861d468c19c08e7bbfaf3492e7e1513aec505372f80fa60679","properties":{"control_id":"PM-31","coverage":"partial","delta":"implementing the monitoring program - ongoing monitoring, correlation/analysis, response actions, and status reporting - satisfied by the continuous-monitoring companion control (CA-7 home)","framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-33-50bafd1b.json","sourceId":"uc:UC-GOV-33","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-31-18226732.json","targetId":"ctrl:nist-800-53:PM-31","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8492b3183360605efaa6231f21ace4d883bad855101b7893a1cff8939d6362c2","properties":{"control_id":"AU-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-33-50bafd1b.json","sourceId":"uc:UC-GOV-33","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-au-1-c04f4c39.json","targetId":"ctrl:nist-800-53:AU-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:852a4a54f4e51339ae6119d7b4af02494ee00aca521cdb405d30992a53dcdd35","properties":{},"sourceDetailPath":"/data/v1/records/wf-c26-0d7976b8.json","sourceId":"wf:C26","targetDetailPath":"/data/v1/records/uc-uc-gov-33-50bafd1b.json","targetId":"uc:UC-GOV-33","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8c3d5de4262f6ead11fef1e9374cc1e779b32feded749a47a40e6ef1c656b067","properties":{"rationale":"Establishing audit-logging, integrity, and continuous-monitoring policies remedies missing policy for this domain.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-33-50bafd1b.json","sourceId":"uc:UC-GOV-33","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:988741cc23fe104184d595237a3e3a27adf50b582ee6d5b027e2196861d7f9fd","properties":{},"sourceDetailPath":"/data/v1/records/wf-c1-f9e3db77.json","sourceId":"wf:C1","targetDetailPath":"/data/v1/records/uc-uc-gov-33-50bafd1b.json","targetId":"uc:UC-GOV-33","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f244b624f1ecae47a6fdde9ce9d87cc868fa1f9ef5b45caea1157b72939cb1f6","properties":{"control_id":"SI-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-33-50bafd1b.json","sourceId":"uc:UC-GOV-33","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-si-1-d116c2dc.json","targetId":"ctrl:nist-800-53:SI-1","type":"maps_to"}],"schemaVersion":1}
