{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-35","description":"Establish, document, and disseminate an incident response policy and supporting procedures that define what constitutes a security incident, roles, responsibilities, and authorities, and requirements for detection, internal reporting, handling, escalation, and post-incident review. Review and update the policy and procedures at defined intervals and after significant incidents or exercises.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"IR-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"NIS2-Art21b","coverage":"partial","delta":"operational incident detection, handling, and response capability","framework":"nis2","relationship":"intersects_with"}],"statement":"Establish, document, and disseminate an incident response policy and supporting procedures that define what constitutes a security incident, roles, responsibilities, and authorities, and requirements for detection, internal reporting, handling, escalation, and post-incident review. Review and update the policy and procedures at defined intervals and after significant incidents or exercises.","title":"Maintain incident response policy and procedures","unified_id":"UC-GOV-35"},"id":"uc:UC-GOV-35","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-35","sourceIds":["nis2","nist-800-53"],"sourceUrl":null,"title":"UC-GOV-35 — Maintain incident response policy and procedures","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1761356601b0bff62e19bc5bb4f2f0214310024d0cb128365be184e18252f112","properties":{"control_id":"NIS2-Art21b","coverage":"partial","delta":"operational incident detection, handling, and response capability","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-35-b003f925.json","sourceId":"uc:UC-GOV-35","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21b-0635d82d.json","targetId":"ctrl:nis2:NIS2-Art21b","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:70688cb7d150ee99386a94479f65201517d189fb4ecc975352a921c4d8a36b3e","properties":{"rationale":"Defined detection, escalation, and post-incident review reduce the reputational damage of mishandled breaches.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-35-b003f925.json","sourceId":"uc:UC-GOV-35","targetDetailPath":"/data/v1/records/risk-reputational-brand-crisis-4d7c293d.json","targetId":"risk:reputational-brand-crisis","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ac8743ff250a1b216aa3f8579d8240bb903f102f806ab918b2c75df9724fd31d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-35-b003f925.json","targetId":"uc:UC-GOV-35","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b8b887883f62a50435a168d03b6f1aaf3265148b44a84136bd1a09b39d5d82db","properties":{"control_id":"IR-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-35-b003f925.json","sourceId":"uc:UC-GOV-35","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ir-1-de4620ea.json","targetId":"ctrl:nist-800-53:IR-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f161121f24a878f107ad43ff7ae8ddca3eaa21fea212cd13fde4ae75071e0f4a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c26-0d7976b8.json","sourceId":"wf:C26","targetDetailPath":"/data/v1/records/uc-uc-gov-35-b003f925.json","targetId":"uc:UC-GOV-35","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f302d6bc9aa84cc234fc1d08bb67cff3d6c9f21a4d211d1ea21e7dbfab631047","properties":{},"sourceDetailPath":"/data/v1/records/wf-g9-d1e65641.json","sourceId":"wf:G9","targetDetailPath":"/data/v1/records/uc-uc-gov-35-b003f925.json","targetId":"uc:UC-GOV-35","type":"oversees"}],"schemaVersion":1}
