{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-36","description":"Establish, document, and disseminate policies and procedures for system and communications protection, including the required use of cryptography and encryption, secured communication channels, and multi-factor and strong authentication expectations for remote and privileged access. Review and update these policies at defined intervals and as cryptographic standards and threats evolve.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"SC-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"NIS2-Art21h","coverage":"full","framework":"nis2","relationship":"superset_of"},{"control_id":"NIS2-Art21j","coverage":"partial","delta":"actual deployment of MFA and secured emergency communication systems","framework":"nis2","relationship":"intersects_with"}],"statement":"Establish, document, and disseminate policies and procedures for system and communications protection, including the required use of cryptography and encryption, secured communication channels, and multi-factor and strong authentication expectations for remote and privileged access. Review and update these policies at defined intervals and as cryptographic standards and threats evolve.","title":"Maintain communications security and cryptography policies","unified_id":"UC-GOV-36"},"id":"uc:UC-GOV-36","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-36","sourceIds":["nis2","nist-800-53"],"sourceUrl":null,"title":"UC-GOV-36 — Maintain communications security and cryptography policies","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:166855d3a2e2b69b9c4db7645bbfd56c9cc7d36d893b9f99cdfc09cd532b423c","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-36-8eac71a2.json","targetId":"uc:UC-GOV-36","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:189b3985dfa4c056997dd2abf022b0f59bd800f8a62097d80e959879fc0e55b0","properties":{},"sourceDetailPath":"/data/v1/records/wf-g9-d1e65641.json","sourceId":"wf:G9","targetDetailPath":"/data/v1/records/uc-uc-gov-36-8eac71a2.json","targetId":"uc:UC-GOV-36","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:251c0e73768ca98fda93f31a33027edba793af39a97341f6031fd10d38f36631","properties":{"rationale":"Establishing communications-security and cryptography policies (encryption, MFA expectations) remedies missing policy for this domain.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-36-8eac71a2.json","sourceId":"uc:UC-GOV-36","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:41aaa7a64c3af985962f3ffbcae842e2e36a2e728a20575c4b0bc514d1fdc3ec","properties":{"control_id":"NIS2-Art21h","coverage":"full","delta":null,"framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-36-8eac71a2.json","sourceId":"uc:UC-GOV-36","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21h-59950523.json","targetId":"ctrl:nis2:NIS2-Art21h","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5275d1a4960973895785ebf2e65f6f951a2eb9fa4cd28fb7baa7f87e5698bece","properties":{"control_id":"SC-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-36-8eac71a2.json","sourceId":"uc:UC-GOV-36","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-1-e5853fb5.json","targetId":"ctrl:nist-800-53:SC-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6b57a277a7d8f8fa698438f9358b04b4dfa0a04db4dcdaaeab3804dde976104c","properties":{"control_id":"NIS2-Art21j","coverage":"partial","delta":"actual deployment of MFA and secured emergency communication systems","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-36-8eac71a2.json","sourceId":"uc:UC-GOV-36","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21j-49982c35.json","targetId":"ctrl:nis2:NIS2-Art21j","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:84597e04a3c368bb0c99544fbdc2d416be456559ea49b7d5f8358d138ae4df6c","properties":{},"sourceDetailPath":"/data/v1/records/wf-c26-0d7976b8.json","sourceId":"wf:C26","targetDetailPath":"/data/v1/records/uc-uc-gov-36-8eac71a2.json","targetId":"uc:UC-GOV-36","type":"operates"}],"schemaVersion":1}
