{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-37","description":"Implement an insider threat program that includes a cross-discipline insider threat incident handling team and defined indicators, reporting channels, and response procedures, together with a threat awareness program that shares current threat information across the organization, including with leadership and security personnel. Review the effectiveness of both programs at defined intervals and adjust them to the evolving threat environment.","details":{"control_category":"administrative","control_type":"detective","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"PM-12","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PM-16","coverage":"partial","delta":"PM-16 requires cross-organization (inter-organizational) threat-intelligence sharing, not only internal dissemination","framework":"nist-800-53","relationship":"intersects_with"}],"statement":"Implement an insider threat program that includes a cross-discipline insider threat incident handling team and defined indicators, reporting channels, and response procedures, together with a threat awareness program that shares current threat information across the organization, including with leadership and security personnel. Review the effectiveness of both programs at defined intervals and adjust them to the evolving threat environment.","title":"Operate insider-threat and threat-awareness programs","unified_id":"UC-GOV-37"},"id":"uc:UC-GOV-37","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-37","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-GOV-37 — Operate insider-threat and threat-awareness programs","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0f4df0b1f2b6286be0d0bf893b312a382f06412a78120807b6ffc7ac5611042e","properties":{"rationale":"An insider-threat program with defined indicators, reporting channels, and response detects and deters insider theft and fraud.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-37-8fd5a91b.json","sourceId":"uc:UC-GOV-37","targetDetailPath":"/data/v1/records/risk-fraud-internal-misappropriation-d235cd10.json","targetId":"risk:fraud-internal-misappropriation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:820f596c37f27dae3b239817dd42c2cc6b515e8c3ad9a8a049d63f75043ddcb7","properties":{"control_id":"PM-12","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-37-8fd5a91b.json","sourceId":"uc:UC-GOV-37","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-12-473cd679.json","targetId":"ctrl:nist-800-53:PM-12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bb972e44256aca18fe9a60427a0533c7f591e59d850fe3210c3a5632e2ae8e70","properties":{},"sourceDetailPath":"/data/v1/records/wf-c20-5b99e185.json","sourceId":"wf:C20","targetDetailPath":"/data/v1/records/uc-uc-gov-37-8fd5a91b.json","targetId":"uc:UC-GOV-37","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c7aa096e58657235dcbe302ea3cfc96f2833ce7e0e668b144120df8c554cebc0","properties":{"control_id":"PM-16","coverage":"partial","delta":"PM-16 requires cross-organization (inter-organizational) threat-intelligence sharing, not only internal dissemination","framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-37-8fd5a91b.json","sourceId":"uc:UC-GOV-37","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-16-363dd0bb.json","targetId":"ctrl:nist-800-53:PM-16","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e32060dff82fb286105da1a34c4a9546e0f5efa53242470dd1f5a4fc7fdffbaa","properties":{"rationale":"Insider-threat indicators and monitoring add a detective layer over concealed rogue activity.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-37-8fd5a91b.json","sourceId":"uc:UC-GOV-37","targetDetailPath":"/data/v1/records/risk-fraud-unauthorized-trading-activity-e5d9d4b9.json","targetId":"risk:fraud-unauthorized-trading-activity","type":"mitigates"}],"schemaVersion":1}
