{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Human Resources / Personnel Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-HR-02","description":"Employment contracts and terms state each individual's information security responsibilities, including obligations that survive employment. Personnel sign confidentiality or non-disclosure agreements and access agreements before being granted access, and re-sign when agreements are materially updated. Position descriptions document role-specific security duties, and signed acknowledgments are retained as evidence.","details":{"control_category":"administrative","control_type":"preventive","domain":"Human Resources / Personnel Security","guidance":[],"members":[{"control_id":"PS-6","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PS-9","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.6.2","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"A.6.6","coverage":"partial","delta":"NDAs from external/other interested parties, addressed by the third-party personnel control","framework":"iso-27001","relationship":"intersects_with"}],"statement":"Employment contracts and terms state each individual's information security responsibilities, including obligations that survive employment. Personnel sign confidentiality or non-disclosure agreements and access agreements before being granted access, and re-sign when agreements are materially updated. Position descriptions document role-specific security duties, and signed acknowledgments are retained as evidence.","title":"Formalize security responsibilities in employment terms","unified_id":"UC-HR-02"},"id":"uc:UC-HR-02","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-HR-02","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"UC-HR-02 — Formalize security responsibilities in employment terms","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:01e23ae5a796875e721f64dd4fb87b98dddb979298813930e1cb4d6ee9b61842","properties":{},"sourceDetailPath":"/data/v1/records/wf-c7-acbef2ee.json","sourceId":"wf:C7","targetDetailPath":"/data/v1/records/uc-uc-hr-02-a54c8912.json","targetId":"uc:UC-HR-02","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:346c101ee7548d0c65e6f981ebbda843783a5bcd2c48490b24f826076db54276","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-02-a54c8912.json","sourceId":"uc:UC-HR-02","targetDetailPath":"/data/v1/records/risk-hr-discrimination-harassment-767d6cb7.json","targetId":"risk:hr-discrimination-harassment","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:38805ad4453a6a209d92fc85fb3c05e329471ee52082ee2d100823409d2cebda","properties":{},"sourceDetailPath":"/data/v1/records/wf-g25-fdd65bfd.json","sourceId":"wf:G25","targetDetailPath":"/data/v1/records/uc-uc-hr-02-a54c8912.json","targetId":"uc:UC-HR-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:466a020d9155bf095f26f8dfdceec468959b77f8f152099748d1ae2efcd0adf4","properties":{"control_id":"A.6.2","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-02-a54c8912.json","sourceId":"uc:UC-HR-02","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-6-2-89c7f287.json","targetId":"ctrl:iso-27001:A.6.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:64ba3437d0674ef1c7bdd38a43157d848551ada9d7a9f07d7eabd9740296fb41","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-hr-02-a54c8912.json","targetId":"uc:UC-HR-02","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:674e78b74b62c27b59aa3b326d707784d11fc45fd4b6f3e8467c8197ddd20ace","properties":{"control_id":"PS-6","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-02-a54c8912.json","sourceId":"uc:UC-HR-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ps-6-4440ab25.json","targetId":"ctrl:nist-800-53:PS-6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:94f49510d64c5d65dddcfb5749b810bef56d079f70b1c2b48be497f0e39119f8","properties":{"control_id":"A.6.6","coverage":"partial","delta":"NDAs from external/other interested parties, addressed by the third-party personnel control","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-02-a54c8912.json","sourceId":"uc:UC-HR-02","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-6-6-1b732496.json","targetId":"ctrl:iso-27001:A.6.6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cfa198534da77adaed75f554df00b80eb0630dbe083ca2aef093055366f194e5","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-hr-02-a54c8912.json","targetId":"uc:UC-HR-02","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e4eac034b0068b856f47e4dc6577e0626bbfc3acafbe074f91184edcb38f93bc","properties":{"control_id":"PS-9","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-02-a54c8912.json","sourceId":"uc:UC-HR-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ps-9-958e0b88.json","targetId":"ctrl:nist-800-53:PS-9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb6ffdc2557ad76361ef72397aedaed3b295cdf5a147e754afbe01d963ee4abd","properties":{"rationale":"Embeds infosec responsibilities, confidentiality/NDA and access agreements into employment terms, directly closing the missing-security-contract-terms gap.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-02-a54c8912.json","sourceId":"uc:UC-HR-02","targetDetailPath":"/data/v1/records/risk-hr-missing-security-terms-discipline-0a47163d.json","targetId":"risk:hr-missing-security-terms-discipline","type":"mitigates"}],"schemaVersion":1}
