{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Human Resources / Personnel Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-HR-06","description":"Human resources processes incorporate cybersecurity at each stage, from recruiting and onboarding through role change and separation, with defined security checkpoints. The organization defines competence requirements for roles, attracts and develops qualified personnel through training and performance evaluation, and plans for succession and contingency in security-relevant positions.","details":{"control_category":"administrative","control_type":"preventive","domain":"Human Resources / Personnel Security","guidance":[],"members":[{"control_id":"GV.RR-04","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"CC1.4","coverage":"full","framework":"soc2","relationship":"superset_of"}],"statement":"Human resources processes incorporate cybersecurity at each stage, from recruiting and onboarding through role change and separation, with defined security checkpoints. The organization defines competence requirements for roles, attracts and develops qualified personnel through training and performance evaluation, and plans for succession and contingency in security-relevant positions.","title":"Embed security and competence in HR practices","unified_id":"UC-HR-06"},"id":"uc:UC-HR-06","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-HR-06","sourceIds":["nist-csf-2","soc2"],"sourceUrl":null,"title":"UC-HR-06 — Embed security and competence in HR practices","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1ab76fafa621d96aa66912576c1e6c8a1de1ffe34e22b1c4b726baaed6ffb6b6","properties":{"rationale":"Developing personnel through training and embedding cybersecurity across HR stages builds a security-aware workforce; enabler, not the dedicated awareness-training control.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-06-36a1f4aa.json","sourceId":"uc:UC-HR-06","targetDetailPath":"/data/v1/records/risk-aware-insufficient-training-7cb09d2f.json","targetId":"risk:aware-insufficient-training","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:389675e3093fdf9664339a3729a967816507ac0f5878f448a776b9baa70061a0","properties":{"rationale":"Succession/contingency planning for security-relevant roles plus attracting and developing scarce skills directly reduces key-talent loss and knowledge-transfer gaps.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-06-36a1f4aa.json","sourceId":"uc:UC-HR-06","targetDetailPath":"/data/v1/records/risk-hr-talent-loss-succession-50c0fc0a.json","targetId":"risk:hr-talent-loss-succession","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3c8a74ba8b808c16ea07af1173a9c739f34f9d104a23aaef3786dd8bc15ebd4c","properties":{},"sourceDetailPath":"/data/v1/records/wf-d05-2302db1f.json","sourceId":"wf:D05","targetDetailPath":"/data/v1/records/uc-uc-hr-06-36a1f4aa.json","targetId":"uc:UC-HR-06","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5cee50095cc685c6afcb45a85ff83676717d3552fe246b800adffb3f2c65ff88","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-hr-06-36a1f4aa.json","targetId":"uc:UC-HR-06","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b305f30de92658cb06ef31c95b7d359ba071be977277da983b2452c0f67d5546","properties":{"rationale":"Defining role competence requirements enables the role-based training and development that closes gaps for staff in security-relevant roles.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-06-36a1f4aa.json","sourceId":"uc:UC-HR-06","targetDetailPath":"/data/v1/records/risk-aware-role-based-training-gap-3e2ca2c3.json","targetId":"risk:aware-role-based-training-gap","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cd248f4889b85a1dedac6efe2d92c36e42eb80296249d48a5a0b7b12f03966a6","properties":{"control_id":"GV.RR-04","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-06-36a1f4aa.json","sourceId":"uc:UC-HR-06","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rr-04-defc7f20.json","targetId":"ctrl:nist-csf-2:GV.RR-04","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d5f7dda6e5271d0b3bc7a0474df05ff2a095f29cb8cf032d0e4f06082925351e","properties":{},"sourceDetailPath":"/data/v1/records/wf-c19-ef930979.json","sourceId":"wf:C19","targetDetailPath":"/data/v1/records/uc-uc-hr-06-36a1f4aa.json","targetId":"uc:UC-HR-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f6a35f2f1dda8db4df2aa72b6bb4628a40949788201a00b3575d3b7669b7287c","properties":{},"sourceDetailPath":"/data/v1/records/wf-d31-af2d985a.json","sourceId":"wf:D31","targetDetailPath":"/data/v1/records/uc-uc-hr-06-36a1f4aa.json","targetId":"uc:UC-HR-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fc722ea274f3cc0d81a8a299f7e39497596df0bfc462a5ff1ab14c7eca25c467","properties":{"control_id":"CC1.4","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-06-36a1f4aa.json","sourceId":"uc:UC-HR-06","targetDetailPath":"/data/v1/records/ctrl-soc2-cc1-4-6e16c0ae.json","targetId":"ctrl:soc2:CC1.4","type":"maps_to"}],"schemaVersion":1}
