{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Incident Management & Response","type":"corrective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-IR-08","description":"Maintain a notification matrix of internal stakeholders, regulators, and other external parties with triggers, deadlines, content requirements, and approved communication owners. Require personnel to report suspected incidents to the response capability within defined timeframes, notify authorities and other required external bodies within their statutory windows, and share incident information with designated internal and external stakeholders as the communications plan directs. Notify affected individuals when thresholds are met — for high-risk personal-data breaches, communicate without undue delay in clear and plain language with mitigation advice; for regulated categories of data, notify individuals, media, and regulators within the mandated statutory windows when applicable thresholds are reached, honoring notification duties owed to partner organizations. Retain evidence of every notification's timing, audience, and content.","details":{"control_category":"administrative","control_type":"corrective","domain":"Incident Management & Response","guidance":[],"members":[{"control_id":"IR-6","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"RS.CO-02","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"RS.CO-03","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GDPR-Art34","coverage":"full","framework":"gdpr","relationship":"superset_of"},{"control_id":"HIPAA-164.400-414","coverage":"partial","delta":"individual notice within 60 days; media notice at 500+ residents of a state/jurisdiction; HHS notice at 500+ individuals (contemporaneous); HHS notification required for all breaches (sub-500 via annual log)","framework":"hipaa","relationship":"intersects_with"}],"statement":"Maintain a notification matrix of internal stakeholders, regulators, and other external parties with triggers, deadlines, content requirements, and approved communication owners. Require personnel to report suspected incidents to the response capability within defined timeframes, notify authorities and other required external bodies within their statutory windows, and share incident information with designated internal and external stakeholders as the communications plan directs. Notify affected individuals when thresholds are met — for high-risk personal-data breaches, communicate without undue delay in clear and plain language with mitigation advice; for regulated categories of data, notify individuals, media, and regulators within the mandated statutory windows when applicable thresholds are reached, honoring notification duties owed to partner organizations. Retain evidence of every notification's timing, audience, and content.","title":"Notify authorities and affected parties within deadlines","unified_id":"UC-IR-08"},"id":"uc:UC-IR-08","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-IR-08","sourceIds":["gdpr","hipaa","nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"UC-IR-08 — Notify authorities and affected parties within deadlines","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:02516314da9b65ef577d6a4188e2a6dd74a75257171474c354faa4fdfd795034","properties":{"control_id":"RS.CO-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-08-01afe3d1.json","sourceId":"uc:UC-IR-08","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-rs-co-02-bd695eeb.json","targetId":"ctrl:nist-csf-2:RS.CO-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:16c299d41edf19be14879b87685497d898252c077ecae6454388362bb74bb506","properties":{"control_id":"GDPR-Art34","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-08-01afe3d1.json","sourceId":"uc:UC-IR-08","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art34-6e2bfc74.json","targetId":"ctrl:gdpr:GDPR-Art34","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3ec7830226564cce898cf4cbabf8594d2f81ae8cebd37edcebb14811db6b60c9","properties":{},"sourceDetailPath":"/data/v1/records/wf-r16-5b93e206.json","sourceId":"wf:R16","targetDetailPath":"/data/v1/records/uc-uc-ir-08-01afe3d1.json","targetId":"uc:UC-IR-08","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:463c2c0034411e95da828e0cd200cc1c3bf15c1d2d2c8b4d54c69b3c52e59697","properties":{"rationale":"The notification matrix, statutory-window notifications to regulators/individuals, and retained evidence directly defend against late or incomplete breach notification (GDPR/HIPAA).","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-08-01afe3d1.json","sourceId":"uc:UC-IR-08","targetDetailPath":"/data/v1/records/risk-ir-breach-notification-failure-1f01c218.json","targetId":"risk:ir-breach-notification-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6a9b7c9d3dcbbef7202ad8b275e114331935d082046a65fdd1ac267ba6689e58","properties":{"control_id":"IR-6","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-08-01afe3d1.json","sourceId":"uc:UC-IR-08","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ir-6-73f4e13c.json","targetId":"ctrl:nist-800-53:IR-6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:88f4acbbafe9cadad6d161c0243b9cb59680cb265ad1485b366b06bec45fb7c8","properties":{},"sourceDetailPath":"/data/v1/records/wf-g7-9762f11b.json","sourceId":"wf:G7","targetDetailPath":"/data/v1/records/uc-uc-ir-08-01afe3d1.json","targetId":"uc:UC-IR-08","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cf20f209cd1c7d4ef9387c1eeb0c255613c65e9023166ff5fc7b6a53a6a5f8ef","properties":{"control_id":"HIPAA-164.400-414","coverage":"partial","delta":"individual notice within 60 days; media notice at 500+ residents of a state/jurisdiction; HHS notice at 500+ individuals (contemporaneous); HHS notification required for all breaches (sub-500 via annual log)","framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-08-01afe3d1.json","sourceId":"uc:UC-IR-08","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-400-414-aeadadc4.json","targetId":"ctrl:hipaa:HIPAA-164.400-414","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb1667b49922aa0007f8ad4fe6549f321c4e110c53a172b10f3ce16a0582bf63","properties":{"control_id":"RS.CO-03","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-08-01afe3d1.json","sourceId":"uc:UC-IR-08","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-rs-co-03-fd0a4591.json","targetId":"ctrl:nist-csf-2:RS.CO-03","type":"maps_to"}],"schemaVersion":1}
