{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Incident Management & Response","type":"corrective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-IR-11","description":"Maintain and execute a documented procedure for responding to information spillage — sensitive or regulated information landing on systems not authorized to hold it. On discovery, identify the information and the extent of contamination, alert designated personnel without amplifying exposure, isolate and eradicate the spilled information from affected systems and backups, and assess any obligations triggered by the exposure. Provide procedures and training for personnel exposed to spilled information and document each spill response.","details":{"control_category":"administrative","control_type":"corrective","domain":"Incident Management & Response","guidance":[],"members":[{"control_id":"IR-9","coverage":"full","framework":"nist-800-53","relationship":"equal"}],"statement":"Maintain and execute a documented procedure for responding to information spillage — sensitive or regulated information landing on systems not authorized to hold it. On discovery, identify the information and the extent of contamination, alert designated personnel without amplifying exposure, isolate and eradicate the spilled information from affected systems and backups, and assess any obligations triggered by the exposure. Provide procedures and training for personnel exposed to spilled information and document each spill response.","title":"Respond to information spillage with defined procedures","unified_id":"UC-IR-11"},"id":"uc:UC-IR-11","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-IR-11","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-IR-11 — Respond to information spillage with defined procedures","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:166935d9719564a73ed2200b1235851ee4b4d463b17697887db60d45efdee995","properties":{},"sourceDetailPath":"/data/v1/records/wf-c23-d6d82467.json","sourceId":"wf:C23","targetDetailPath":"/data/v1/records/uc-uc-ir-11-6234912d.json","targetId":"uc:UC-IR-11","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3ded1a136cdc46e87df75c78707b65cc33687b57ef2c8537c1abd73c71064323","properties":{"control_id":"IR-9","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-11-6234912d.json","sourceId":"uc:UC-IR-11","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ir-9-27a1dce0.json","targetId":"ctrl:nist-800-53:IR-9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5835f536ceae6e7d465086aea1d7e72874b25d0ef88b17f8b482cde65d17e64b","properties":{"rationale":"Assessing obligations triggered by the spill determines regulatory notification duties for the exposed regulated data.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-11-6234912d.json","sourceId":"uc:UC-IR-11","targetDetailPath":"/data/v1/records/risk-ir-breach-notification-failure-1f01c218.json","targetId":"risk:ir-breach-notification-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e2620ed554135eba78e6935c257e090b67fcf286ca9580116cf4132dbea67372","properties":{"rationale":"Isolating and eradicating spilled sensitive/regulated information from systems and backups directly reduces the extent of unauthorized disclosure (spillage named in the risk).","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-11-6234912d.json","sourceId":"uc:UC-IR-11","targetDetailPath":"/data/v1/records/risk-data-breach-unauthorized-disclosure-3b1c296c.json","targetId":"risk:data-breach-unauthorized-disclosure","type":"mitigates"}],"schemaVersion":1}
