{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Logging, Monitoring & Detection","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-LOG-06","description":"Define written criteria for declaring a security incident, including thresholds that identify a reportable personal-data breach. Evaluate analyzed events against those criteria, declare incidents and initiate the response process when criteria are met, and record the assessment and rationale for every evaluated event. For reportable personal-data breaches, notify the competent regulator within the mandated statutory window with the prescribed content, and document all breaches, their effects, and remediation regardless of whether notification was required.","details":{"control_category":"administrative","control_type":"detective","domain":"Logging, Monitoring & Detection","guidance":[],"members":[{"control_id":"DE.AE-08","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"CC7.3","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"GDPR-Art33","coverage":"full","framework":"gdpr","relationship":"superset_of"}],"statement":"Define written criteria for declaring a security incident, including thresholds that identify a reportable personal-data breach. Evaluate analyzed events against those criteria, declare incidents and initiate the response process when criteria are met, and record the assessment and rationale for every evaluated event. For reportable personal-data breaches, notify the competent regulator within the mandated statutory window with the prescribed content, and document all breaches, their effects, and remediation regardless of whether notification was required.","title":"Evaluate events and declare incidents against defined criteria","unified_id":"UC-LOG-06"},"id":"uc:UC-LOG-06","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-LOG-06","sourceIds":["gdpr","nist-csf-2","soc2"],"sourceUrl":null,"title":"UC-LOG-06 — Evaluate events and declare incidents against defined criteria","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:100540596138cdf338bbb60b9e8ac90ea72bcf84924273e18908a7571db29247","properties":{"control_id":"DE.AE-08","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","sourceId":"uc:UC-LOG-06","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-08-67efb705.json","targetId":"ctrl:nist-csf-2:DE.AE-08","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2197453a5f72d08e056274c107712e69d0bc55d818d6145e05c90a85813b2be6","properties":{"rationale":"Declaring incidents when criteria are met triggers the response that contains and limits attack impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","sourceId":"uc:UC-LOG-06","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3169f2abc7f4fe1d152757d80f0cb5ad870bd962db2898bc84fe7d135ea5f6f1","properties":{"control_id":"GDPR-Art33","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","sourceId":"uc:UC-LOG-06","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art33-a2a440c2.json","targetId":"ctrl:gdpr:GDPR-Art33","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:60030743a8cc801e5e01ec5b6a9070ed8fa2e653c9ea466db24e10e4c8ef9cea","properties":{},"sourceDetailPath":"/data/v1/records/wf-r16-5b93e206.json","sourceId":"wf:R16","targetDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","targetId":"uc:UC-LOG-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:60dbb5404f8d594610367bd670338d7a466c294fff4d450727ec01af5c42631b","properties":{},"sourceDetailPath":"/data/v1/records/wf-c3-4a88b225.json","sourceId":"wf:C3","targetDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","targetId":"uc:UC-LOG-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c4aede063404f15c4aee018871d0a4b458aee737dcef9711460cb006ed3e43b9","properties":{"control_id":"CC7.3","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","sourceId":"uc:UC-LOG-06","targetDetailPath":"/data/v1/records/ctrl-soc2-cc7-3-00826815.json","targetId":"ctrl:soc2:CC7.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c505b091a0468b98eac64eaa53c34c1432ee60f0efa3222ea30c1d8eeab400a0","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","targetId":"uc:UC-LOG-06","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fb070e6fb79e092e4f8cab56f17580c95828b1f586a1d506487d9fef186e8a0d","properties":{"rationale":"Defined criteria to evaluate events, declare incidents, and initiate response supply the escalation process for detected breaches that was absent.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","sourceId":"uc:UC-LOG-06","targetDetailPath":"/data/v1/records/risk-log-no-monitoring-supervision-712fe573.json","targetId":"risk:log-no-monitoring-supervision","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ffd8d149aaba0da444f2773512dc412cf75c85607cb3711369ba7d2a9447c03e","properties":{"rationale":"Declaring data-breach incidents against defined thresholds and notifying regulators/individuals reduces the impact of data theft.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","sourceId":"uc:UC-LOG-06","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"}],"schemaVersion":1}
