{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Logging, Monitoring & Detection","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-LOG-09","description":"Define monitoring requirements for external service providers and monitor their activities, service status, and security-relevant events against contractual obligations, reviewing provider-supplied logs and reports on a defined cadence. Where audit trails cross organizational boundaries, agree methods for coordinating, exchanging, and protecting audit information with the external parties and preserve the identity context needed to trace cross-organizational actions.","details":{"control_category":"administrative","control_type":"detective","domain":"Logging, Monitoring & Detection","guidance":[],"members":[{"control_id":"DE.CM-06","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"AU-16","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"E009","coverage":"partial","delta":"monitoring of third-party API connections, integrations, and sessions into AI systems, including revocation of stale access","framework":"aiuc-1","relationship":"intersects_with"}],"statement":"Define monitoring requirements for external service providers and monitor their activities, service status, and security-relevant events against contractual obligations, reviewing provider-supplied logs and reports on a defined cadence. Where audit trails cross organizational boundaries, agree methods for coordinating, exchanging, and protecting audit information with the external parties and preserve the identity context needed to trace cross-organizational actions.","title":"Monitor providers and exchange audit data across organizations","unified_id":"UC-LOG-09"},"id":"uc:UC-LOG-09","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-LOG-09","sourceIds":["aiuc-1","nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"UC-LOG-09 — Monitor providers and exchange audit data across organizations","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:06787cf328f510260906f3f6e8195ad05fb90c275aed6cc084f6f1603955f478","properties":{"rationale":"Reviewing provider logs and monitoring their activity detects data theft routed through third-party channels.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-09-54136146.json","sourceId":"uc:UC-LOG-09","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3c2c2d06f4f2cac0c9f4d36baee8ef688aedb5a600f946e929e640d4a494520a","properties":{"rationale":"Monitoring provider security-relevant events detects the malicious or compromised supplier threat vector.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-09-54136146.json","sourceId":"uc:UC-LOG-09","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:427213dbb05eb996893397ffe80d1d32fdfa3a2bf8f1b2fee3e7ccbf99ea72c0","properties":{},"sourceDetailPath":"/data/v1/records/wf-r6-824a647c.json","sourceId":"wf:R6","targetDetailPath":"/data/v1/records/uc-uc-log-09-54136146.json","targetId":"uc:UC-LOG-09","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:644eafb401e2554492733991f471d02011d4c2262d35d799b1905537c8da0701","properties":{"control_id":"DE.CM-06","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-log-09-54136146.json","sourceId":"uc:UC-LOG-09","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-cm-06-241a1dc5.json","targetId":"ctrl:nist-csf-2:DE.CM-06","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:88d8d6b1e1e7916cef18ac8d1fb8819223cc6bf64ef4ca18ca9d8608c50b56a4","properties":{},"sourceDetailPath":"/data/v1/records/wf-g13-0f34ff59.json","sourceId":"wf:G13","targetDetailPath":"/data/v1/records/uc-uc-log-09-54136146.json","targetId":"uc:UC-LOG-09","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8cb35f18640a015a191d5a530c3d991e1a734707dd04dc4af8d8b6df5bf3ff7b","properties":{},"sourceDetailPath":"/data/v1/records/wf-c55-3a35dd8b.json","sourceId":"wf:C55","targetDetailPath":"/data/v1/records/uc-uc-log-09-54136146.json","targetId":"uc:UC-LOG-09","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:97cd5cbbbc55b1553e712071e30149a44148e4e1ac171f8195b56904e01bae81","properties":{"rationale":"Monitoring provider activity against contractual obligations detects the supply-chain vector campaigns exploit to enter.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-09-54136146.json","sourceId":"uc:UC-LOG-09","targetDetailPath":"/data/v1/records/risk-cyber-coordinated-campaign-b5879769.json","targetId":"risk:cyber-coordinated-campaign","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d6b82cd46208c4bfbdb7713cb4a63e7022b0a7d6c89b3e104e2c50a36ce0ae5f","properties":{"control_id":"AU-16","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-log-09-54136146.json","sourceId":"uc:UC-LOG-09","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-au-16-9594725f.json","targetId":"ctrl:nist-800-53:AU-16","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f88f1f5f58d8e1ec14714587c7e139ff273175c626d9948d5a60b0dd530f56fe","properties":{"control_id":"E009","coverage":"partial","delta":"monitoring of third-party API connections, integrations, and sessions into AI systems, including revocation of stale access","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-log-09-54136146.json","sourceId":"uc:UC-LOG-09","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-e009-5269a385.json","targetId":"ctrl:aiuc-1:E009","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fb2ac6c31a059c3019577e8cefe32d3c5da85a674664ffd768cb879005a1cdf0","properties":{"rationale":"Exchanging audit data across boundaries and preserving identity context to trace cross-organizational actions remedies audit-trail gaps at provider handoffs.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-09-54136146.json","sourceId":"uc:UC-LOG-09","targetDetailPath":"/data/v1/records/risk-log-missing-audit-trail-37d1ba80.json","targetId":"risk:log-missing-audit-trail","type":"mitigates"}],"schemaVersion":1}
