{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Risk Assessment & Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-02","description":"Risk management is integrated into organizational structures, decision-making, and business activities rather than operated as a standalone silo. Cybersecurity and information security risk activities are incorporated into enterprise risk management processes, and information security risk is addressed within project management for all projects from initiation through delivery. ERM artifacts referencing cyber risk and project gate documentation with security risk sections evidence operation.","details":{"control_category":"administrative","control_type":"preventive","domain":"Risk Assessment & Management","guidance":[],"members":[{"control_id":"31000-P1","coverage":"full","framework":"iso-31000","relationship":"superset_of"},{"control_id":"31000-FW2","coverage":"full","framework":"iso-31000","relationship":"superset_of"},{"control_id":"GV.RM-03","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"A.5.8","coverage":"full","framework":"iso-27001","relationship":"superset_of"}],"statement":"Risk management is integrated into organizational structures, decision-making, and business activities rather than operated as a standalone silo. Cybersecurity and information security risk activities are incorporated into enterprise risk management processes, and information security risk is addressed within project management for all projects from initiation through delivery. ERM artifacts referencing cyber risk and project gate documentation with security risk sections evidence operation.","title":"Integrate risk management into enterprise processes and projects","unified_id":"UC-RISK-02"},"id":"uc:UC-RISK-02","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-02","sourceIds":["iso-27001","iso-31000","nist-csf-2"],"sourceUrl":null,"title":"UC-RISK-02 — Integrate risk management into enterprise processes and projects","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0da3bc474260b75a3f2a77a1c5c58d36b4bb88caca3bdc88209c7154ad73499d","properties":{"control_id":"31000-P1","coverage":"full","delta":null,"framework":"iso-31000","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2018"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-02-0f8519bb.json","sourceId":"uc:UC-RISK-02","targetDetailPath":"/data/v1/records/ctrl-iso-31000-31000-p1-ee160f4d.json","targetId":"ctrl:iso-31000:31000-P1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:28645f2a325f79d63c399b18c3c84e6724856ee2eb2dbd3307cbd7cf87505038","properties":{"control_id":"31000-FW2","coverage":"full","delta":null,"framework":"iso-31000","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2018"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-02-0f8519bb.json","sourceId":"uc:UC-RISK-02","targetDetailPath":"/data/v1/records/ctrl-iso-31000-31000-fw2-002ea142.json","targetId":"ctrl:iso-31000:31000-FW2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:52fddd6bb4310a990e0736070615bf075c1bea5afacc03c4d9e545908a07e89a","properties":{"rationale":"GV.RM-03 member folds cyber risk into ERM, giving threats enterprise governance and resourcing, an enabler rather than the operative defense against attackers.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-02-0f8519bb.json","sourceId":"uc:UC-RISK-02","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:90643faef3c896206b0ca47a8b46aa57f71afeca85508290607ad39a6560e102","properties":{"control_id":"GV.RM-03","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-02-0f8519bb.json","sourceId":"uc:UC-RISK-02","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-03-4891faf8.json","targetId":"ctrl:nist-csf-2:GV.RM-03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:91dfeb71ae7b5413acc15e129d12942c098bed40469dccdac37064ef4150acec","properties":{},"sourceDetailPath":"/data/v1/records/wf-g5-873e0b12.json","sourceId":"wf:G5","targetDetailPath":"/data/v1/records/uc-uc-risk-02-0f8519bb.json","targetId":"uc:UC-RISK-02","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:96c0b877a6f77c769fe02d2fd36d3fd61537aab48fd6b10983d7c6be89f6a09d","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-02-0f8519bb.json","sourceId":"uc:UC-RISK-02","targetDetailPath":"/data/v1/records/risk-financial-credit-market-risk-b9cbc5a3.json","targetId":"risk:financial-credit-market-risk","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a09570a6185e464a33d447ed7e365813f9ec4e119b3b996bb917758789fe6d6c","properties":{"control_id":"A.5.8","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-02-0f8519bb.json","sourceId":"uc:UC-RISK-02","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-8-bf8c2add.json","targetId":"ctrl:iso-27001:A.5.8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a20e813c4558411644b1958078da25ef79cb8c9959abae7d8baca26e28f6bd07","properties":{},"sourceDetailPath":"/data/v1/records/wf-g19-77005a54.json","sourceId":"wf:G19","targetDetailPath":"/data/v1/records/uc-uc-risk-02-0f8519bb.json","targetId":"uc:UC-RISK-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b9ee85d756575a42f52b717386da075f3819594150c1259ce288f7cd4c991789","properties":{"rationale":"A.5.8 member requires infosec risk addressed in project management from initiation to delivery, contributing to project governance and fewer delivery surprises.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-02-0f8519bb.json","sourceId":"uc:UC-RISK-02","targetDetailPath":"/data/v1/records/risk-gov-project-change-management-335e75ed.json","targetId":"risk:gov-project-change-management","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e13f3c8824b442934f0e24e253c0265811625e9c69ab60a5cc8dffc57e614a04","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-risk-02-0f8519bb.json","targetId":"uc:UC-RISK-02","type":"tests"}],"schemaVersion":1}
