{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Risk Assessment & Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-04","description":"The organization specifies business objectives with sufficient clarity to enable the identification and assessment of risks relating to those objectives. Mission-essential and business processes are defined, including their information protection needs, and serve as the basis for risk assessment scoping. Objective and process definitions are documented, approved, and revisited when strategy or operations change.","details":{"control_category":"administrative","control_type":"preventive","domain":"Risk Assessment & Management","guidance":[],"members":[{"control_id":"PM-11","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"P6","coverage":"full","framework":"coso-ic","relationship":"superset_of"},{"control_id":"CC3.1","coverage":"full","framework":"soc2","relationship":"superset_of"}],"statement":"The organization specifies business objectives with sufficient clarity to enable the identification and assessment of risks relating to those objectives. Mission-essential and business processes are defined, including their information protection needs, and serve as the basis for risk assessment scoping. Objective and process definitions are documented, approved, and revisited when strategy or operations change.","title":"Define objectives and business context for risk assessment","unified_id":"UC-RISK-04"},"id":"uc:UC-RISK-04","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-04","sourceIds":["coso-ic","nist-800-53","soc2"],"sourceUrl":null,"title":"UC-RISK-04 — Define objectives and business context for risk assessment","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1b00615d228a5949ac91edbdcc5d6584c5485bfec99c7eacb0c7bf40e2b0a86e","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-risk-04-1a2bee69.json","targetId":"uc:UC-RISK-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:35acc0742fe766708ad03b93b836214d4e90afe798caf06b44994877b7dfca12","properties":{"control_id":"CC3.1","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-04-1a2bee69.json","sourceId":"uc:UC-RISK-04","targetDetailPath":"/data/v1/records/ctrl-soc2-cc3-1-4fb807c4.json","targetId":"ctrl:soc2:CC3.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:533daa71036c6a02ac7b274032a71c0d473cdba4d39ae07b1f1f5550835d269a","properties":{},"sourceDetailPath":"/data/v1/records/wf-g3-4c4dc6e1.json","sourceId":"wf:G3","targetDetailPath":"/data/v1/records/uc-uc-risk-04-1a2bee69.json","targetId":"uc:UC-RISK-04","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6a4dec3fa75f031e94ea4b954dec1116f59f8252010094997edbe766bb2b5799","properties":{"rationale":"COSO P6 member requires objectives specified with clarity and consistency, reducing the poorly-defined/inconsistent-objective driver of strategic misalignment (partial contributor).","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-04-1a2bee69.json","sourceId":"uc:UC-RISK-04","targetDetailPath":"/data/v1/records/risk-strategic-misalignment-execution-d9c0675b.json","targetId":"risk:strategic-misalignment-execution","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6b5fcb76037cd3fb957fc7279bdd5d8a418ca73fd6742ce018ca6cad681fb31a","properties":{},"sourceDetailPath":"/data/v1/records/wf-d53-e1a69743.json","sourceId":"wf:D53","targetDetailPath":"/data/v1/records/uc-uc-risk-04-1a2bee69.json","targetId":"uc:UC-RISK-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7b89b54e2c6b690c3af89f43ccd3f3485a8f811ea46e513bccf6498afa695154","properties":{},"sourceDetailPath":"/data/v1/records/wf-g20-9d0df1c7.json","sourceId":"wf:G20","targetDetailPath":"/data/v1/records/uc-uc-risk-04-1a2bee69.json","targetId":"uc:UC-RISK-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a8d701934e20627e2031ea822b66a45953371b274acf28a0fb1b8c03ef3d4e61","properties":{"rationale":"Specifying objectives and business context clearly is the foundation that makes risk identification and assessment possible; absent it the process is inadequate.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-04-1a2bee69.json","sourceId":"uc:UC-RISK-04","targetDetailPath":"/data/v1/records/risk-risk-assessment-inadequate-328128b5.json","targetId":"risk:risk-assessment-inadequate","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b233b5a5f41b5a57dfec85baad4c3840fec6829d2b957e5b49a34afa95c74cc0","properties":{},"sourceDetailPath":"/data/v1/records/wf-c6-8bc75783.json","sourceId":"wf:C6","targetDetailPath":"/data/v1/records/uc-uc-risk-04-1a2bee69.json","targetId":"uc:UC-RISK-04","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:df828e368b0a23a5acecc6ce5395ac5ad255b9d77edea108c86286b234be8586","properties":{"control_id":"P6","coverage":"full","delta":null,"framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-04-1a2bee69.json","sourceId":"uc:UC-RISK-04","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p6-e614a304.json","targetId":"ctrl:coso-ic:P6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f25e89c48b758b8bdf385894193805daf7f37d9f8929f9583970db58b02351ce","properties":{"control_id":"PM-11","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-04-1a2bee69.json","sourceId":"uc:UC-RISK-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-11-6ecc2587.json","targetId":"ctrl:nist-800-53:PM-11","type":"maps_to"}],"schemaVersion":1}
