{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Risk Assessment & Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-06","description":"The organization performs an enterprise-wide risk assessment at least annually and upon significant change, identifying and analyzing risks to the achievement of objectives, including cybersecurity, privacy, and financial reporting risks. Assessments follow the documented methodology, address the design of the control environment and evolving threats and technologies, and are approved by management. Assessment reports, methodology references, and approvals are retained as evidence.","details":{"control_category":"administrative","control_type":"preventive","domain":"Risk Assessment & Management","guidance":[],"members":[{"control_id":"RA-3","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"CC3.2","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"P7","coverage":"full","framework":"coso-ic","relationship":"superset_of"},{"control_id":"ELC-RA","coverage":"partial","delta":"objective-setting, fraud, and change aspects covered by dedicated unified controls","framework":"sox","relationship":"intersects_with"},{"control_id":"500.9","coverage":"full","framework":"nydfs-500","relationship":"superset_of"}],"statement":"The organization performs an enterprise-wide risk assessment at least annually and upon significant change, identifying and analyzing risks to the achievement of objectives, including cybersecurity, privacy, and financial reporting risks. Assessments follow the documented methodology, address the design of the control environment and evolving threats and technologies, and are approved by management. Assessment reports, methodology references, and approvals are retained as evidence.","title":"Perform periodic enterprise risk assessments","unified_id":"UC-RISK-06"},"id":"uc:UC-RISK-06","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-06","sourceIds":["coso-ic","nist-800-53","nydfs-500","soc2","sox"],"sourceUrl":null,"title":"UC-RISK-06 — Perform periodic enterprise risk assessments","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:01ce8ae1ab49976e0742f5ce7d0bf3b50631a0265d24712d5fbea9da3da2f2eb","properties":{},"sourceDetailPath":"/data/v1/records/wf-g22-87bce2d6.json","sourceId":"wf:G22","targetDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","targetId":"uc:UC-RISK-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1b96f0765a2dfb4e5c76bdcb09eb295102be82d719a3b7bd233ebba82e04a84b","properties":{"control_id":"ELC-RA","coverage":"partial","delta":"objective-setting, fraud, and change aspects covered by dedicated unified controls","framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","sourceId":"uc:UC-RISK-06","targetDetailPath":"/data/v1/records/ctrl-sox-elc-ra-413d9faf.json","targetId":"ctrl:sox:ELC-RA","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2ded127132372d45cce1477acd35b28858bb09c6f9583e315f1e478c20e0fb26","properties":{"control_id":"500.9","coverage":"full","delta":null,"framework":"nydfs-500","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"23 NYCRR 500, Second Amendment"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","sourceId":"uc:UC-RISK-06","targetDetailPath":"/data/v1/records/ctrl-nydfs-500-500-9-b028c41d.json","targetId":"ctrl:nydfs-500:500.9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:46aa39a4ea46095a7cf37e080fc784c4480c2b0ec372694e0227c4b9c014074a","properties":{"control_id":"P7","coverage":"full","delta":null,"framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","sourceId":"uc:UC-RISK-06","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p7-a272f700.json","targetId":"ctrl:coso-ic:P7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:585b39e9665280e2a21bfb0b9e368412a75c1efaae0d3eb7e761d0bae681e8af","properties":{},"sourceDetailPath":"/data/v1/records/wf-s1-ee2f3289.json","sourceId":"wf:S1","targetDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","targetId":"uc:UC-RISK-06","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5ffb88ce652506ecf84fb88b264d0eb42d61ca1f72fd14d38745d836f4be9592","properties":{"rationale":"NYDFS 500.9 member and explicit cyber scope make the assessment periodically surface evolving cyber threats for treatment, enabling context not the operative defense.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","sourceId":"uc:UC-RISK-06","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:98cda5d4b4abe99247293c18cc7e46d5a58f7b03184c6b1020210b1a870e9a2b","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","targetId":"uc:UC-RISK-06","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ae895c1c28a8cbb446dfc38f4aa5539ef46ec9665cc27a4740ebcd935409425b","properties":{},"sourceDetailPath":"/data/v1/records/wf-g3-4c4dc6e1.json","sourceId":"wf:G3","targetDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","targetId":"uc:UC-RISK-06","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b1e0fadedb57c20d3ea67fbd9e84dca3abeffb503857bdef4a04f5cc656382c4","properties":{"control_id":"CC3.2","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","sourceId":"uc:UC-RISK-06","targetDetailPath":"/data/v1/records/ctrl-soc2-cc3-2-18f9e8ee.json","targetId":"ctrl:soc2:CC3.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b762f997b3bc0017c1a025bf61e5f61e921d86e77f588f176f280dc4530d151f","properties":{"rationale":"Performing periodic enterprise-wide risk assessments per a documented methodology directly operates the assessment process the risk describes as absent.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","sourceId":"uc:UC-RISK-06","targetDetailPath":"/data/v1/records/risk-risk-assessment-inadequate-328128b5.json","targetId":"risk:risk-assessment-inadequate","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bd98758e685f20b10abe90de0b6f384856fc8fce6766450f55a92357c6260407","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","sourceId":"uc:UC-RISK-06","targetDetailPath":"/data/v1/records/risk-financial-liquidity-capital-e0ac2d24.json","targetId":"risk:financial-liquidity-capital","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dbc6070be128a48d9f960cbeff16992d5c8966356cae343f5f7a3fae071a3b0e","properties":{},"sourceDetailPath":"/data/v1/records/wf-d05-2302db1f.json","sourceId":"wf:D05","targetDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","targetId":"uc:UC-RISK-06","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e40a509a5b6ecc81db036f54a1eecc59d883856c986331d8c0f88d05c5fdf158","properties":{"control_id":"RA-3","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","sourceId":"uc:UC-RISK-06","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ra-3-0cfd86d9.json","targetId":"ctrl:nist-800-53:RA-3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ed16bc97e01423c26331d1ecb77eca054fb85dcbffcb94a45240210d15311c11","properties":{},"sourceDetailPath":"/data/v1/records/wf-c6-8bc75783.json","sourceId":"wf:C6","targetDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","targetId":"uc:UC-RISK-06","type":"oversees"}],"schemaVersion":1}
