{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Risk Assessment & Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-18","description":"Systems and the information they process, store, and transmit are categorized based on the potential impact of a loss of confidentiality, integrity, and availability, with categorization decisions documented and approved by accountable officials. Criticality analysis identifies critical system components, functions, and dependencies so protection and resilience investments are prioritized accordingly.","details":{"control_category":"administrative","control_type":"preventive","domain":"Risk Assessment & Management","guidance":[],"members":[{"control_id":"RA-2","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"RA-9","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Systems and the information they process, store, and transmit are categorized based on the potential impact of a loss of confidentiality, integrity, and availability, with categorization decisions documented and approved by accountable officials. Criticality analysis identifies critical system components, functions, and dependencies so protection and resilience investments are prioritized accordingly.","title":"Categorize systems and components by impact and criticality","unified_id":"UC-RISK-18"},"id":"uc:UC-RISK-18","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-RISK-18","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-RISK-18 — Categorize systems and components by impact and criticality","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0a958c8a97eef0e5f150162eb961441d1838052d57bfc5d112daa20cd159632a","properties":{"control_id":"RA-9","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-18-23752e70.json","sourceId":"uc:UC-RISK-18","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ra-9-a6abec7e.json","targetId":"ctrl:nist-800-53:RA-9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:56b287868d8de8b35f4d342ac4ffa8734ee89f732abced69770e766a0f24580a","properties":{"rationale":"Impact/criticality categorization prioritizes protective and resilience investment on high-value systems: necessary context, not the operative defense (inventory-type enabler).","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-18-23752e70.json","sourceId":"uc:UC-RISK-18","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:64ecb25913c9fd315ec017e8b5a042f5449f98d0c168671c93970dee902680a4","properties":{},"sourceDetailPath":"/data/v1/records/wf-c24-000b9f1d.json","sourceId":"wf:C24","targetDetailPath":"/data/v1/records/uc-uc-risk-18-23752e70.json","targetId":"uc:UC-RISK-18","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a30ad0cdb3dedb3b840902adeca08545a943af94e52e50b1694369d4b0f8d1e1","properties":{"control_id":"RA-2","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-18-23752e70.json","sourceId":"uc:UC-RISK-18","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ra-2-915f85ce.json","targetId":"ctrl:nist-800-53:RA-2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ab32e2107522b3034bdf9db923f37f6e55d8bc6453012ec5d5f642b6d9561cf2","properties":{},"sourceDetailPath":"/data/v1/records/wf-d55-248b03a5.json","sourceId":"wf:D55","targetDetailPath":"/data/v1/records/uc-uc-risk-18-23752e70.json","targetId":"uc:UC-RISK-18","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bba5dfd331464cefd508fcab32ed91229b9f2359f9b19c720153bafe6cc76af6","properties":{"rationale":"Criticality analysis identifies critical components, functions and dependencies, informing which processes continuity/recovery planning must prioritize.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-18-23752e70.json","sourceId":"uc:UC-RISK-18","targetDetailPath":"/data/v1/records/risk-bcdr-no-tested-continuity-plan-d4d9e7a9.json","targetId":"risk:bcdr-no-tested-continuity-plan","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:caaafc8ae2efca7395f7a592060cdb4c5314ba5fc9dcbc1d32bd7f17d44b39e3","properties":{},"sourceDetailPath":"/data/v1/records/wf-c8-5634a289.json","sourceId":"wf:C8","targetDetailPath":"/data/v1/records/uc-uc-risk-18-23752e70.json","targetId":"uc:UC-RISK-18","type":"oversees"}],"schemaVersion":1}
