{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Secure Development (SDLC) & Application Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-SDLC-12","description":"Manage application and infrastructure assets through their life cycle: maintain an accurate record of solution assets, ownership, and licensing, and optimize their use and cost. Identify system components approaching end of support and replace or upgrade them, or apply documented compensating controls with explicit risk acceptance, before support lapses.","details":{"control_category":"administrative","control_type":"preventive","domain":"Secure Development (SDLC) & Application Security","guidance":[],"members":[{"control_id":"SA-22","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"BAI09","coverage":"full","framework":"cobit-2019","relationship":"superset_of"}],"statement":"Manage application and infrastructure assets through their life cycle: maintain an accurate record of solution assets, ownership, and licensing, and optimize their use and cost. Identify system components approaching end of support and replace or upgrade them, or apply documented compensating controls with explicit risk acceptance, before support lapses.","title":"Manage solution assets and retire unsupported components","unified_id":"UC-SDLC-12"},"id":"uc:UC-SDLC-12","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-SDLC-12","sourceIds":["cobit-2019","nist-800-53"],"sourceUrl":null,"title":"UC-SDLC-12 — Manage solution assets and retire unsupported components","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1b07004b01c26b180943b890aecdc016338f3537705b062696c61c5cd1b9a040","properties":{},"sourceDetailPath":"/data/v1/records/wf-c64-5695dd2f.json","sourceId":"wf:C64","targetDetailPath":"/data/v1/records/uc-uc-sdlc-12-08ce2fc7.json","targetId":"uc:UC-SDLC-12","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:35eebd189f1575ee338fadccdde6be2f9eded242acad4ddcb3aa02c74807db27","properties":{"control_id":"BAI09","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-12-08ce2fc7.json","sourceId":"uc:UC-SDLC-12","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai09-09a008c3.json","targetId":"ctrl:cobit-2019:BAI09","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4410ab1f8381e575b2bd1b4621aca4346fcdd5a9dde590e56a3c41b7cd446ecd","properties":{"rationale":"Retiring or upgrading unsupported components removes accumulated known exploitable vulnerabilities.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-12-08ce2fc7.json","sourceId":"uc:UC-SDLC-12","targetDetailPath":"/data/v1/records/risk-sdlc-vulnerabilities-in-software-10c28b16.json","targetId":"risk:sdlc-vulnerabilities-in-software","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:82c2b6d38de4a2a6f287d61024a12d35b34826c48429a1733a87c3db68d89694","properties":{},"sourceDetailPath":"/data/v1/records/wf-g15-1231bc14.json","sourceId":"wf:G15","targetDetailPath":"/data/v1/records/uc-uc-sdlc-12-08ce2fc7.json","targetId":"uc:UC-SDLC-12","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8320b41b9717aa08cd44fd936c3cf4d80cf5fa036bf5e437041beefe4bb2cf67","properties":{"rationale":"An accurate asset/license inventory tracks third-party/AI dependencies and provider end-of-support exposure.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-12-08ce2fc7.json","sourceId":"uc:UC-SDLC-12","targetDetailPath":"/data/v1/records/risk-ai-supply-chain-concentration-9f791f54.json","targetId":"risk:ai-supply-chain-concentration","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ca63580a071d6e4de88a57921c5f95fbf8ee13ec9f3a36e73a4fe3c86a912e1b","properties":{"control_id":"SA-22","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-12-08ce2fc7.json","sourceId":"uc:UC-SDLC-12","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sa-22-5cba6bc8.json","targetId":"ctrl:nist-800-53:SA-22","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fecba36c6eed5046effa9686140b64226575b96a4fcb7c54de02f63de52b21c4","properties":{"rationale":"Identifying and replacing end-of-support components before support lapses prevents systems becoming unpatchable and fragile.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-12-08ce2fc7.json","sourceId":"uc:UC-SDLC-12","targetDetailPath":"/data/v1/records/risk-tech-maintainability-breach-f075a363.json","targetId":"risk:tech-maintainability-breach","type":"mitigates"}],"schemaVersion":1}
