{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Third-Party / Supply-Chain Risk","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-01","description":"Establish and operate a management-approved third-party and supply-chain risk management program with a written strategy, policies, and procedures, reviewed at defined intervals and after significant changes to the supply chain or threat landscape. Define and communicate roles and responsibilities for supplier, customer, and partner relationships, and integrate third-party and supply-chain risk into enterprise and cybersecurity risk management. Maintain a register of third-party relationships and contractual arrangements prioritized by criticality, and assess criticality, substitutability, and concentration risk before contracting. Apply risk-based due diligence, embed security requirements, audit and access rights, termination rights, and sub-outsourcing conditions in agreements, and protect organizational information processed, stored, or transmitted on external systems. Define, agree, and periodically review service agreements and supplier performance, reassess third parties on a defined cycle, operate controls to identify and address weaknesses across the relationship life cycle, and maintain documented, tested exit strategies for providers supporting critical or important functions.","details":{"control_category":"administrative","control_type":"preventive","domain":"Third-Party / Supply-Chain Risk","guidance":[],"members":[{"control_id":"SR-2","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SR-3","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"GV.SC-01","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GV.SC-02","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GV.SC-03","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GV.SC-04","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"A.5.19","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"500.11","coverage":"partial","delta":"policies must address TPSP MFA/access, encryption, event-notice, and representations guidelines","framework":"nydfs-500","relationship":"intersects_with"},{"control_id":"PM-30","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SR-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PM-17","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"NIS2-Art21d","coverage":"partial","delta":"operational supplier security assessments and contractual safeguards per supplier","framework":"nis2","relationship":"intersects_with"},{"control_id":"APO09","coverage":"partial","delta":"service catalog definition and SLA lifecycle management","framework":"cobit-2019","relationship":"intersects_with"},{"control_id":"APO10","coverage":"partial","delta":"day-to-day vendor performance monitoring and contract administration","framework":"cobit-2019","relationship":"intersects_with"},{"control_id":"DORA-Art28-44","coverage":"partial","delta":"DORA-specific regulator obligations (register of information format, competent-authority/Lead Overseer interactions) beyond the general third-party program","framework":"dora","relationship":"intersects_with"}],"statement":"Establish and operate a management-approved third-party and supply-chain risk management program with a written strategy, policies, and procedures, reviewed at defined intervals and after significant changes to the supply chain or threat landscape. Define and communicate roles and responsibilities for supplier, customer, and partner relationships, and integrate third-party and supply-chain risk into enterprise and cybersecurity risk management. Maintain a register of third-party relationships and contractual arrangements prioritized by criticality, and assess criticality, substitutability, and concentration risk before contracting. Apply risk-based due diligence, embed security requirements, audit and access rights, termination rights, and sub-outsourcing conditions in agreements, and protect organizational information processed, stored, or transmitted on external systems. Define, agree, and periodically review service agreements and supplier performance, reassess third parties on a defined cycle, operate controls to identify and address weaknesses across the relationship life cycle, and maintain documented, tested exit strategies for providers supporting critical or important functions.","title":"Operate a third-party security risk management program","unified_id":"UC-TPRM-01"},"id":"uc:UC-TPRM-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-01","sourceIds":["cobit-2019","dora","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500"],"sourceUrl":null,"title":"UC-TPRM-01 — Operate a third-party security risk management program","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:03e990ef1d32ef898869078a3d5cc8e35e040894e29f8a665eee7e5c4cfd8bf8","properties":{"control_id":"GV.SC-03","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-03-92c70175.json","targetId":"ctrl:nist-csf-2:GV.SC-03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:06766bcaa97fc503e3075bacd5a32b70ca02cddb5723c7adb91b171d249be995","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","targetId":"uc:UC-TPRM-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:06ae859dddd555345768d16603e34a8b7d27ae8eb414b92a5b8727feeeb6b1e9","properties":{},"sourceDetailPath":"/data/v1/records/wf-g29-6f0c8a46.json","sourceId":"wf:G29","targetDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","targetId":"uc:UC-TPRM-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:26ab45627440071e57e3737038b50fa6aabc730e4396a7e303860dfcfcd4cd5d","properties":{"control_id":"GV.SC-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-01-a154a187.json","targetId":"ctrl:nist-csf-2:GV.SC-01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2d46706b6e745cd422a98d5f8bba591358b1bcda6a393dbc8b1b08029f1d05a0","properties":{"control_id":"PM-30","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-30-4ffda7b6.json","targetId":"ctrl:nist-800-53:PM-30","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:31568ab19606852875865ba961cec39ec0856b3bd2b22a3694bdbd7d5927c900","properties":{},"sourceDetailPath":"/data/v1/records/wf-r6-824a647c.json","sourceId":"wf:R6","targetDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","targetId":"uc:UC-TPRM-01","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:443f786d43ee6948e95374e37c50e83b401cf7827e8bdb8d7420e4abd2529647","properties":{"rationale":"Embedding security requirements and audit/access rights, reviewing service agreements and supplier performance, and reassessing on a cycle directly counters unmonitored, unbound suppliers.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4563542ddc82224ac1112c258485ce77febeec9fa9f0a8eaf3a33969254150ee","properties":{},"sourceDetailPath":"/data/v1/records/wf-a7-454c1d0e.json","sourceId":"wf:A7","targetDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","targetId":"uc:UC-TPRM-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:56dfe103e06ba3e03327b976baf2e7ccda67ac05f21e445799bcd6d251284b07","properties":{"rationale":"Assessing concentration and substitutability and maintaining exit strategies reduces the impact of a disrupted critical-input supplier.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-disruption-0d7e0959.json","targetId":"risk:tprm-supply-chain-disruption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:69a6c7f9bed48e02129fbab011819e3d8abc7f7cd2f0680cee3c0301c965118b","properties":{"rationale":"Assessing criticality, substitutability, and concentration before contracting and maintaining tested exit strategies for critical providers is the core defense against vendor failure and concentration.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-tprm-critical-vendor-failure-cb39c2bc.json","targetId":"risk:tprm-critical-vendor-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:72ba8a5abe71532bacbb0d85adcf0d79ccb88c653f130984008cbbcfc38f3075","properties":{"rationale":"Concentration/substitutability assessment and exit strategies reduce the impact of geopolitically-driven supplier and supply-chain disruption.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-strategic-geopolitical-4e7aba30.json","targetId":"risk:strategic-geopolitical","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7c88645873ad26067703dfff2fa5edbe8d16c2aa87ee258ea3d14f7db1426f7d","properties":{"control_id":"GV.SC-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-02-03d3af49.json","targetId":"ctrl:nist-csf-2:GV.SC-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:82c40a552cf2e27f24846e459e9b2a1e347e530e140706bfaaa950dca104839a","properties":{"control_id":"A.5.19","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-19-d8db0691.json","targetId":"ctrl:iso-27001:A.5.19","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:93f7691cf30adc29a795fbcc56324d18fd9cc47a9b2f968a6b493b02e24fb22a","properties":{"control_id":"SR-2","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sr-2-b9ccf77e.json","targetId":"ctrl:nist-800-53:SR-2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9db04fad46758b81ec779f5584e60874a16ab5fca9f18a03cf7cab7a292bda84","properties":{},"sourceDetailPath":"/data/v1/records/wf-g13-0f34ff59.json","sourceId":"wf:G13","targetDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","targetId":"uc:UC-TPRM-01","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9fcbba45083adb3c7c068d3856009702ed3be50e4a02d006813495f938215166","properties":{},"sourceDetailPath":"/data/v1/records/wf-c2-a1078981.json","sourceId":"wf:C2","targetDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","targetId":"uc:UC-TPRM-01","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a32ac4e3ba2b3786dad93a7f814ca064093b2170c57a47abe8f3256a3a763393","properties":{"control_id":"SR-3","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sr-3-0f4252c2.json","targetId":"ctrl:nist-800-53:SR-3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b0f240d0bb2e0ebdc690ff63fa6b509a1063b8fad26027a37b7d9e376b2fe859","properties":{"rationale":"Risk-based due diligence, a criticality-ranked register, sub-outsourcing conditions, and reassessment reduce the N-tier compliance-failure exposure driving vicarious liability.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-tprm-vendor-compliance-vicarious-liability-0215657c.json","targetId":"risk:tprm-vendor-compliance-vicarious-liability","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b48d208fc579b8bfaf3f263db5da6c421457ede838fd19c511096175349f2716","properties":{"control_id":"APO10","coverage":"partial","delta":"day-to-day vendor performance monitoring and contract administration","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-apo10-2c3cb0dc.json","targetId":"ctrl:cobit-2019:APO10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bb6c7ef9afdbf96a9b37de7ac9c8e2302589796b7675e414a5bb3d7e127a93c1","properties":{"control_id":"SR-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sr-1-b3b3302c.json","targetId":"ctrl:nist-800-53:SR-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c4d9a8ef5397b2733ba341189f1046dc4fd3c7ebc85625e7b2ba47829b0eab5e","properties":{"control_id":"500.11","coverage":"partial","delta":"policies must address TPSP MFA/access, encryption, event-notice, and representations guidelines","framework":"nydfs-500","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"23 NYCRR 500, Second Amendment"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-nydfs-500-500-11-55bec62e.json","targetId":"ctrl:nydfs-500:500.11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ccd0e376207f2decfe033433db539cafbba762a294aff5120dfa29a56d500050","properties":{"rationale":"Defining, agreeing, and reviewing service agreements and supplier performance and operating lifecycle controls to address weaknesses directly targets non-performance.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-tprm-vendor-service-nonperformance-081f2fb9.json","targetId":"risk:tprm-vendor-service-nonperformance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d1bc3d44abfcb1b212921d6c5e3323d0b33cf5166e5957cd9e0d160834fac695","properties":{"rationale":"A criticality-ranked third-party register plus concentration and exit-strategy assessment applies to AI API providers, reducing concentration and outage impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-ai-supply-chain-concentration-9f791f54.json","targetId":"risk:ai-supply-chain-concentration","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d7cc1f08f27b6315ce2ec5eed4c8b0a4dc59776e29cddc1c7873e1fdeecb6d99","properties":{"rationale":"Assessing concentration risk and maintaining exit strategies for critical providers reduces the ecosystem single-point-of-failure impact from GPAI-capability concentration.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-ai-gpai-systemic-transparency-7a746323.json","targetId":"risk:ai-gpai-systemic-transparency","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ec961b1b3f32baa0f536e2fd5d9aaf473b1850c9b5c789ecab5fe9839e56aa3f","properties":{"control_id":"PM-17","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-pm-17-7712d8a9.json","targetId":"ctrl:nist-800-53:PM-17","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f2e2e7b72bc628ac1dc26cf6544d63f62633d9a1276598c3474fe2e52c916f16","properties":{"control_id":"DORA-Art28-44","coverage":"partial","delta":"DORA-specific regulator obligations (register of information format, competent-authority/Lead Overseer interactions) beyond the general third-party program","framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art28-44-d3e89c89.json","targetId":"ctrl:dora:DORA-Art28-44","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f62c3dd850999cd7501d541d730ce1297ebba264414e99059d7c5fc526e7df89","properties":{"control_id":"NIS2-Art21d","coverage":"partial","delta":"operational supplier security assessments and contractual safeguards per supplier","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21d-9b82b64b.json","targetId":"ctrl:nis2:NIS2-Art21d","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fa1e03375b19113343f4dead8c7384d2ce6473a62a0177095daa5a8303d69ee2","properties":{"control_id":"APO09","coverage":"partial","delta":"service catalog definition and SLA lifecycle management","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-apo09-2d1f48e2.json","targetId":"ctrl:cobit-2019:APO09","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ff8184b47e04d3a4cfab0cc7760eabf38016f3ab9330e99b2f0e5151b4ce3aad","properties":{"control_id":"GV.SC-04","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-04-ccaf1868.json","targetId":"ctrl:nist-csf-2:GV.SC-04","type":"maps_to"}],"schemaVersion":1}
