{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Third-Party / Supply-Chain Risk","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-06","description":"Include termination and post-relationship provisions in supplier agreements and supply-chain risk plans: return or verified destruction of data, revocation of access and credentials, service transition, and retention of required evidence. Dispose of data, documentation, tools, and system components securely at end of life or end of relationship using defined techniques, and record each disposal.","details":{"control_category":"administrative","control_type":"preventive","domain":"Third-Party / Supply-Chain Risk","guidance":[],"members":[{"control_id":"SR-12","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"GV.SC-10","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"}],"statement":"Include termination and post-relationship provisions in supplier agreements and supply-chain risk plans: return or verified destruction of data, revocation of access and credentials, service transition, and retention of required evidence. Dispose of data, documentation, tools, and system components securely at end of life or end of relationship using defined techniques, and record each disposal.","title":"Manage secure termination and disposal at relationship end","unified_id":"UC-TPRM-06"},"id":"uc:UC-TPRM-06","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-06","sourceIds":["nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"UC-TPRM-06 — Manage secure termination and disposal at relationship end","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:669a6e122977861115741614acfeae0b9d974a61980b3e748fe8c1b606857875","properties":{},"sourceDetailPath":"/data/v1/records/wf-r6-824a647c.json","sourceId":"wf:R6","targetDetailPath":"/data/v1/records/uc-uc-tprm-06-0d2c1b90.json","targetId":"uc:UC-TPRM-06","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:747237129db0e2edaa088d008ed4d239673c6ebc02bd80561e44b14183a4b089","properties":{"rationale":"Access revocation and verified data return at termination reduce the residual-access breach vector but supply neither the security requirements nor the ongoing monitoring the risk describes, so the effect is contributory.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-06-0d2c1b90.json","sourceId":"uc:UC-TPRM-06","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:79842bd8499836e6e1949843ca3a9c95b77e3c5e9d1e1d57d2e7568ee0be529c","properties":{"control_id":"GV.SC-10","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-06-0d2c1b90.json","sourceId":"uc:UC-TPRM-06","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-10-1285c655.json","targetId":"ctrl:nist-csf-2:GV.SC-10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8e19fe83325fffd4d57205245a5ba46311539a1fb85eb8758096baf267795d72","properties":{"rationale":"Data return, access revocation, and service-transition provisions enable clean exit and recovery when a critical vendor fails or exits.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-06-0d2c1b90.json","sourceId":"uc:UC-TPRM-06","targetDetailPath":"/data/v1/records/risk-tprm-critical-vendor-failure-cb39c2bc.json","targetId":"risk:tprm-critical-vendor-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b44a502c267cbbb4c4c68f3055dbad162310171d8323efe20a9ad1f563749592","properties":{"rationale":"Service-transition provisions at termination reduce the switching impact when moving off a non-performing vendor.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-06-0d2c1b90.json","sourceId":"uc:UC-TPRM-06","targetDetailPath":"/data/v1/records/risk-tprm-vendor-service-nonperformance-081f2fb9.json","targetId":"risk:tprm-vendor-service-nonperformance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c7cbef82b4bf52382dc8f1201d85da3637b8d20c7df74fc4c2588266662b0068","properties":{"control_id":"SR-12","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-06-0d2c1b90.json","sourceId":"uc:UC-TPRM-06","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sr-12-0db719cf.json","targetId":"ctrl:nist-800-53:SR-12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e551307721f1b290d8a4ef02e0f7113f58963d184d26519bcec63fbc88e7e009","properties":{},"sourceDetailPath":"/data/v1/records/wf-g30-ab069982.json","sourceId":"wf:G30","targetDetailPath":"/data/v1/records/uc-uc-tprm-06-0d2c1b90.json","targetId":"uc:UC-TPRM-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb1cb15221280e6b1a6602e6984f504d71dbd8810665591fefef4dc307c1b936","properties":{},"sourceDetailPath":"/data/v1/records/wf-g13-0f34ff59.json","sourceId":"wf:G13","targetDetailPath":"/data/v1/records/uc-uc-tprm-06-0d2c1b90.json","targetId":"uc:UC-TPRM-06","type":"oversees"}],"schemaVersion":1}
