{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["risk:ai-gpai-systemic-transparency","risk:ai-supply-chain-concentration","risk:bcdr-it-resilience-outage","risk:bcdr-no-tested-continuity-plan","risk:hr-talent-loss-succession","risk:net-denial-of-service","risk:sdlc-malware-injection-compromise","risk:sdlc-ransomware","risk:strategic-geopolitical","risk:tech-hardware-equipment-failure","risk:tech-software-system-failure","risk:tprm-critical-vendor-failure","risk:tprm-supply-chain-disruption","risk:tprm-vendor-compliance-vicarious-liability","risk:tprm-vendor-service-nonperformance","risk:tprm-weak-supplier-oversight","risk:vuln-unpatched-known-flaws","risk:vuln-zero-day","uc:UC-BCDR-02","uc:UC-BCDR-06","uc:UC-BCDR-10","uc:UC-BCDR-16","uc:UC-TPRM-01","wf:A7","wf:C14","wf:C2","wf:C20","wf:C3","wf:C80","wf:D06","wf:D11","wf:D24","wf:G13"],"directIds":["ctrl:dora:DORA-Art17-23","ctrl:dora:DORA-Art24-27","ctrl:dora:DORA-Art28-44","ctrl:dora:DORA-Art45","ctrl:dora:DORA-Art5","ctrl:dora:DORA-Ch2","std:dora"],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"EU DORA","next":"/assets/agent_sources-dora-2.518c3715e1bf87e7.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"administrative","framework":"dora","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/dora/","description":"ICT-related incident management, classification and reporting","details":{"automation":"hybrid","control_category":"administrative","control_id":"DORA-Art17-23","control_type":"corrective","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Third-Party / Supply-Chain Risk","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"dora","group":"EU DORA (Digital Operational Resilience Act)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-dora-dora-art17-23-9aa7977f.html","id":"ctrl:dora:DORA-Art17-23","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Adora%3ADORA-Art17-23","sourceIds":["dora"],"sourceUrl":null,"title":"DORA-Art17-23 — ICT-related incident management, classification and reporting","type":"control","url":"/assets/agent_record-ctrl-dora-dora-art17-23-9aa7977f.313cf7638f5cfdb3.json"},{"attributes":{"category":"technical","framework":"dora","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/dora/","description":"Digital operational resilience testing (incl. threat-led penetration testing)","details":{"automation":"hybrid","control_category":"technical","control_id":"DORA-Art24-27","control_type":"detective","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Third-Party / Supply-Chain Risk","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"dora","group":"EU DORA (Digital Operational Resilience Act)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-dora-dora-art24-27-dc4b8836.html","id":"ctrl:dora:DORA-Art24-27","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Adora%3ADORA-Art24-27","sourceIds":["dora"],"sourceUrl":null,"title":"DORA-Art24-27 — Digital operational resilience testing (incl. threat-led penetration testing)","type":"control","url":"/assets/agent_record-ctrl-dora-dora-art24-27-dc4b8836.10b427458b73121d.json"},{"attributes":{"category":"administrative","framework":"dora","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/dora/","description":"Managing of ICT third-party risk","details":{"automation":"manual","control_category":"administrative","control_id":"DORA-Art28-44","control_type":"preventive","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Third-Party / Supply-Chain Risk","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"dora","group":"EU DORA (Digital Operational Resilience Act)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-dora-dora-art28-44-d3e89c89.html","id":"ctrl:dora:DORA-Art28-44","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Adora%3ADORA-Art28-44","sourceIds":["dora"],"sourceUrl":null,"title":"DORA-Art28-44 — Managing of ICT third-party risk","type":"control","url":"/assets/agent_record-ctrl-dora-dora-art28-44-d3e89c89.a71563b64de05293.json"},{"attributes":{"category":"administrative","framework":"dora","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/dora/","description":"Information and intelligence sharing arrangements","details":{"automation":"manual","control_category":"administrative","control_id":"DORA-Art45","control_type":"preventive","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Third-Party / Supply-Chain Risk","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"dora","group":"EU DORA (Digital Operational Resilience Act)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-dora-dora-art45-bb72d2e3.html","id":"ctrl:dora:DORA-Art45","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Adora%3ADORA-Art45","sourceIds":["dora"],"sourceUrl":null,"title":"DORA-Art45 — Information and intelligence sharing arrangements","type":"control","url":"/assets/agent_record-ctrl-dora-dora-art45-bb72d2e3.3fc6e3ce80d93299.json"},{"attributes":{"category":"administrative","framework":"dora","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/dora/","description":"Governance and organisation (management body responsibility)","details":{"automation":"manual","control_category":"administrative","control_id":"DORA-Art5","control_type":"preventive","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Third-Party / Supply-Chain Risk","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"dora","group":"EU DORA (Digital Operational Resilience Act)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-dora-dora-art5-3d1842f7.html","id":"ctrl:dora:DORA-Art5","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Adora%3ADORA-Art5","sourceIds":["dora"],"sourceUrl":null,"title":"DORA-Art5 — Governance and organisation (management body responsibility)","type":"control","url":"/assets/agent_record-ctrl-dora-dora-art5-3d1842f7.843a5a617cff9f36.json"},{"attributes":{"category":"administrative","framework":"dora","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/dora/","description":"ICT risk management framework (Art 5-16)","details":{"automation":"manual","control_category":"administrative","control_id":"DORA-Ch2","control_type":"preventive","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Third-Party / Supply-Chain Risk","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"dora","group":"EU DORA (Digital Operational Resilience Act)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-dora-dora-ch2-891a747a.html","id":"ctrl:dora:DORA-Ch2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Adora%3ADORA-Ch2","sourceIds":["dora"],"sourceUrl":null,"title":"DORA-Ch2 — ICT risk management framework (Art 5-16)","type":"control","url":"/assets/agent_record-ctrl-dora-dora-ch2-891a747a.7f641d4dbc859a90.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Third-Party / Supply-Chain Risk","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["eu-ai-act-risk","nist-ai-rmf-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-gpai-systemic-transparency","description":"GPAI providers failing transparency/copyright/training-data obligations; systemic-risk models (>10^25 FLOPs) lacking red-teaming, incident reporting, and cybersecurity; unlabeled deepfake/synthetic content; and concentration of GPAI capability creating ecosystem single points of failure.","details":{"category":"ai_governance","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"ai-gpai-systemic-transparency","taxonomies":["eu-ai-act-risk","nist-ai-rmf-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-gpai-systemic-transparency-7a746323.html","id":"risk:ai-gpai-systemic-transparency","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-gpai-systemic-transparency","sourceIds":["aiuc-1","cobit-2019","dora","eu-ai-act","iso-27001","iso-42001","nis2","nist-800-53","nist-csf-2","nydfs-500"],"sourceUrl":null,"title":"GPAI transparency, systemic-risk and synthetic-content obligations","type":"risk","url":"/assets/agent_record-risk-ai-gpai-systemic-transparency-7a746323.6e7a571abe779b08.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Third-Party / Supply-Chain Risk","Secure Development (SDLC) & Application Security"],"inherent_rating":"high","taxonomy":["nist-ai-rmf-risk","iso-23894-ai-risk","eu-ai-act-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-supply-chain-concentration","description":"Because the organization relies on third-party pretrained models, datasets, and libraries that may carry backdoors, malicious code, or bias, and concentrates on a few external AI API providers, AI-dependent workflows are exposed to both supply-chain compromise and provider outage or insolvency, resulting in compromised model behaviour or sudden loss of AI capability.","details":{"category":"ai_governance","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"ai-supply-chain-concentration","taxonomies":["nist-ai-rmf-risk","iso-23894-ai-risk","eu-ai-act-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-supply-chain-concentration-9f791f54.html","id":"risk:ai-supply-chain-concentration","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-supply-chain-concentration","sourceIds":["aiuc-1","cobit-2019","dora","eu-ai-act","iso-27001","iso-42001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2"],"sourceUrl":null,"title":"AI supply-chain compromise and provider concentration","type":"risk","url":"/assets/agent_record-risk-ai-supply-chain-concentration-9f791f54.263d1eb3adc4c1e2.json"},{"attributes":{"category":"business_continuity","domain":["Business Continuity & Disaster Recovery","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["coso-erm-risk","basel-operational-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Abcdr-it-resilience-outage","description":"Critical technology infrastructure or applications experience unplanned outages, data loss, or prolonged recovery times — including failure of DR systems to activate — disrupting operations and harming stakeholders.","details":{"category":"business_continuity","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"bcdr-it-resilience-outage","taxonomies":["coso-erm-risk","basel-operational-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-bcdr-it-resilience-outage-18dfc108.html","id":"risk:bcdr-it-resilience-outage","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Abcdr-it-resilience-outage","sourceIds":["cobit-2019","dora","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"sourceUrl":null,"title":"IT resilience failure — unplanned outage, data loss, slow recovery","type":"risk","url":"/assets/agent_record-risk-bcdr-it-resilience-outage-18dfc108.676c731632e2a885.json"},{"attributes":{"category":"business_continuity","domain":["Business Continuity & Disaster Recovery","Risk Assessment & Management"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk","iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Abcdr-no-tested-continuity-plan","description":"No BCP/DR plan, or plans that exist but have never been exercised end-to-end, so a natural disaster, pandemic, civil unrest, or infrastructure failure disables critical processes with no tested recovery path.","details":{"category":"business_continuity","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"bcdr-no-tested-continuity-plan","taxonomies":["enterprise-risk","coso-erm-risk","iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-bcdr-no-tested-continuity-plan-d4d9e7a9.html","id":"risk:bcdr-no-tested-continuity-plan","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Abcdr-no-tested-continuity-plan","sourceIds":["cobit-2019","dora","iso-27001","nist-800-53","nydfs-500","soc1","soc2","sox"],"sourceUrl":null,"title":"Absent or untested business continuity / disaster recovery plan","type":"risk","url":"/assets/agent_record-risk-bcdr-no-tested-continuity-plan-d4d9e7a9.2e628816044d5241.json"},{"attributes":{"category":"people_hr","domain":["Human Resources / Personnel Security","Business Continuity & Disaster Recovery"],"inherent_rating":"high","taxonomy":["coso-erm-risk","enterprise-risk","iso-27005-threat","iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Ahr-talent-loss-succession","description":"Departure of key executives or irreplaceable specialists without succession or knowledge-transfer plans, plus inability to recruit/retain scarce skills (cyber, data, AI/ML), causing loss of institutional knowledge and execution capacity. Also covers loss of key personnel disrupting operations dependent on specialist knowledge.","details":{"category":"people_hr","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"hr-talent-loss-succession","taxonomies":["coso-erm-risk","enterprise-risk","iso-27005-threat","iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-hr-talent-loss-succession-50c0fc0a.html","id":"risk:hr-talent-loss-succession","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Ahr-talent-loss-succession","sourceIds":["dora","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Critical talent loss, scarcity and succession gaps","type":"risk","url":"/assets/agent_record-risk-hr-talent-loss-succession-50c0fc0a.15de0cf049397eda.json"},{"attributes":{"category":"cyber_security","domain":["Network & Communications Security","Business Continuity & Disaster Recovery"],"inherent_rating":"high","taxonomy":["nist-800-30-threat-event","iso-27005-threat","basel-operational-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Anet-denial-of-service","description":"Simple, targeted, or distributed denial-of-service attacks, wireless jamming, and saturation of systems or networks (adversarial or excessive legitimate load) make resources unavailable to intended users.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"net-denial-of-service","taxonomies":["nist-800-30-threat-event","iso-27005-threat","basel-operational-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-net-denial-of-service-934ccd7f.html","id":"risk:net-denial-of-service","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Anet-denial-of-service","sourceIds":["cobit-2019","dora","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Denial-of-service and system saturation","type":"risk","url":"/assets/agent_record-risk-net-denial-of-service-934ccd7f.b1375cbae5286875.json"},{"attributes":{"category":"cyber_security","domain":["Secure Development (SDLC) & Application Security","Network & Communications Security","Vulnerability & Patch Management"],"inherent_rating":"critical","taxonomy":["nist-800-30-threat-event","basel-operational-risk","iso-27005-threat"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Asdlc-malware-injection-compromise","description":"Adversary crafts and delivers known, modified, or targeted malware (via email, web, removable media, or downloadable software) and compromises system software to take control, exfiltrate data, or degrade functions.","details":{"category":"cyber_security","impact":"critical","inherent_rating":"critical","likelihood":"high","risk_id":"sdlc-malware-injection-compromise","taxonomies":["nist-800-30-threat-event","basel-operational-risk","iso-27005-threat"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.html","id":"risk:sdlc-malware-injection-compromise","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Asdlc-malware-injection-compromise","sourceIds":["aiuc-1","cobit-2019","dora","eu-ai-act","iso-27001","nist-800-53","nist-csf-2","pci-dss"],"sourceUrl":null,"title":"Malware delivery, insertion and compromise of systems","type":"risk","url":"/assets/agent_record-risk-sdlc-malware-injection-compromise-ec5a8dc4.fad24733760f31d9.json"},{"attributes":{"category":"cyber_security","domain":["Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Incident Management & Response"],"inherent_rating":"critical","taxonomy":["basel-operational-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Asdlc-ransomware","description":"Criminal groups deploy ransomware that encrypts systems and data, disrupting operations, causing losses, and demanding extortion payment — a high-impact convergence of malware, availability, and continuity risk.","details":{"category":"cyber_security","impact":"critical","inherent_rating":"critical","likelihood":"medium","risk_id":"sdlc-ransomware","taxonomies":["basel-operational-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-sdlc-ransomware-32ab67f4.html","id":"risk:sdlc-ransomware","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Asdlc-ransomware","sourceIds":["aiuc-1","cobit-2019","dora","eu-ai-act","iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Ransomware disrupting operations and data availability","type":"risk","url":"/assets/agent_record-risk-sdlc-ransomware-32ab67f4.56e0ec5a2584ab1d.json"},{"attributes":{"category":"strategic","domain":["Risk Assessment & Management","Third-Party / Supply-Chain Risk"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Astrategic-geopolitical","description":"Armed conflict, political instability, sanctions, trade-policy reversals (tariffs, export bans, data-localization, forced tech transfer), expropriation/nationalization, and adverse macroeconomic cycles disrupt operations, supply chains, and cost structures.","details":{"category":"strategic","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"strategic-geopolitical","taxonomies":["enterprise-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-strategic-geopolitical-4e7aba30.html","id":"risk:strategic-geopolitical","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Astrategic-geopolitical","sourceIds":["cobit-2019","coso-erm","coso-ic","dora","iso-27001","iso-31000","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2"],"sourceUrl":null,"title":"Geopolitical, macroeconomic and sovereign risk","type":"risk","url":"/assets/agent_record-risk-strategic-geopolitical-4e7aba30.21005b4da044225f.json"},{"attributes":{"category":"operational","domain":["Business Continuity & Disaster Recovery","Asset Management & Inventory"],"inherent_rating":"medium","taxonomy":["iso-27005-threat","nist-800-30-threat-source","nist-800-30-threat-event","basel-operational-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atech-hardware-equipment-failure","description":"Malfunction or breakdown of storage, processing, communications, sensor, controller, or display equipment (aging, resource depletion, disk errors) disrupting availability or integrity — including intermittent/degraded operation producing incorrect results.","details":{"category":"operational","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"tech-hardware-equipment-failure","taxonomies":["iso-27005-threat","nist-800-30-threat-source","nist-800-30-threat-event","basel-operational-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tech-hardware-equipment-failure-25948451.html","id":"risk:tech-hardware-equipment-failure","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atech-hardware-equipment-failure","sourceIds":["cobit-2019","dora","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"sourceUrl":null,"title":"Hardware and equipment failure","type":"risk","url":"/assets/agent_record-risk-tech-hardware-equipment-failure-25948451.3a7e6b9d681e4d45.json"},{"attributes":{"category":"operational","domain":["Business Continuity & Disaster Recovery","Secure Development (SDLC) & Application Security"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-source","basel-operational-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atech-software-system-failure","description":"Failure or malfunction of operating-system, networking, or application software (defects, resource depletion, failed releases) causing loss of availability/integrity and impeding mission/business functions — including core banking/payments outages.","details":{"category":"operational","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"tech-software-system-failure","taxonomies":["iso-27005-threat","nist-800-30-threat-source","basel-operational-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tech-software-system-failure-2e2c5364.html","id":"risk:tech-software-system-failure","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atech-software-system-failure","sourceIds":["cobit-2019","dora","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"sourceUrl":null,"title":"Software and information-system failure","type":"risk","url":"/assets/agent_record-risk-tech-software-system-failure-2e2c5364.025addde30ebc5e9.json"},{"attributes":{"category":"third_party","domain":["Third-Party / Supply-Chain Risk","Business Continuity & Disaster Recovery"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk","basel-operational-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-critical-vendor-failure","description":"A key supplier, SaaS provider, or outsourced partner becomes insolvent, exits the market, or suffers a prolonged outage; sole-source and shared-tier concentration (multiple tier-1 vendors on a common tier-2) creates hidden single points of failure with no backup.","details":{"category":"third_party","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"tprm-critical-vendor-failure","taxonomies":["enterprise-risk","coso-erm-risk","basel-operational-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tprm-critical-vendor-failure-cb39c2bc.html","id":"risk:tprm-critical-vendor-failure","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-critical-vendor-failure","sourceIds":["cobit-2019","dora","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"Critical vendor failure, insolvency or concentration","type":"risk","url":"/assets/agent_record-risk-tprm-critical-vendor-failure-cb39c2bc.40d00208e79dbc8a.json"},{"attributes":{"category":"operational","domain":["Third-Party / Supply-Chain Risk","Business Continuity & Disaster Recovery"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-supply-chain-disruption","description":"Geopolitical events, natural disasters, port congestion, or logistics failures interrupt supply of critical raw materials or components (semiconductors, rare earths); just-in-time models are exposed to demand spikes.","details":{"category":"operational","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"tprm-supply-chain-disruption","taxonomies":["enterprise-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tprm-supply-chain-disruption-0d7e0959.html","id":"risk:tprm-supply-chain-disruption","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-supply-chain-disruption","sourceIds":["cobit-2019","dora","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2"],"sourceUrl":null,"title":"Supply-chain disruption of critical inputs","type":"risk","url":"/assets/agent_record-risk-tprm-supply-chain-disruption-0d7e0959.3070d406a058fdb6.json"},{"attributes":{"category":"third_party","domain":["Third-Party / Supply-Chain Risk","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-vendor-compliance-vicarious-liability","description":"A vendor, subcontractor, or channel partner violates labor, environmental, anti-bribery (FCPA/UKBA), or data-protection rules, exposing the company to liability and reputational harm; fourth-party/N-tier dependencies are opaque.","details":{"category":"third_party","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"tprm-vendor-compliance-vicarious-liability","taxonomies":["enterprise-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tprm-vendor-compliance-vicarious-liability-0215657c.html","id":"risk:tprm-vendor-compliance-vicarious-liability","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-vendor-compliance-vicarious-liability","sourceIds":["ccpa","cobit-2019","dora","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"Third-party compliance failure creating vicarious liability","type":"risk","url":"/assets/agent_record-risk-tprm-vendor-compliance-vicarious-liability-0215657c.77578fe7de7d58ff.json"},{"attributes":{"category":"third_party","domain":["Third-Party / Supply-Chain Risk"],"inherent_rating":"medium","taxonomy":["basel-operational-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-vendor-service-nonperformance","description":"Outsourced processing, IT, payroll/HR, print/mail, or sub-custodian providers fail to meet service levels, deliver defective software, make incorrect payments, or breach contractual deliverables, causing processing errors, outages, and loss.","details":{"category":"third_party","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"tprm-vendor-service-nonperformance","taxonomies":["basel-operational-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tprm-vendor-service-nonperformance-081f2fb9.html","id":"risk:tprm-vendor-service-nonperformance","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-vendor-service-nonperformance","sourceIds":["ccpa","cobit-2019","dora","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"Vendor/outsourcing service non-performance and disputes","type":"risk","url":"/assets/agent_record-risk-tprm-vendor-service-nonperformance-081f2fb9.6aa8159a02796175.json"},{"attributes":{"category":"third_party","domain":["Third-Party / Supply-Chain Risk","Governance, Policy & Oversight"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-weak-supplier-oversight","description":"Because supplier contracts omit security requirements and SLAs and third-party service delivery is not monitored, processors and sub-processors operate without equivalent, audited obligations, so third-party weaknesses and breaches propagate into the organization undetected.","details":{"category":"third_party","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"tprm-weak-supplier-oversight","taxonomies":["iso-27005-vulnerability","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tprm-weak-supplier-oversight-1baaa012.html","id":"risk:tprm-weak-supplier-oversight","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-weak-supplier-oversight","sourceIds":["ccpa","cobit-2019","dora","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"Weak supplier security requirements and monitoring","type":"risk","url":"/assets/agent_record-risk-tprm-weak-supplier-oversight-1baaa012.91f09390d6cc203e.json"},{"attributes":{"category":"cyber_security","domain":["Vulnerability & Patch Management","Secure Configuration & Change Management"],"inherent_rating":"critical","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event","iso-27005-threat"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Avuln-unpatched-known-flaws","description":"Use of software with publicly known, unpatched flaws (CVEs) that adversaries readily exploit — including recently discovered vulnerabilities exploited before mitigations are in place, and internal-system vulnerability exploitation.","details":{"category":"cyber_security","impact":"high","inherent_rating":"critical","likelihood":"high","risk_id":"vuln-unpatched-known-flaws","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event","iso-27005-threat"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-vuln-unpatched-known-flaws-c4a6b075.html","id":"risk:vuln-unpatched-known-flaws","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Avuln-unpatched-known-flaws","sourceIds":["dora","gdpr","iso-27001","nist-800-53","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Exploitation of known, unpatched vulnerabilities","type":"risk","url":"/assets/agent_record-risk-vuln-unpatched-known-flaws-c4a6b075.3a21c5668d469a67.json"},{"attributes":{"category":"cyber_security","domain":["Vulnerability & Patch Management","Secure Development (SDLC) & Application Security"],"inherent_rating":"high","taxonomy":["nist-800-30-threat-event","iso-27005-threat"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Avuln-zero-day","description":"Adversary employs attacks that exploit as-yet-unpublicized vulnerabilities (targeted, based on reconnaissance, or nontargeted), compromising systems before any patch or signature exists.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"vuln-zero-day","taxonomies":["nist-800-30-threat-event","iso-27005-threat"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-vuln-zero-day-a821d603.html","id":"risk:vuln-zero-day","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Avuln-zero-day","sourceIds":["aiuc-1","cobit-2019","dora","eu-ai-act","iso-27001","nist-800-53","nist-csf-2","pci-dss"],"sourceUrl":null,"title":"Zero-day exploitation","type":"risk","url":"/assets/agent_record-risk-vuln-zero-day-a821d603.0a4e24c84e6d51c6.json"},{"attributes":{"authority":"mandatory","category":"dora"},"canonicalUrl":"https://controlsmap.com/frameworks/dora/","description":"EU DORA — Digital Operational Resilience Act","details":{"amendmentState":"none","authority":"mandatory","effectiveDate":"2025-01-17","note":null,"propositions":[],"publicationDate":"2022-12-27","reviewed_at":null,"source_url":null,"version":"Regulation (EU) 2022/2554"},"direct":true,"htmlUrl":"/agents/records/std-dora-95cf939d.html","id":"std:dora","mapUrl":"https://controlsmap.com/?v=1&node=std%3Adora","sourceIds":["dora"],"sourceUrl":null,"title":"EU DORA","type":"standard","url":"/assets/agent_record-std-dora-95cf939d.6795d60d089e0bd4.json"},{"attributes":{"category":"administrative","domain":"Business Continuity & Disaster Recovery","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-BCDR-02","description":"Establish a documented ICT risk management framework covering identification, protection, detection, response, recovery, and learning for critical ICT services, with a defined digital operational resilience strategy and risk tolerance. The management body approves the framework, assigns clear roles and responsibilities for ICT risk, allocates supporting budget, reviews the framework at least annually, and remains accountable for its effectiveness.","details":{"control_category":"administrative","control_type":"preventive","domain":"Business Continuity & Disaster Recovery","guidance":[],"members":[{"control_id":"DORA-Ch2","coverage":"partial","delta":"detailed protection, backup, and recovery capabilities implemented via companion controls","framework":"dora","relationship":"intersects_with"},{"control_id":"DORA-Art5","coverage":"full","framework":"dora","relationship":"superset_of"}],"statement":"Establish a documented ICT risk management framework covering identification, protection, detection, response, recovery, and learning for critical ICT services, with a defined digital operational resilience strategy and risk tolerance. The management body approves the framework, assigns clear roles and responsibilities for ICT risk, allocates supporting budget, reviews the framework at least annually, and remains accountable for its effectiveness.","title":"Establish and govern an ICT operational resilience framework","unified_id":"UC-BCDR-02"},"direct":false,"htmlUrl":"/agents/records/uc-uc-bcdr-02-2a51c24c.html","id":"uc:UC-BCDR-02","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-BCDR-02","sourceIds":["dora"],"sourceUrl":null,"title":"UC-BCDR-02 — Establish and govern an ICT operational resilience framework","type":"unified","url":"/assets/agent_record-uc-uc-bcdr-02-2a51c24c.ad7ee14201ae473c.json"},{"attributes":{"category":"administrative","domain":"Business Continuity & Disaster Recovery","type":"corrective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-BCDR-06","description":"Log, classify, and prioritize operational and security incidents and service requests, respond within defined service levels, and escalate by severity until service is restored. Classify and report major ICT incidents to regulators, customers, and affected parties within required timeframes. Perform root-cause analysis of significant and recurring incidents, and track underlying problems through to permanent resolution.","details":{"control_category":"administrative","control_type":"corrective","domain":"Business Continuity & Disaster Recovery","guidance":[],"members":[{"control_id":"DSS02","coverage":"full","framework":"cobit-2019","relationship":"superset_of"},{"control_id":"DSS03","coverage":"full","framework":"cobit-2019","relationship":"superset_of"},{"control_id":"DORA-Art17-23","coverage":"partial","delta":"major-incident report clocks: initial 24h, intermediate 72h, final 1 month","framework":"dora","relationship":"intersects_with"}],"statement":"Log, classify, and prioritize operational and security incidents and service requests, respond within defined service levels, and escalate by severity until service is restored. Classify and report major ICT incidents to regulators, customers, and affected parties within required timeframes. Perform root-cause analysis of significant and recurring incidents, and track underlying problems through to permanent resolution.","title":"Resolve operational incidents and eliminate root causes","unified_id":"UC-BCDR-06"},"direct":false,"htmlUrl":"/agents/records/uc-uc-bcdr-06-c505e5bd.html","id":"uc:UC-BCDR-06","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-BCDR-06","sourceIds":["cobit-2019","dora"],"sourceUrl":null,"title":"UC-BCDR-06 — Resolve operational incidents and eliminate root causes","type":"unified","url":"/assets/agent_record-uc-uc-bcdr-06-c505e5bd.6d6cd6f9a1129bae.json"},{"attributes":{"category":"administrative","domain":"Business Continuity & Disaster Recovery","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-BCDR-10","description":"Test business continuity, disaster recovery, and restoration capabilities at least annually through scenario exercises, failover and restore tests, and, where required for critical systems, advanced or threat-led penetration testing. Train all personnel with contingency roles on their responsibilities upon assignment and periodically thereafter. Review test and exercise results and remediate identified gaps.","details":{"control_category":"administrative","control_type":"detective","domain":"Business Continuity & Disaster Recovery","guidance":[],"members":[{"control_id":"CP-3","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"CP-4","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A1.3","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"DORA-Art24-27","coverage":"partial","delta":"vulnerability assessments and the Art 25 security-testing catalogue satisfied by companion controls; TLPT regime specifics - three-yearly cadence, authority-approved scope, independent/certified testers (Arts 26-27), and tester independence (Art 24(4)) - require dedicated controls","framework":"dora","relationship":"intersects_with"}],"statement":"Test business continuity, disaster recovery, and restoration capabilities at least annually through scenario exercises, failover and restore tests, and, where required for critical systems, advanced or threat-led penetration testing. Train all personnel with contingency roles on their responsibilities upon assignment and periodically thereafter. Review test and exercise results and remediate identified gaps.","title":"Test recovery capabilities and train contingency personnel","unified_id":"UC-BCDR-10"},"direct":false,"htmlUrl":"/agents/records/uc-uc-bcdr-10-602160e4.html","id":"uc:UC-BCDR-10","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-BCDR-10","sourceIds":["dora","nist-800-53","soc2"],"sourceUrl":null,"title":"UC-BCDR-10 — Test recovery capabilities and train contingency personnel","type":"unified","url":"/assets/agent_record-uc-uc-bcdr-10-602160e4.a2451b53187d3302.json"},{"attributes":{"category":"administrative","domain":"Vulnerability & Patch Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-BCDR-16","description":"Establish arrangements to exchange cyber threat information and intelligence, such as indicators of compromise, tactics, and alerts, with trusted communities of peers and authorities. Operate the exchange under agreements that protect sensitive business information and comply with data protection requirements.","details":{"control_category":"administrative","control_type":"preventive","domain":"Vulnerability & Patch Management","guidance":[],"members":[{"control_id":"DORA-Art45","coverage":"full","framework":"dora","relationship":"equal"}],"statement":"Establish arrangements to exchange cyber threat information and intelligence, such as indicators of compromise, tactics, and alerts, with trusted communities of peers and authorities. Operate the exchange under agreements that protect sensitive business information and comply with data protection requirements.","title":"Participate in cyber threat intelligence sharing","unified_id":"UC-BCDR-16"},"direct":false,"htmlUrl":"/agents/records/uc-uc-bcdr-16-462251f1.html","id":"uc:UC-BCDR-16","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-BCDR-16","sourceIds":["dora"],"sourceUrl":null,"title":"UC-BCDR-16 — Participate in cyber threat intelligence sharing","type":"unified","url":"/assets/agent_record-uc-uc-bcdr-16-462251f1.ec4600d14fbded7a.json"},{"attributes":{"category":"administrative","domain":"Third-Party / Supply-Chain Risk","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-01","description":"Establish and operate a management-approved third-party and supply-chain risk management program with a written strategy, policies, and procedures, reviewed at defined intervals and after significant changes to the supply chain or threat landscape. Define and communicate roles and responsibilities for supplier, customer, and partner relationships, and integrate third-party and supply-chain risk into enterprise and cybersecurity risk management. Maintain a register of third-party relationships and contractual arrangements prioritized by criticality, and assess criticality, substitutability, and concentration risk before contracting. Apply risk-based due diligence, embed security requirements, audit and access rights, termination rights, and sub-outsourcing conditions in agreements, and protect organizational information processed, stored, or transmitted on external systems. Define, agree, and periodically review service agreements and supplier performance, reassess third parties on a defined cycle, operate controls to identify and address weaknesses across the relationship life cycle, and maintain documented, tested exit strategies for providers supporting critical or important functions.","details":{"control_category":"administrative","control_type":"preventive","domain":"Third-Party / Supply-Chain Risk","guidance":[],"members":[{"control_id":"SR-2","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SR-3","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"GV.SC-01","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GV.SC-02","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GV.SC-03","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GV.SC-04","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"A.5.19","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"500.11","coverage":"partial","delta":"policies must address TPSP MFA/access, encryption, event-notice, and representations guidelines","framework":"nydfs-500","relationship":"intersects_with"},{"control_id":"PM-30","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"SR-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PM-17","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"NIS2-Art21d","coverage":"partial","delta":"operational supplier security assessments and contractual safeguards per supplier","framework":"nis2","relationship":"intersects_with"},{"control_id":"APO09","coverage":"partial","delta":"service catalog definition and SLA lifecycle management","framework":"cobit-2019","relationship":"intersects_with"},{"control_id":"APO10","coverage":"partial","delta":"day-to-day vendor performance monitoring and contract administration","framework":"cobit-2019","relationship":"intersects_with"},{"control_id":"DORA-Art28-44","coverage":"partial","delta":"DORA-specific regulator obligations (register of information format, competent-authority/Lead Overseer interactions) beyond the general third-party program","framework":"dora","relationship":"intersects_with"}],"statement":"Establish and operate a management-approved third-party and supply-chain risk management program with a written strategy, policies, and procedures, reviewed at defined intervals and after significant changes to the supply chain or threat landscape. Define and communicate roles and responsibilities for supplier, customer, and partner relationships, and integrate third-party and supply-chain risk into enterprise and cybersecurity risk management. Maintain a register of third-party relationships and contractual arrangements prioritized by criticality, and assess criticality, substitutability, and concentration risk before contracting. Apply risk-based due diligence, embed security requirements, audit and access rights, termination rights, and sub-outsourcing conditions in agreements, and protect organizational information processed, stored, or transmitted on external systems. Define, agree, and periodically review service agreements and supplier performance, reassess third parties on a defined cycle, operate controls to identify and address weaknesses across the relationship life cycle, and maintain documented, tested exit strategies for providers supporting critical or important functions.","title":"Operate a third-party security risk management program","unified_id":"UC-TPRM-01"},"direct":false,"htmlUrl":"/agents/records/uc-uc-tprm-01-16b62053.html","id":"uc:UC-TPRM-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-TPRM-01","sourceIds":["cobit-2019","dora","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500"],"sourceUrl":null,"title":"UC-TPRM-01 — Operate a third-party security risk management program","type":"unified","url":"/assets/agent_record-uc-uc-tprm-01-16b62053.e1971425fb996beb.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-third-party-assurance-engagement","description":"Runs on the existing Audit item for this engagement (audit_type=vendor_review) — the workflow enriches that already-planned engagement record, it never creates a duplicate — consuming the confirmed scope, criteria, and calendar handed off from Audit Engagement Planning. An IA-led third-party vendor assurance engagement that concludes on the design and operating effectiveness of the organization’s TPRM program — governance, risk tiering, vendor control-environment reliance, monitoring, exclusions, and reporting. Vendors under test are the existing Vendor items, each finding is an Issue item, and the named deliverable is a reperformable engagement workpaper package. In scope: assuring the program (IA evaluates management’s third-party risk management; it does not operate it). Out of scope: operating the vendor lifecycle (onboarding, tier refresh, remediation), which belongs to the second-line Third-Party Vendor Risk Lifecycle workflow; deep single-report SOC work, which can be delegated to the reusable Vendor SOC 1/SOC 2 Report Review & CUEC Mapping workflow; and ICT arrangements caught by regulatory regimes, which route to Third-Party ICT Vendor Regulatory Assurance. Findings and the engagement conclusion exit through Audit Report Drafting, and action plans route to Finding Remediation & Action-Plan Monitoring.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-third-party-assurance-engagement","capabilities":[],"controls":["UC-AUDIT-12","UC-AUDIT-13","UC-AUDIT-16","UC-TPRM-01","UC-TPRM-02","UC-TPRM-04"],"domains":["audit"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:559830dd60ca4ef7406b72e8d19e4c47cc75cede6d875886681f1bf77abddf64","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:audit-third-party-assurance-engagement","standards":["iia-2024"],"teams":["internal-audit","procurement"]},"direct":false,"htmlUrl":"/agents/records/wf-a7-454c1d0e.html","id":"wf:A7","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AA7","slug":"audit-third-party-assurance-engagement","sourceIds":["cobit-2019","dora","iia-2024","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2"],"sourceUrl":null,"title":"Third-Party Vendor Assurance Engagement","type":"workflow","url":"/assets/agent_record-wf-a7-454c1d0e.2d019e7089068b15.json"},{"attributes":{"department":"operations","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-bcdr-test-exercise","description":"Run one operating cycle of an existing business continuity / disaster recovery plan-testing Control (the BC/DR test control this instance attaches to, UC-BCDR-04 \"tests\"): plan, execute, and evaluate a BC/DR exercise against the RTO and RPO objectives, then fold the resulting gaps back into the BC and DR plans as versioned redlines — a decision-aware workflow. It consumes as declared inputs the in-force BC and DR plans (existing Policy items), the business impact analysis (BIA), and prior after-action reports; it creates an Audit item (audit_type=operational) as the definitive exercise record, and produces named deliverables: an approved exercise package, an actual-versus-target RTO/RPO scorecard, remediation findings (Issue items), and a signed-off after-action report with an indexed evidence package. In scope: scoping, running, and evaluating one scheduled or triggered BC/DR exercise for the selected in-scope systems and business services, and folding resulting gaps back into the BC and DR plans. Out of scope: real incident response, and recovery-objective (RTO or RPO) changes to systems outside the agreed exercise scope. Standalone: no upstream or downstream workflow is required; any cross-workflow linkage — for example a related incident-response or BIA-maintenance workflow — is expressed as a declared input, not a predecessor.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-bcdr-test-exercise","capabilities":[],"controls":["UC-BCDR-10","UC-BCDR-01","UC-BCDR-03","UC-ASSET-11","UC-BCDR-04","UC-BCDR-07"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:a8327d73b34cf64076fa4977e8aedb36e95121d78b859e40ddbc05bbbf6079a0","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-bcdr-test-exercise","standards":["iso-27001","nist-800-53"],"teams":["operations","it"]},"direct":false,"htmlUrl":"/agents/records/wf-c14-c6170cdd.html","id":"wf:C14","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC14","slug":"controls-bcdr-test-exercise","sourceIds":["cobit-2019","dora","iso-27001","nist-800-53","nist-csf-2","nydfs-500","soc2"],"sourceUrl":null,"title":"Business Continuity & DR Test Exercise","type":"workflow","url":"/assets/agent_record-wf-c14-c6170cdd.aedf13a86c35c1ad.json"},{"attributes":{"department":"it","domain":"controls","lineOfDefense":"monitor"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-csf-profile-maturity-assessment","description":"Runs on an Audit item created for this assessment cycle (audit_type = readiness) — the CSF assessment engagement the workflow instance attaches to and enriches as it progresses (scope, period, rating, and report fields are written on that Audit item; every in-scope Control is linked to it so the controls-scoped profile is queryable). Build, against that boundary, a NIST CSF 2.0 Current Profile, a Target Profile, an organizational Tier rating, a subcategory gap analysis, and a CISO-ready remediation roadmap. The workflow originates on its own — scoping ingests prior CSF profiles and open POA&M (Issue) items as data, not as a named upstream handoff. In scope: rating the in-scope control set against the CSF 2.0 Core, setting target outcomes, assigning a Tier, and producing a prioritized roadmap. Out of scope: executing the remediation projects themselves and re-performing independent assurance testing. The named deliverable is the assessment package (profiles, gap analysis, Tier, posture report, roadmap, closure artifact), handed off to TWO downstream workflows that consume it rather than repeat the profiling: the Cybersecurity Assurance Review (always) and the AI Governance & Risk/Impact Assessment (only when AI systems fall inside the boundary).","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-csf-profile-maturity-assessment","capabilities":[],"controls":["UC-AUDIT-22","UC-RISK-13","UC-RISK-14","UC-GOV-02","UC-GOV-04","UC-GOV-06","UC-GOV-09","UC-GOV-10","UC-GOV-11","UC-GOV-12","UC-TPRM-01","UC-RISK-15"],"domains":["controls"],"lineOfDefense":"monitor","mappingStatus":"mapped","releaseId":"sha256:27c45a606d72b2ab411434c5a4c54d39fbe813777b3075321f79ec72cf5de5a8","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-csf-profile-maturity-assessment","standards":["nist-csf-2"],"teams":["it","executive"]},"direct":false,"htmlUrl":"/agents/records/wf-c2-a1078981.html","id":"wf:C2","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC2","slug":"controls-csf-profile-maturity-assessment","sourceIds":["cobit-2019","coso-erm","coso-ic","dora","iso-27001","iso-31000","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2","sox"],"sourceUrl":null,"title":"CSF 2.0 Profile & Maturity Assessment","type":"workflow","url":"/assets/agent_record-wf-c2-a1078981.ca8fbf68850a08ec.json"},{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-threat-intelligence-program","description":"Runs on the existing Process item \"Threat Intelligence & Insider Threat Program\" (process_type=security_process, process_owner = program lead) — a long-lived program record related to the Control items it operates (UC-RISK-17, UC-BCDR-16, UC-GOV-37); each cycle is one recurring workflow instance attached to that Process, enriching the standing program rather than creating a new one. Decision-aware, covering NIST SP 800-53 PM-12, PM-16, and RA-10 and NIST CSF 2.0 ID.RA and DE.CM. In scope: cyclic intake and curation of threat intelligence into a validated intake register and intel cards, governed internal dissemination and TLP-marked outbound sharing packages, intel-driven threat hunts (producing the hunt summary) and any resulting investigation record, and privacy-guarded review of insider-threat indicators with a governed board disposition and a restricted insider case file, closing with a program-effectiveness report and a reperformable cycle archive. No upstream workflow feeds it; the only cross-run input is the prior cycle's carry-forward package (the carry-forward document from the previous instance's program-effectiveness report step, which closes each cycle), and each cycle emits the next one. Out of scope and handed off only in prose (no terminal handoff node): incident-response execution (the incident-response process, once an incident is declared at open-investigation) and HR/legal employment actions (owned by those functions within an insider case). Each cycle's intel-and-hunt track and its insider-threat track start in parallel from their own inputs.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-threat-intelligence-program","capabilities":[],"controls":["UC-RISK-17","UC-BCDR-16","UC-GOV-37"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:9e50ff9e802446081a3b33b6195cb72fc672500d02b83389a22727d7e12d9ece","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-threat-intelligence-program","standards":["nist-800-53","nist-csf-2"],"teams":["it"]},"direct":false,"htmlUrl":"/agents/records/wf-c20-5b99e185.html","id":"wf:C20","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC20","slug":"controls-threat-intelligence-program","sourceIds":["dora","iso-27001","nist-800-53"],"sourceUrl":null,"title":"Threat Intelligence & Insider Threat Program","type":"workflow","url":"/assets/agent_record-wf-c20-5b99e185.c8c99637d160c839.json"},{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-cybersecurity-incident-response","description":"Cybersecurity incident-response cycle as a decision-aware workflow spanning detection and validation, scoping, incident declaration and response-plan activation, containment with evidence preservation, eradication and recovery, POA&M updates for the control deficiencies the incident exposed, and a technical lessons-learned retrospective, closed through a disposition decision and archival. The workflow instance runs on the incident record — an Issue item (issue_type=exception, source=management_identified, severity per the org scheme) created at detection, since the schema has no native Incident type — and enriches that one record through to archival rather than creating duplicates. In scope: security events and confirmed incidents affecting the system boundary and its NIST 800-53 IR-family controls — the detection sources (logging/monitoring Control items, UC-LOG-06), affected systems (Process items, UC-ASSET-11), containment and recovery actions, forensic evidence, the deficiency Issues that become the POA&M, and their linked Risk items. Out of scope: the enterprise incident-management ticketing lifecycle and external breach-notification/legal reporting, which run in their own workflows. Where an Incident Management Lifecycle workflow is running, this cycle consumes its handoff package (initial ticket, reporter, affected systems); it hands the closed incident's control-deficiency findings — the open POA&M Issues (issue_type=deficiency) — to the Continuous Controls Monitoring (ISCM) Cycle as shared items it queries directly.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-cybersecurity-incident-response","capabilities":[],"controls":["UC-IR-04","UC-IR-05","UC-IR-06","UC-IR-07","UC-IR-09","UC-IR-10","UC-LOG-06","UC-RISK-14","UC-ASSET-11","UC-BCDR-06","UC-BCDR-07","UC-BCDR-08"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:24f03436d3713f92be067a14847e35f7b71d0b34c3bab5fe0e06bcc04156c45f","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-cybersecurity-incident-response","standards":["nist-800-53","nist-csf-2"],"teams":["it"]},"direct":false,"htmlUrl":"/agents/records/wf-c3-4a88b225.html","id":"wf:C3","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC3","slug":"controls-cybersecurity-incident-response","sourceIds":["cobit-2019","coso-ic","dora","gdpr","iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"Cybersecurity Incident Response","type":"workflow","url":"/assets/agent_record-wf-c3-4a88b225.8eb008b74e3e5013.json"},{"attributes":{"department":"it","domain":"controls","lineOfDefense":"operate"},"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-incident-problem-review","description":"Runs on the existing system item. Record an incident on a system, evidence containment against response targets, and determine root cause with preventive action. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-incident-problem-review","capabilities":["incident-problem-management"],"controls":["UC-BCDR-06"],"domains":["controls"],"lineOfDefense":"operate","mappingStatus":"mapped","releaseId":"sha256:93d0aa5a409d203e64d1562914362cc6b67fd832883fe53c57410d39b3caa247","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:controls-system-incident-problem-review","standards":[],"teams":["it"]},"direct":false,"htmlUrl":"/agents/records/wf-c80-7d360115.html","id":"wf:C80","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AC80","slug":"controls-system-incident-problem-review","sourceIds":["cobit-2019","dora"],"sourceUrl":null,"title":"Incident & Problem Management","type":"workflow","url":"/assets/agent_record-wf-c80-7d360115.d946dbebbb1901a0.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-iso27001-stage2-controls-audit","description":"Attach to the existing Audit engagement, owned by Internal Audit, using its approved Statement of Applicability, risk treatment plan, scope, review period and operating evidence; produce the Stage 2 Annex A Controls Audit report, four signed theme conclusions and finding register for the engagement and remediation owners. Apply the approved Statement of Applicability to ISO/IEC 27001:2022 Annex A.5.1–A.5.37, A.6.1–A.6.8, A.7.1–A.7.14 and A.8.1–A.8.34; document each exclusion and assess direct and inherited responsibilities. This Annex A assessment contributes to the engagement and does not independently establish full ISMS conformity or issue certification. Stage 1 and readiness remain separate workflows; any certification decision remains with the authorized certification body.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-iso27001-stage2-controls-audit","capabilities":[],"controls":["UC-ACCESS-02","UC-ACCESS-03","UC-ACCESS-04","UC-ACCESS-05","UC-ACCESS-06","UC-ACCESS-08","UC-ACCESS-09","UC-ACCESS-18","UC-ASSET-01","UC-ASSET-03","UC-ASSET-04","UC-ASSET-06","UC-ASSET-07","UC-ASSET-08","UC-AUDIT-23","UC-AUDIT-24","UC-AUDIT-25","UC-BCDR-01","UC-BCDR-03","UC-BCDR-04","UC-CONFIG-01","UC-CONFIG-02","UC-CONFIG-03","UC-CONFIG-05","UC-CRYPTO-02","UC-DATA-09","UC-DATA-11","UC-DATA-12","UC-DATA-13","UC-GOV-03","UC-GOV-06","UC-GOV-07","UC-GOV-08","UC-GOV-14","UC-GOV-22","UC-GOV-23","UC-HR-01","UC-HR-02","UC-HR-03","UC-HR-04","UC-HR-05","UC-HR-07","UC-IR-01","UC-IR-03","UC-IR-04","UC-IR-06","UC-IR-07","UC-IR-10","UC-LOG-01","UC-LOG-02","UC-LOG-04","UC-LOG-08","UC-NET-01","UC-NET-13","UC-PHYS-01","UC-PHYS-02","UC-PHYS-03","UC-PHYS-04","UC-PHYS-05","UC-PHYS-06","UC-PHYS-08","UC-PHYS-09","UC-RISK-02","UC-RISK-17","UC-SDLC-01","UC-SDLC-03","UC-SDLC-04","UC-SDLC-05","UC-SDLC-10","UC-SDLC-14","UC-TPRM-01","UC-TPRM-04","UC-TPRM-07","UC-TPRM-08","UC-TRAIN-01","UC-VULN-03","UC-VULN-04","UC-VULN-05"],"domains":["audit"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:b684ea2e0d1a9c1dea7abe73d94ca5e187127e4e8497cd066aaf3917023996ae","roleIntegrity":{"activityCount":5,"ermPhases":["assess","report"],"lineRoles":["third"],"serviceModes":["assurance"],"warnings":[{"code":"reliance-basis-incomplete","message":"Template-design warning: material reliance is mapped without a tagged step covering the full provider-reliance basis.","missing":["competence","recency"],"nodeIds":["approve-annex-a-conclusion","assess-organizational-controls","assess-people-controls","assess-physical-controls","assess-technological-controls"],"title":"Reliance basis is incomplete"}]},"sourceTemplateId":"workflow-library:audit-iso27001-stage2-controls-audit","standards":["iso-27001"],"teams":["internal-audit"]},"direct":false,"htmlUrl":"/agents/records/wf-d06-c9616fb8.html","id":"wf:D06","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AD06","slug":"audit-iso27001-stage2-controls-audit","sourceIds":["aiuc-1","ccpa","cobit-2019","coso-erm","coso-ic","dora","eu-ai-act","gdpr","hipaa","iia-2024","iia-pos-2026-three-lines","iso-27001","iso-31000","nis2","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"ISO 27001 Stage 2 Annex A Controls Audit","type":"workflow","url":"/assets/agent_record-wf-d06-c9616fb8.602879df218362f9.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-soc2-availability-assessment","description":"Design-readiness review of the SOC 2 availability series: capacity management, environmental protections with backup and recovery infrastructure, and recovery plan testing (A1.1–A1.3). Design-readiness assessment limited to the listed SOC 2 criteria. Evidence may include operating examples to assess the design; this module does not provide a SOC 2 Type II opinion. Attach this workflow to the existing audit engagement item; retain evidence and conclusions on its workflow steps.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-soc2-availability-assessment","capabilities":[],"controls":["UC-BCDR-03","UC-BCDR-05","UC-BCDR-10"],"domains":["audit"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:7983431d7321b998260992c652b92d70e13509f7bf8e704d755e882efb2c9f77","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:audit-soc2-availability-assessment","standards":["soc2"],"teams":["internal-audit"]},"direct":false,"htmlUrl":"/agents/records/wf-d11-12a96993.html","id":"wf:D11","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AD11","slug":"audit-soc2-availability-assessment","sourceIds":["dora","iso-27001","nist-800-53","nist-csf-2","soc2"],"sourceUrl":null,"title":"SOC 2 Availability Assessment","type":"workflow","url":"/assets/agent_record-wf-d11-12a96993.6c739f497bc7bcc8.json"},{"attributes":{"department":"internal-audit","domain":"audit","lineOfDefense":"assure"},"canonicalUrl":"https://workflow-library.com/all/?w=audit-soc2-type2-interim-testing","description":"Interim fieldwork for the Type II examination: cycle walkthroughs, design assessment against the Trust Services Criteria, the first operating-effectiveness testing wave over the agreed interim evidence window, and exception triage feeding remediation and retest planning before the period closes. Interim SOC 2 Type II fieldwork for the listed control selections and agreed interim window. Later-period testing and the service auditor's independent opinion remain outside this module. Attach this workflow to the existing audit engagement item; retain evidence and conclusions on its workflow steps.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=audit-soc2-type2-interim-testing","capabilities":[],"controls":["UC-ACCESS-01","UC-ACCESS-02","UC-ACCESS-03","UC-ACCESS-09","UC-BCDR-03","UC-BCDR-10","UC-CONFIG-01","UC-CONFIG-02","UC-CRYPTO-01","UC-GOV-16","UC-GOV-21","UC-HR-01","UC-IR-06","UC-IR-10","UC-LOG-01","UC-RISK-14","UC-TRAIN-01","UC-VULN-03"],"domains":["audit"],"lineOfDefense":"assure","mappingStatus":"mapped","releaseId":"sha256:26d1ded689c4f18e7d13568fab54fde2e1caa585cc01e7820226c793cfd2b175","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:audit-soc2-type2-interim-testing","standards":["soc2"],"teams":["internal-audit"]},"direct":false,"htmlUrl":"/agents/records/wf-d24-a9f3daf6.html","id":"wf:D24","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AD24","slug":"audit-soc2-type2-interim-testing","sourceIds":["aiuc-1","cobit-2019","coso-erm","coso-ic","dora","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"SOC 2 Type II Interim Testing","type":"workflow","url":"/assets/agent_record-wf-d24-a9f3daf6.9ed11f6a49666f17.json"},{"attributes":{"department":"procurement","domain":"grc","lineOfDefense":"monitor"},"canonicalUrl":"https://workflow-library.com/all/?w=grc-third-party-vendor-risk-lifecycle","description":"Operate the third-party vendor risk lifecycle end to end: scope and tier the vendor population, gather and analyze assurance evidence (SOC reports and CUECs, plus C-SCRM controls), embed contractual protections, enroll ongoing monitoring, and reach a governed disposition and approval. The vendor register IS the set of Vendor items — tiered by criticality (tier) and data exposure (data_classification), owned (business_owner, risk_owner), and driven by reassessment_cadence with last/next assessment dates and monitoring_status; each assessment cycle runs as one workflow instance over that register. In scope: vendor and supplier third-party risk assessment, onboarding controls, and periodic reassessment. Out of scope: procurement sourcing and commercial negotiation, and the deeper fieldwork of a Third-Party Vendor Assurance Engagement, to which the approved package is handed off. This workflow is self-initiating and consumes no upstream workflow package.","details":{"canonicalUrl":"https://workflow-library.com/all/?w=grc-third-party-vendor-risk-lifecycle","capabilities":[],"controls":["UC-TPRM-01","UC-TPRM-02","UC-TPRM-03","UC-TPRM-04","UC-ASSET-05","UC-ACCESS-21","UC-DATA-16","UC-HR-05","UC-LOG-09","UC-SDLC-10","UC-TPRM-05","UC-TPRM-06","UC-TPRM-07","UC-TPRM-09","UC-TPRM-08"],"domains":["grc"],"lineOfDefense":"monitor","mappingStatus":"mapped","releaseId":"sha256:96f9e2a2333ab1b869a093e9ffa77920c2a18e3719304346f9daebe8bc6ce5fa","roleIntegrity":{"activityCount":0,"ermPhases":[],"lineRoles":[],"serviceModes":[],"warnings":[]},"sourceTemplateId":"workflow-library:grc-third-party-vendor-risk-lifecycle","standards":["nist-800-53","soc2"],"teams":["procurement"]},"direct":false,"htmlUrl":"/agents/records/wf-g13-0f34ff59.html","id":"wf:G13","mapUrl":"https://controlsmap.com/?v=1&node=wf%3AG13","slug":"grc-third-party-vendor-risk-lifecycle","sourceIds":["aiuc-1","ccpa","cobit-2019","dora","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"Third-Party Vendor Risk Lifecycle","type":"workflow","url":"/assets/agent_record-wf-g13-0f34ff59.4e127df71d98cfe8.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:06766bcaa97fc503e3075bacd5a32b70ca02cddb5723c7adb91b171d249be995","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","targetId":"uc:UC-TPRM-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:06ae859dddd555345768d16603e34a8b7d27ae8eb414b92a5b8727feeeb6b1e9","properties":{},"sourceDetailPath":"/data/v1/records/wf-g29-6f0c8a46.json","sourceId":"wf:G29","targetDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","targetId":"uc:UC-TPRM-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1d531e42d1d715ed599e863ffe36bae6966a39a6b05d5b0d83bc9e66693e2a39","properties":{"rationale":"annual exercises, failover/restore tests, and gap remediation directly cure the untested-plan condition","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","sourceId":"uc:UC-BCDR-10","targetDetailPath":"/data/v1/records/risk-bcdr-no-tested-continuity-plan-d4d9e7a9.json","targetId":"risk:bcdr-no-tested-continuity-plan","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:22ff62f8a198d23e64dcf7728f0b1a4bdb22d1834ffcd2ebcdcb9e01463e5300","properties":{"rationale":"training all contingency-role personnel reduces single-person dependency for recovery execution","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","sourceId":"uc:UC-BCDR-10","targetDetailPath":"/data/v1/records/risk-hr-talent-loss-succession-50c0fc0a.json","targetId":"risk:hr-talent-loss-succession","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:25fdc78599966b3c35b4a301474a3d8a4d7073c9d219ea65459dba52b7850ef4","properties":{"rationale":"incident response restores and problem management drives permanent fixes for recurring equipment faults","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/risk-tech-hardware-equipment-failure-25948451.json","targetId":"risk:tech-hardware-equipment-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2a4cb1cf4b3bc12321bc556ef2ef799ae4d99a2cacb64894f72cffffad144d4b","properties":{"rationale":"testing failover/restore and remediating gaps reduces the likelihood that DR fails to activate in a real outage","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","sourceId":"uc:UC-BCDR-10","targetDetailPath":"/data/v1/records/risk-bcdr-it-resilience-outage-18dfc108.json","targetId":"risk:bcdr-it-resilience-outage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2e1dd368ab61117184f962a4423da9347a8dc7bd50f9574314804ebded1af983","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-dora-dora-art28-44-d3e89c89.json","sourceId":"ctrl:dora:DORA-Art28-44","targetDetailPath":"/data/v1/records/std-dora-95cf939d.json","targetId":"std:dora","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:311639e86b776f3f168a0b4f45e79accc724e13dd8882b4898685f949d3cabc3","properties":{"rationale":"Exchanging IOCs/TTPs gives early warning of novel exploits, but the sharing arrangement feeds detection/blocking rather than itself being the operative zero-day defense.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-16-462251f1.json","sourceId":"uc:UC-BCDR-16","targetDetailPath":"/data/v1/records/risk-vuln-zero-day-a821d603.json","targetId":"risk:vuln-zero-day","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:31568ab19606852875865ba961cec39ec0856b3bd2b22a3694bdbd7d5927c900","properties":{},"sourceDetailPath":"/data/v1/records/wf-r6-824a647c.json","sourceId":"wf:R6","targetDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","targetId":"uc:UC-TPRM-01","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:34442316db48f111db9f970498059929690de3050b20fcf535d7a55c5ad0f887","properties":{"control_id":"DORA-Art5","coverage":"full","delta":null,"framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-02-2a51c24c.json","sourceId":"uc:UC-BCDR-02","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art5-3d1842f7.json","targetId":"ctrl:dora:DORA-Art5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:435470550375d418dcc629b659104f189e5fcbbef8cdb77b62204259ad3388e1","properties":{"control_id":"DORA-Art45","coverage":"full","delta":null,"framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-16-462251f1.json","sourceId":"uc:UC-BCDR-16","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art45-bb72d2e3.json","targetId":"ctrl:dora:DORA-Art45","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:443f786d43ee6948e95374e37c50e83b401cf7827e8bdb8d7420e4abd2529647","properties":{"rationale":"Embedding security requirements and audit/access rights, reviewing service agreements and supplier performance, and reassessing on a cycle directly counters unmonitored, unbound suppliers.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4563542ddc82224ac1112c258485ce77febeec9fa9f0a8eaf3a33969254150ee","properties":{},"sourceDetailPath":"/data/v1/records/wf-a7-454c1d0e.json","sourceId":"wf:A7","targetDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","targetId":"uc:UC-TPRM-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5471ca0c7cf01ea72d5ed6a32d4530a092810cff89582f846be3c055c2f80315","properties":{"rationale":"the framework requires a defined resilience/recovery strategy, driving plans to exist","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-02-2a51c24c.json","sourceId":"uc:UC-BCDR-02","targetDetailPath":"/data/v1/records/risk-bcdr-no-tested-continuity-plan-d4d9e7a9.json","targetId":"risk:bcdr-no-tested-continuity-plan","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:56dfe103e06ba3e03327b976baf2e7ccda67ac05f21e445799bcd6d251284b07","properties":{"rationale":"Assessing concentration and substitutability and maintaining exit strategies reduces the impact of a disrupted critical-input supplier.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-disruption-0d7e0959.json","targetId":"risk:tprm-supply-chain-disruption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5cf49ff3f7e015288403566f84e98c82474a60673fae3931772be04b75b4d8ec","properties":{"rationale":"incident response restores service within SLAs and root-cause problem resolution reduces outage duration and recurrence","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/risk-bcdr-it-resilience-outage-18dfc108.json","targetId":"risk:bcdr-it-resilience-outage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6053c30f7892043bff62bcc4400882c794555c1031daf2351b4c1af6bc5883cf","properties":{"rationale":"Shared malware indicators of compromise enable detection and blocking of known campaigns.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-16-462251f1.json","sourceId":"uc:UC-BCDR-16","targetDetailPath":"/data/v1/records/risk-sdlc-malware-injection-compromise-ec5a8dc4.json","targetId":"risk:sdlc-malware-injection-compromise","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:61400058960e74453bf67e913c8094529fa4804cb7f815ff211aeb01a0421dca","properties":{},"sourceDetailPath":"/data/v1/records/wf-d24-a9f3daf6.json","sourceId":"wf:D24","targetDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","targetId":"uc:UC-BCDR-10","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:69a6c7f9bed48e02129fbab011819e3d8abc7f7cd2f0680cee3c0301c965118b","properties":{"rationale":"Assessing criticality, substitutability, and concentration before contracting and maintaining tested exit strategies for critical providers is the core defense against vendor failure and concentration.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-tprm-critical-vendor-failure-cb39c2bc.json","targetId":"risk:tprm-critical-vendor-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:72ba8a5abe71532bacbb0d85adcf0d79ccb88c653f130984008cbbcfc38f3075","properties":{"rationale":"Concentration/substitutability assessment and exit strategies reduce the impact of geopolitically-driven supplier and supply-chain disruption.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-strategic-geopolitical-4e7aba30.json","targetId":"risk:strategic-geopolitical","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7424483991072df36e59cd4612f8fd1b705a42b41bd7c4eb5e452b390e2d9672","properties":{"rationale":"logging, escalating, and root-causing incidents directly resolves and prevents recurring software failures","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/risk-tech-software-system-failure-2e2c5364.json","targetId":"risk:tech-software-system-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:85e3fe15b6aecae5530dd0e132ddcc858e1e6040ce834f04a59cf58b13927548","properties":{},"sourceDetailPath":"/data/v1/records/wf-c14-c6170cdd.json","sourceId":"wf:C14","targetDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","targetId":"uc:UC-BCDR-10","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:875cfbac8df6a236a2e1428c73589c803433cea9a99404efd5a39e80e7f3dab9","properties":{},"sourceDetailPath":"/data/v1/records/wf-d11-12a96993.json","sourceId":"wf:D11","targetDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","targetId":"uc:UC-BCDR-10","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8b9de4df2b9b11f4758d16caba3a14418486d52562080438d56995febeaf4511","properties":{"control_id":"DORA-Art17-23","coverage":"partial","delta":"major-incident report clocks: initial 24h, intermediate 72h, final 1 month","framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art17-23-9aa7977f.json","targetId":"ctrl:dora:DORA-Art17-23","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9db04fad46758b81ec779f5584e60874a16ab5fca9f18a03cf7cab7a292bda84","properties":{},"sourceDetailPath":"/data/v1/records/wf-g13-0f34ff59.json","sourceId":"wf:G13","targetDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","targetId":"uc:UC-TPRM-01","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9f229e45003f2c7c825f7932294437466bf8be9e39c6c4ab0bcb25d8dc6b2192","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-dora-dora-art17-23-9aa7977f.json","sourceId":"ctrl:dora:DORA-Art17-23","targetDetailPath":"/data/v1/records/std-dora-95cf939d.json","targetId":"std:dora","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9f4c9e165d71a26a8ae4396e5317ceb0d2d2a2e344201e8ad906a161ee1f775f","properties":{},"sourceDetailPath":"/data/v1/records/wf-c3-4a88b225.json","sourceId":"wf:C3","targetDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","targetId":"uc:UC-BCDR-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9fcbba45083adb3c7c068d3856009702ed3be50e4a02d006813495f938215166","properties":{},"sourceDetailPath":"/data/v1/records/wf-c2-a1078981.json","sourceId":"wf:C2","targetDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","targetId":"uc:UC-TPRM-01","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a823227bef104ee8b1ec5e45cf9214e64c74bbba8b49797e77874e3716a32f26","properties":{"rationale":"severity-based incident response contains and escalates a ransomware event toward restoration","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/risk-sdlc-ransomware-32ab67f4.json","targetId":"risk:sdlc-ransomware","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ab09fdd190f6cccbc1b587f3d1c1f50feab2ec3ed9a3c01937de1dd3cf6522c0","properties":{},"sourceDetailPath":"/data/v1/records/wf-g16-694f4e2b.json","sourceId":"wf:G16","targetDetailPath":"/data/v1/records/uc-uc-bcdr-02-2a51c24c.json","targetId":"uc:UC-BCDR-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b0f240d0bb2e0ebdc690ff63fa6b509a1063b8fad26027a37b7d9e376b2fe859","properties":{"rationale":"Risk-based due diligence, a criticality-ranked register, sub-outsourcing conditions, and reassessment reduce the N-tier compliance-failure exposure driving vicarious liability.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-tprm-vendor-compliance-vicarious-liability-0215657c.json","targetId":"risk:tprm-vendor-compliance-vicarious-liability","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b3bfaef213094c94a8d4b5b1d32b765d8d25c6a7c1bf939b43b5927b5e690830","properties":{"control_id":"DORA-Ch2","coverage":"partial","delta":"detailed protection, backup, and recovery capabilities implemented via companion controls","framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-02-2a51c24c.json","sourceId":"uc:UC-BCDR-02","targetDetailPath":"/data/v1/records/ctrl-dora-dora-ch2-891a747a.json","targetId":"ctrl:dora:DORA-Ch2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bb8674403229a0ce2c5ec8c9080da85bd8087859e0a852a85af0bac50d670a98","properties":{"control_id":"DORA-Art24-27","coverage":"partial","delta":"vulnerability assessments and the Art 25 security-testing catalogue satisfied by companion controls; TLPT regime specifics - three-yearly cadence, authority-approved scope, independent/certified testers (Arts 26-27), and tester independence (Art 24(4)) - require dedicated controls","framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","sourceId":"uc:UC-BCDR-10","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art24-27-dc4b8836.json","targetId":"ctrl:dora:DORA-Art24-27","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ccd0e376207f2decfe033433db539cafbba762a294aff5120dfa29a56d500050","properties":{"rationale":"Defining, agreeing, and reviewing service agreements and supplier performance and operating lifecycle controls to address weaknesses directly targets non-performance.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-tprm-vendor-service-nonperformance-081f2fb9.json","targetId":"risk:tprm-vendor-service-nonperformance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cff1193b4288fe551157bf960ab5acccac13ae290735955d5c5e704f34cab9db","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-dora-dora-art24-27-dc4b8836.json","sourceId":"ctrl:dora:DORA-Art24-27","targetDetailPath":"/data/v1/records/std-dora-95cf939d.json","targetId":"std:dora","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d01f94392dc563be0aa2b00b6b75d9fc39ee97811b15eb3cf2774047f5b49b79","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-dora-dora-art45-bb72d2e3.json","sourceId":"ctrl:dora:DORA-Art45","targetDetailPath":"/data/v1/records/std-dora-95cf939d.json","targetId":"std:dora","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d0efb67e45137161ae9555ed37f5b450841d2a542b5fa69f548eae823032d61c","properties":{},"sourceDetailPath":"/data/v1/records/wf-g7-9762f11b.json","sourceId":"wf:G7","targetDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","targetId":"uc:UC-BCDR-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d1bc3d44abfcb1b212921d6c5e3323d0b33cf5166e5957cd9e0d160834fac695","properties":{"rationale":"A criticality-ranked third-party register plus concentration and exit-strategy assessment applies to AI API providers, reducing concentration and outage impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-ai-supply-chain-concentration-9f791f54.json","targetId":"risk:ai-supply-chain-concentration","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d55547e0001aae58a60b2bb584f30c2d2c4026873922f47cfc850a87b0365ac9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-dora-dora-ch2-891a747a.json","sourceId":"ctrl:dora:DORA-Ch2","targetDetailPath":"/data/v1/records/std-dora-95cf939d.json","targetId":"std:dora","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d7cc1f08f27b6315ce2ec5eed4c8b0a4dc59776e29cddc1c7873e1fdeecb6d99","properties":{"rationale":"Assessing concentration risk and maintaining exit strategies for critical providers reduces the ecosystem single-point-of-failure impact from GPAI-capability concentration.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-ai-gpai-systemic-transparency-7a746323.json","targetId":"risk:ai-gpai-systemic-transparency","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f2e2e7b72bc628ac1dc26cf6544d63f62633d9a1276598c3474fe2e52c916f16","properties":{"control_id":"DORA-Art28-44","coverage":"partial","delta":"DORA-specific regulator obligations (register of information format, competent-authority/Lead Overseer interactions) beyond the general third-party program","framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art28-44-d3e89c89.json","targetId":"ctrl:dora:DORA-Art28-44","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f4d07480aabe1493dc9b848172945bf621c47b3b1dab36fc4f82036e2e06e7c9","properties":{},"sourceDetailPath":"/data/v1/records/wf-c20-5b99e185.json","sourceId":"wf:C20","targetDetailPath":"/data/v1/records/uc-uc-bcdr-16-462251f1.json","targetId":"uc:UC-BCDR-16","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f66a5d84c2198ce10ae46c518865b71602dfe108a6aba6146c1e13c57af60f77","properties":{"rationale":"Shared alerts on actively-exploited known vulnerabilities drive prioritized remediation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-16-462251f1.json","sourceId":"uc:UC-BCDR-16","targetDetailPath":"/data/v1/records/risk-vuln-unpatched-known-flaws-c4a6b075.json","targetId":"risk:vuln-unpatched-known-flaws","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f8a5ee844e2fad35f8c77e9177a20cab901b502a00aa51b12b1b7fd1ffeac03d","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-dora-dora-art5-3d1842f7.json","sourceId":"ctrl:dora:DORA-Art5","targetDetailPath":"/data/v1/records/std-dora-95cf939d.json","targetId":"std:dora","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fb1605fa71e8c698225f13730978a2d1108c3677adb1265b2e61f81525255a57","properties":{"rationale":"incident detection and escalation mitigate an ongoing denial-of-service event","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/risk-net-denial-of-service-934ccd7f.json","targetId":"risk:net-denial-of-service","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fdb80f611ab2725bcc785362922bc7bee39deb4409fb99d59e8a1653639a67c8","properties":{},"sourceDetailPath":"/data/v1/records/wf-c80-7d360115.json","sourceId":"wf:C80","targetDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","targetId":"uc:UC-BCDR-06","type":"operates"}],"schemaVersion":1,"scope":"sources","total":44}
