{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["risk:ai-gpai-systemic-transparency","risk:ai-supply-chain-concentration","risk:compliance-improper-market-practices","risk:compliance-litigation-enforcement","risk:compliance-no-independent-audit","risk:esg-climate-transition","risk:fin-icfr-material-weakness","risk:fraud-internal-misappropriation","risk:gov-oversight-failure","risk:gov-policy-absent","risk:reputational-brand-crisis","risk:strategic-geopolitical","risk:tprm-critical-vendor-failure","risk:tprm-supply-chain-disruption","risk:tprm-vendor-compliance-vicarious-liability","risk:tprm-vendor-service-nonperformance","risk:tprm-weak-supplier-oversight","uc:UC-GOV-05","uc:UC-GOV-14","uc:UC-GOV-22","uc:UC-GOV-24","uc:UC-GOV-29","uc:UC-GOV-31","uc:UC-GOV-32","uc:UC-GOV-34","uc:UC-GOV-35","uc:UC-GOV-36"],"directIds":["ctrl:nis2:NIS2-Art20","ctrl:nis2:NIS2-Art21a","ctrl:nis2:NIS2-Art21b","ctrl:nis2:NIS2-Art21c","ctrl:nis2:NIS2-Art21d","ctrl:nis2:NIS2-Art21e","ctrl:nis2:NIS2-Art21f","ctrl:nis2:NIS2-Art21g","ctrl:nis2:NIS2-Art21h","ctrl:nis2:NIS2-Art21i","ctrl:nis2:NIS2-Art21j","ctrl:nis2:NIS2-Art23","std:nis2"],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"EU NIS2","next":"/assets/agent_sources-nis2-2.ca2b4bf2d36bea3d.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"administrative","framework":"nis2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nis2/","description":"Governance and management body accountability / training","details":{"automation":"manual","control_category":"administrative","control_id":"NIS2-Art20","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Incident Management & Response","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Secure Development (SDLC) & Application Security","Cryptography & Key Management","Access Control & Identity Management","Awareness & Training","Logging, Monitoring & Detection"],"framework":"nis2","group":"EU NIS2 Directive","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-nis2-nis2-art20-28d702ac.html","id":"ctrl:nis2:NIS2-Art20","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anis2%3ANIS2-Art20","sourceIds":["nis2"],"sourceUrl":null,"title":"NIS2-Art20 — Governance and management body accountability / training","type":"control","url":"/assets/agent_record-ctrl-nis2-nis2-art20-28d702ac.c7873708ff6a8836.json"},{"attributes":{"category":"administrative","framework":"nis2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nis2/","description":"Policies on risk analysis and information system security","details":{"automation":"manual","control_category":"administrative","control_id":"NIS2-Art21a","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Incident Management & Response","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Secure Development (SDLC) & Application Security","Cryptography & Key Management","Access Control & Identity Management","Awareness & Training","Logging, Monitoring & Detection"],"framework":"nis2","group":"EU NIS2 Directive","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-nis2-nis2-art21a-1dbcc08c.html","id":"ctrl:nis2:NIS2-Art21a","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anis2%3ANIS2-Art21a","sourceIds":["nis2"],"sourceUrl":null,"title":"NIS2-Art21a — Policies on risk analysis and information system security","type":"control","url":"/assets/agent_record-ctrl-nis2-nis2-art21a-1dbcc08c.e14adc670152a901.json"},{"attributes":{"category":"administrative","framework":"nis2","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/nis2/","description":"Incident handling","details":{"automation":"hybrid","control_category":"administrative","control_id":"NIS2-Art21b","control_type":"corrective","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Incident Management & Response","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Secure Development (SDLC) & Application Security","Cryptography & Key Management","Access Control & Identity Management","Awareness & Training","Logging, Monitoring & Detection"],"framework":"nis2","group":"EU NIS2 Directive","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-nis2-nis2-art21b-0635d82d.html","id":"ctrl:nis2:NIS2-Art21b","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anis2%3ANIS2-Art21b","sourceIds":["nis2"],"sourceUrl":null,"title":"NIS2-Art21b — Incident handling","type":"control","url":"/assets/agent_record-ctrl-nis2-nis2-art21b-0635d82d.0807ca2f15c4daab.json"},{"attributes":{"category":"administrative","framework":"nis2","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/nis2/","description":"Business continuity, backup management and disaster recovery, crisis management","details":{"automation":"hybrid","control_category":"administrative","control_id":"NIS2-Art21c","control_type":"corrective","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Incident Management & Response","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Secure Development (SDLC) & Application Security","Cryptography & Key Management","Access Control & Identity Management","Awareness & Training","Logging, Monitoring & Detection"],"framework":"nis2","group":"EU NIS2 Directive","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-nis2-nis2-art21c-18adf13b.html","id":"ctrl:nis2:NIS2-Art21c","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anis2%3ANIS2-Art21c","sourceIds":["nis2"],"sourceUrl":null,"title":"NIS2-Art21c — Business continuity, backup management and disaster recovery, crisis management","type":"control","url":"/assets/agent_record-ctrl-nis2-nis2-art21c-18adf13b.17c9c7a0a2870ada.json"},{"attributes":{"category":"administrative","framework":"nis2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nis2/","description":"Supply chain security","details":{"automation":"manual","control_category":"administrative","control_id":"NIS2-Art21d","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Incident Management & Response","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Secure Development (SDLC) & Application Security","Cryptography & Key Management","Access Control & Identity Management","Awareness & Training","Logging, Monitoring & Detection"],"framework":"nis2","group":"EU NIS2 Directive","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-nis2-nis2-art21d-9b82b64b.html","id":"ctrl:nis2:NIS2-Art21d","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anis2%3ANIS2-Art21d","sourceIds":["nis2"],"sourceUrl":null,"title":"NIS2-Art21d — Supply chain security","type":"control","url":"/assets/agent_record-ctrl-nis2-nis2-art21d-9b82b64b.97613441d4c992df.json"},{"attributes":{"category":"technical","framework":"nis2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nis2/","description":"Security in acquisition, development and maintenance of network and information systems (incl. vulnerability handling and disclosure)","details":{"automation":"hybrid","control_category":"technical","control_id":"NIS2-Art21e","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Incident Management & Response","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Secure Development (SDLC) & Application Security","Cryptography & Key Management","Access Control & Identity Management","Awareness & Training","Logging, Monitoring & Detection"],"framework":"nis2","group":"EU NIS2 Directive","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-nis2-nis2-art21e-ae62ba80.html","id":"ctrl:nis2:NIS2-Art21e","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anis2%3ANIS2-Art21e","sourceIds":["nis2"],"sourceUrl":null,"title":"NIS2-Art21e — Security in acquisition, development and maintenance of network and information systems (incl. vulnerability handling and disclosure)","type":"control","url":"/assets/agent_record-ctrl-nis2-nis2-art21e-ae62ba80.8878a515f587104a.json"},{"attributes":{"category":"administrative","framework":"nis2","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/nis2/","description":"Policies and procedures to assess the effectiveness of cybersecurity risk-management measures","details":{"automation":"manual","control_category":"administrative","control_id":"NIS2-Art21f","control_type":"detective","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Incident Management & Response","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Secure Development (SDLC) & Application Security","Cryptography & Key Management","Access Control & Identity Management","Awareness & Training","Logging, Monitoring & Detection"],"framework":"nis2","group":"EU NIS2 Directive","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-nis2-nis2-art21f-a9a69314.html","id":"ctrl:nis2:NIS2-Art21f","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anis2%3ANIS2-Art21f","sourceIds":["nis2"],"sourceUrl":null,"title":"NIS2-Art21f — Policies and procedures to assess the effectiveness of cybersecurity risk-management measures","type":"control","url":"/assets/agent_record-ctrl-nis2-nis2-art21f-a9a69314.21c37d41bf487458.json"},{"attributes":{"category":"administrative","framework":"nis2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nis2/","description":"Basic cyber hygiene practices and cybersecurity training","details":{"automation":"manual","control_category":"administrative","control_id":"NIS2-Art21g","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Incident Management & Response","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Secure Development (SDLC) & Application Security","Cryptography & Key Management","Access Control & Identity Management","Awareness & Training","Logging, Monitoring & Detection"],"framework":"nis2","group":"EU NIS2 Directive","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-nis2-nis2-art21g-6280385a.html","id":"ctrl:nis2:NIS2-Art21g","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anis2%3ANIS2-Art21g","sourceIds":["nis2"],"sourceUrl":null,"title":"NIS2-Art21g — Basic cyber hygiene practices and cybersecurity training","type":"control","url":"/assets/agent_record-ctrl-nis2-nis2-art21g-6280385a.a6de8a00c8c07fab.json"},{"attributes":{"category":"technical","framework":"nis2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nis2/","description":"Policies on the use of cryptography and encryption","details":{"automation":"hybrid","control_category":"technical","control_id":"NIS2-Art21h","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Incident Management & Response","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Secure Development (SDLC) & Application Security","Cryptography & Key Management","Access Control & Identity Management","Awareness & Training","Logging, Monitoring & Detection"],"framework":"nis2","group":"EU NIS2 Directive","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-nis2-nis2-art21h-59950523.html","id":"ctrl:nis2:NIS2-Art21h","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anis2%3ANIS2-Art21h","sourceIds":["nis2"],"sourceUrl":null,"title":"NIS2-Art21h — Policies on the use of cryptography and encryption","type":"control","url":"/assets/agent_record-ctrl-nis2-nis2-art21h-59950523.ae2b225394e4b134.json"},{"attributes":{"category":"administrative","framework":"nis2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nis2/","description":"Human resources security, access control policies and asset management","details":{"automation":"manual","control_category":"administrative","control_id":"NIS2-Art21i","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Incident Management & Response","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Secure Development (SDLC) & Application Security","Cryptography & Key Management","Access Control & Identity Management","Awareness & Training","Logging, Monitoring & Detection"],"framework":"nis2","group":"EU NIS2 Directive","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-nis2-nis2-art21i-d5158327.html","id":"ctrl:nis2:NIS2-Art21i","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anis2%3ANIS2-Art21i","sourceIds":["nis2"],"sourceUrl":null,"title":"NIS2-Art21i — Human resources security, access control policies and asset management","type":"control","url":"/assets/agent_record-ctrl-nis2-nis2-art21i-d5158327.a3d21487b9d14dae.json"},{"attributes":{"category":"technical","framework":"nis2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nis2/","description":"Use of multi-factor authentication, secured communications and emergency communication systems","details":{"automation":"automated","control_category":"technical","control_id":"NIS2-Art21j","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Incident Management & Response","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Secure Development (SDLC) & Application Security","Cryptography & Key Management","Access Control & Identity Management","Awareness & Training","Logging, Monitoring & Detection"],"framework":"nis2","group":"EU NIS2 Directive","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-nis2-nis2-art21j-49982c35.html","id":"ctrl:nis2:NIS2-Art21j","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anis2%3ANIS2-Art21j","sourceIds":["nis2"],"sourceUrl":null,"title":"NIS2-Art21j — Use of multi-factor authentication, secured communications and emergency communication systems","type":"control","url":"/assets/agent_record-ctrl-nis2-nis2-art21j-49982c35.c50aa6551d5e3ec3.json"},{"attributes":{"category":"administrative","framework":"nis2","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/nis2/","description":"Reporting obligations (early warning 24h, incident notification 72h, final report 1 month)","details":{"automation":"manual","control_category":"administrative","control_id":"NIS2-Art23","control_type":"corrective","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Incident Management & Response","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Secure Development (SDLC) & Application Security","Cryptography & Key Management","Access Control & Identity Management","Awareness & Training","Logging, Monitoring & Detection"],"framework":"nis2","group":"EU NIS2 Directive","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-nis2-nis2-art23-93f21077.html","id":"ctrl:nis2:NIS2-Art23","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anis2%3ANIS2-Art23","sourceIds":["nis2"],"sourceUrl":null,"title":"NIS2-Art23 — Reporting obligations (early warning 24h, incident notification 72h, final report 1 month)","type":"control","url":"/assets/agent_record-ctrl-nis2-nis2-art23-93f21077.2355f43f83a026d5.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Third-Party / Supply-Chain Risk","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["eu-ai-act-risk","nist-ai-rmf-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-gpai-systemic-transparency","description":"GPAI providers failing transparency/copyright/training-data obligations; systemic-risk models (>10^25 FLOPs) lacking red-teaming, incident reporting, and cybersecurity; unlabeled deepfake/synthetic content; and concentration of GPAI capability creating ecosystem single points of failure.","details":{"category":"ai_governance","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"ai-gpai-systemic-transparency","taxonomies":["eu-ai-act-risk","nist-ai-rmf-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-gpai-systemic-transparency-7a746323.html","id":"risk:ai-gpai-systemic-transparency","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-gpai-systemic-transparency","sourceIds":["aiuc-1","cobit-2019","dora","eu-ai-act","iso-27001","iso-42001","nis2","nist-800-53","nist-csf-2","nydfs-500"],"sourceUrl":null,"title":"GPAI transparency, systemic-risk and synthetic-content obligations","type":"risk","url":"/assets/agent_record-risk-ai-gpai-systemic-transparency-7a746323.6e7a571abe779b08.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Third-Party / Supply-Chain Risk","Secure Development (SDLC) & Application Security"],"inherent_rating":"high","taxonomy":["nist-ai-rmf-risk","iso-23894-ai-risk","eu-ai-act-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-supply-chain-concentration","description":"Because the organization relies on third-party pretrained models, datasets, and libraries that may carry backdoors, malicious code, or bias, and concentrates on a few external AI API providers, AI-dependent workflows are exposed to both supply-chain compromise and provider outage or insolvency, resulting in compromised model behaviour or sudden loss of AI capability.","details":{"category":"ai_governance","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"ai-supply-chain-concentration","taxonomies":["nist-ai-rmf-risk","iso-23894-ai-risk","eu-ai-act-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-supply-chain-concentration-9f791f54.html","id":"risk:ai-supply-chain-concentration","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-supply-chain-concentration","sourceIds":["aiuc-1","cobit-2019","dora","eu-ai-act","iso-27001","iso-42001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2"],"sourceUrl":null,"title":"AI supply-chain compromise and provider concentration","type":"risk","url":"/assets/agent_record-risk-ai-supply-chain-concentration-9f791f54.263d1eb3adc4c1e2.json"},{"attributes":{"category":"compliance_regulatory","domain":["Compliance, Audit & Assurance","Governance, Policy & Oversight"],"inherent_rating":"high","taxonomy":["basel-operational-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-improper-market-practices","description":"Losses from antitrust violations, market manipulation (spoofing, layering, front-running), benchmark/rate rigging, unlicensed business activity, and sanctions/export-control violations in the conduct of business.","details":{"category":"compliance_regulatory","impact":"high","inherent_rating":"high","likelihood":"low","risk_id":"compliance-improper-market-practices","taxonomies":["basel-operational-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-compliance-improper-market-practices-9c55cfe9.html","id":"risk:compliance-improper-market-practices","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-improper-market-practices","sourceIds":["cobit-2019","coso-erm","iso-27001","nis2","nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"Improper business or market practices","type":"risk","url":"/assets/agent_record-risk-compliance-improper-market-practices-9c55cfe9.1a777f734f0a201c.json"},{"attributes":{"category":"compliance_regulatory","domain":["Compliance, Audit & Assurance","Governance, Policy & Oversight"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-litigation-enforcement","description":"Adverse judgments, class actions, contract/IP disputes, government subpoenas, DOJ/FTC/SEC investigations, consent decrees, or deferred-prosecution agreements imposing penalties, remediation, and management distraction.","details":{"category":"compliance_regulatory","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"compliance-litigation-enforcement","taxonomies":["enterprise-risk","coso-erm-risk"],"treatment":"transfer"},"direct":false,"htmlUrl":"/agents/records/risk-compliance-litigation-enforcement-25e7935d.html","id":"risk:compliance-litigation-enforcement","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-litigation-enforcement","sourceIds":["cobit-2019","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Litigation, investigation and enforcement exposure","type":"risk","url":"/assets/agent_record-risk-compliance-litigation-enforcement-25e7935d.963b6cccfc52b94e.json"},{"attributes":{"category":"compliance_regulatory","domain":["Compliance, Audit & Assurance","Governance, Policy & Oversight"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-no-independent-audit","description":"Because independent internal and external audit and review of information security are not performed, control deficiencies and non-conformities are neither detected nor challenged, so weaknesses persist unremediated and management and the board lose reliable assurance over control effectiveness.","details":{"category":"compliance_regulatory","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"compliance-no-independent-audit","taxonomies":["iso-27005-vulnerability","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-compliance-no-independent-audit-9e1acf0f.html","id":"risk:compliance-no-independent-audit","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-no-independent-audit","sourceIds":["ccpa","cobit-2019","iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-27001","nis2","nist-800-53"],"sourceUrl":null,"title":"Lack of independent audit and compliance review","type":"risk","url":"/assets/agent_record-risk-compliance-no-independent-audit-9e1acf0f.8a44783c74772a6f.json"},{"attributes":{"category":"esg","domain":["Risk Assessment & Management","Governance, Policy & Oversight"],"inherent_rating":"medium","taxonomy":["enterprise-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aesg-climate-transition","description":"Carbon taxes, cap-and-trade, and mandatory Scope 1-2-3 reporting increase operating costs or strand carbon-intensive assets; failure to credibly plan a net-zero transition jeopardizes access to capital and changing consumer preferences.","details":{"category":"esg","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"esg-climate-transition","taxonomies":["enterprise-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-esg-climate-transition-35e73915.html","id":"risk:esg-climate-transition","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aesg-climate-transition","sourceIds":["iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2"],"sourceUrl":null,"title":"Climate transition risk — carbon pricing and stranded assets","type":"risk","url":"/assets/agent_record-risk-esg-climate-transition-35e73915.f51e44df8585499f.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"inherent_rating":"critical","taxonomy":["enterprise-risk","coso-erm-risk","sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-icfr-material-weakness","description":"Because internal control over financial reporting is not maintained effectively - material weaknesses undetected or undisclosed and certifications signed despite known deficiencies - financial statements may be materially misstated and filings delayed or restated, resulting in SEC enforcement, delisting, securities-fraud liability, and loss of investor confidence.","details":{"category":"financial_reporting","impact":"critical","inherent_rating":"critical","likelihood":"medium","risk_id":"fin-icfr-material-weakness","taxonomies":["enterprise-risk","coso-erm-risk","sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-icfr-material-weakness-cdd66323.html","id":"risk:fin-icfr-material-weakness","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-icfr-material-weakness","sourceIds":["cobit-2019","coso-erm","coso-ic","iia-2024","iso-27001","nis2","nist-800-53","nist-csf-2","soc2","sox"],"sourceUrl":null,"title":"Ineffective ICFR / undisclosed material weakness","type":"risk","url":"/assets/agent_record-risk-fin-icfr-material-weakness-cdd66323.c752785baa39846a.json"},{"attributes":{"category":"operational","domain":["Governance, Policy & Oversight","Financial Reporting Controls (SOX)","Risk Assessment & Management"],"inherent_rating":"high","taxonomy":["basel-operational-risk","coso-erm-risk","sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afraud-internal-misappropriation","description":"Employees defraud the entity for financial gain: embezzlement or theft of company/client funds, fraudulent expense/payroll claims, forgery to obtain unauthorized disbursements, bribery/kickback schemes, insider trading on own account, and wilful tax evasion.","details":{"category":"operational","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fraud-internal-misappropriation","taxonomies":["basel-operational-risk","coso-erm-risk","sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fraud-internal-misappropriation-d235cd10.html","id":"risk:fraud-internal-misappropriation","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afraud-internal-misappropriation","sourceIds":["coso-erm","coso-ic","iso-27001","nis2","nist-800-53","nist-csf-2","soc2","sox"],"sourceUrl":null,"title":"Internal fraud — asset misappropriation, embezzlement, forgery","type":"risk","url":"/assets/agent_record-risk-fraud-internal-misappropriation-d235cd10.340e455cacc8708f.json"},{"attributes":{"category":"strategic","domain":["Governance, Policy & Oversight","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["coso-erm-risk","iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Agov-oversight-failure","description":"Because board and management oversight of risk and control is weak - unclear tone at the top, ineffective board composition or independence, poor committee structure, and limited senior-management commitment - control priorities are not enforced and resources are withheld, so risks accumulate unmanaged and control failures go uncorrected across the entity.","details":{"category":"strategic","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"gov-oversight-failure","taxonomies":["coso-erm-risk","iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-gov-oversight-failure-d98ffc12.html","id":"risk:gov-oversight-failure","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Agov-oversight-failure","sourceIds":["cobit-2019","coso-erm","coso-ic","iia-2024","iia-pos-2026-erm","nis2","nist-csf-2","soc2","sox"],"sourceUrl":null,"title":"Inadequate board and management oversight of risk and control","type":"risk","url":"/assets/agent_record-risk-gov-oversight-failure-d98ffc12.e05fa5d3e4686a7a.json"},{"attributes":{"category":"compliance_regulatory","domain":["Governance, Policy & Oversight","Data Protection & Privacy"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Agov-policy-absent","description":"Because documented, approved, and enforced security and privacy policies are missing and roles and duties are undefined, personnel operate without guidance on required controls and behaviours, so controls are applied inconsistently and accountability gaps leave violations undetected and unaddressed.","details":{"category":"compliance_regulatory","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"gov-policy-absent","taxonomies":["iso-27005-vulnerability","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-gov-policy-absent-cf76dbbf.html","id":"risk:gov-policy-absent","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Agov-policy-absent","sourceIds":["cobit-2019","coso-erm","coso-ic","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Missing or insufficient security and privacy policies","type":"risk","url":"/assets/agent_record-risk-gov-policy-absent-cf76dbbf.643fca249d5d0d9c.json"},{"attributes":{"category":"reputational","domain":["Risk Assessment & Management","Governance, Policy & Oversight"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Areputational-brand-crisis","description":"Product-safety/quality failures, executive misconduct, data breaches, adverse media, or viral social-media/activist campaigns erode customer trust, investor confidence, partnerships, and brand equity — with long-term value loss exceeding near-term financial impact.","details":{"category":"reputational","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"reputational-brand-crisis","taxonomies":["enterprise-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-reputational-brand-crisis-4d7c293d.html","id":"risk:reputational-brand-crisis","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Areputational-brand-crisis","sourceIds":["coso-erm","coso-ic","gdpr","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2","sox"],"sourceUrl":null,"title":"Brand and reputational crisis","type":"risk","url":"/assets/agent_record-risk-reputational-brand-crisis-4d7c293d.ca86d666a4dadafe.json"},{"attributes":{"category":"strategic","domain":["Risk Assessment & Management","Third-Party / Supply-Chain Risk"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Astrategic-geopolitical","description":"Armed conflict, political instability, sanctions, trade-policy reversals (tariffs, export bans, data-localization, forced tech transfer), expropriation/nationalization, and adverse macroeconomic cycles disrupt operations, supply chains, and cost structures.","details":{"category":"strategic","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"strategic-geopolitical","taxonomies":["enterprise-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-strategic-geopolitical-4e7aba30.html","id":"risk:strategic-geopolitical","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Astrategic-geopolitical","sourceIds":["cobit-2019","coso-erm","coso-ic","dora","iso-27001","iso-31000","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2"],"sourceUrl":null,"title":"Geopolitical, macroeconomic and sovereign risk","type":"risk","url":"/assets/agent_record-risk-strategic-geopolitical-4e7aba30.21005b4da044225f.json"},{"attributes":{"category":"third_party","domain":["Third-Party / Supply-Chain Risk","Business Continuity & Disaster Recovery"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk","basel-operational-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-critical-vendor-failure","description":"A key supplier, SaaS provider, or outsourced partner becomes insolvent, exits the market, or suffers a prolonged outage; sole-source and shared-tier concentration (multiple tier-1 vendors on a common tier-2) creates hidden single points of failure with no backup.","details":{"category":"third_party","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"tprm-critical-vendor-failure","taxonomies":["enterprise-risk","coso-erm-risk","basel-operational-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tprm-critical-vendor-failure-cb39c2bc.html","id":"risk:tprm-critical-vendor-failure","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-critical-vendor-failure","sourceIds":["cobit-2019","dora","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"Critical vendor failure, insolvency or concentration","type":"risk","url":"/assets/agent_record-risk-tprm-critical-vendor-failure-cb39c2bc.40d00208e79dbc8a.json"},{"attributes":{"category":"operational","domain":["Third-Party / Supply-Chain Risk","Business Continuity & Disaster Recovery"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-supply-chain-disruption","description":"Geopolitical events, natural disasters, port congestion, or logistics failures interrupt supply of critical raw materials or components (semiconductors, rare earths); just-in-time models are exposed to demand spikes.","details":{"category":"operational","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"tprm-supply-chain-disruption","taxonomies":["enterprise-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tprm-supply-chain-disruption-0d7e0959.html","id":"risk:tprm-supply-chain-disruption","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-supply-chain-disruption","sourceIds":["cobit-2019","dora","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2"],"sourceUrl":null,"title":"Supply-chain disruption of critical inputs","type":"risk","url":"/assets/agent_record-risk-tprm-supply-chain-disruption-0d7e0959.3070d406a058fdb6.json"},{"attributes":{"category":"third_party","domain":["Third-Party / Supply-Chain Risk","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-vendor-compliance-vicarious-liability","description":"A vendor, subcontractor, or channel partner violates labor, environmental, anti-bribery (FCPA/UKBA), or data-protection rules, exposing the company to liability and reputational harm; fourth-party/N-tier dependencies are opaque.","details":{"category":"third_party","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"tprm-vendor-compliance-vicarious-liability","taxonomies":["enterprise-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tprm-vendor-compliance-vicarious-liability-0215657c.html","id":"risk:tprm-vendor-compliance-vicarious-liability","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-vendor-compliance-vicarious-liability","sourceIds":["ccpa","cobit-2019","dora","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"Third-party compliance failure creating vicarious liability","type":"risk","url":"/assets/agent_record-risk-tprm-vendor-compliance-vicarious-liability-0215657c.77578fe7de7d58ff.json"},{"attributes":{"category":"third_party","domain":["Third-Party / Supply-Chain Risk"],"inherent_rating":"medium","taxonomy":["basel-operational-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-vendor-service-nonperformance","description":"Outsourced processing, IT, payroll/HR, print/mail, or sub-custodian providers fail to meet service levels, deliver defective software, make incorrect payments, or breach contractual deliverables, causing processing errors, outages, and loss.","details":{"category":"third_party","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"tprm-vendor-service-nonperformance","taxonomies":["basel-operational-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tprm-vendor-service-nonperformance-081f2fb9.html","id":"risk:tprm-vendor-service-nonperformance","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-vendor-service-nonperformance","sourceIds":["ccpa","cobit-2019","dora","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"Vendor/outsourcing service non-performance and disputes","type":"risk","url":"/assets/agent_record-risk-tprm-vendor-service-nonperformance-081f2fb9.6aa8159a02796175.json"},{"attributes":{"category":"third_party","domain":["Third-Party / Supply-Chain Risk","Governance, Policy & Oversight"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-weak-supplier-oversight","description":"Because supplier contracts omit security requirements and SLAs and third-party service delivery is not monitored, processors and sub-processors operate without equivalent, audited obligations, so third-party weaknesses and breaches propagate into the organization undetected.","details":{"category":"third_party","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"tprm-weak-supplier-oversight","taxonomies":["iso-27005-vulnerability","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tprm-weak-supplier-oversight-1baaa012.html","id":"risk:tprm-weak-supplier-oversight","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atprm-weak-supplier-oversight","sourceIds":["ccpa","cobit-2019","dora","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"Weak supplier security requirements and monitoring","type":"risk","url":"/assets/agent_record-risk-tprm-weak-supplier-oversight-1baaa012.91f09390d6cc203e.json"},{"attributes":{"authority":"mandatory","category":"nis2"},"canonicalUrl":"https://controlsmap.com/frameworks/nis2/","description":"EU NIS2 Directive","details":{"amendmentState":"supplemented by Implementing Regulation (EU) 2024/2690 (digital-sector entities)","authority":"mandatory","effectiveDate":"2024-10-18 (transposition deadline 2024-10-17)","note":null,"propositions":[],"publicationDate":"2022-12-27","reviewed_at":null,"source_url":null,"version":"Directive (EU) 2022/2555"},"direct":true,"htmlUrl":"/agents/records/std-nis2-450f1237.html","id":"std:nis2","mapUrl":"https://controlsmap.com/?v=1&node=std%3Anis2","sourceIds":["nis2"],"sourceUrl":null,"title":"EU NIS2","type":"standard","url":"/assets/agent_record-std-nis2-450f1237.41b2107839f56aee.json"},{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-05","description":"The board of directors (or equivalent governing body), demonstrating independence from management and appropriate expertise, oversees the development and performance of internal control and the cybersecurity risk management program, approving the risk strategy and material policies. The board periodically reviews risk-management outcomes, program effectiveness, and management reporting, and directs adjustments to strategy and direction; oversight activities and decisions are documented in minutes and supporting materials.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"CC1.2","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"P2","coverage":"full","framework":"coso-ic","relationship":"superset_of"},{"control_id":"E1","coverage":"full","framework":"coso-erm","relationship":"superset_of"},{"control_id":"GV.OV-01","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"NIS2-Art20","coverage":"partial","delta":"management body members must approve measures and complete cybersecurity training","framework":"nis2","relationship":"intersects_with"}],"statement":"The board of directors (or equivalent governing body), demonstrating independence from management and appropriate expertise, oversees the development and performance of internal control and the cybersecurity risk management program, approving the risk strategy and material policies. The board periodically reviews risk-management outcomes, program effectiveness, and management reporting, and directs adjustments to strategy and direction; oversight activities and decisions are documented in minutes and supporting materials.","title":"Ensure board-level oversight of risk and internal control","unified_id":"UC-GOV-05"},"direct":false,"htmlUrl":"/agents/records/uc-uc-gov-05-b3a47944.html","id":"uc:UC-GOV-05","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-05","sourceIds":["coso-erm","coso-ic","nis2","nist-csf-2","soc2"],"sourceUrl":null,"title":"UC-GOV-05 — Ensure board-level oversight of risk and internal control","type":"unified","url":"/assets/agent_record-uc-uc-gov-05-b3a47944.1bb8a1cc590e84f0.json"},{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-14","description":"Establish, approve, publish, and maintain the organization's information-security policy suite as a governed whole: a top-level policy plus the topic-specific policies, each with an accountable owner, board/management approval, planned review cycles, and communication to relevant parties. Domain-specific policy content is governed by its own unified control; this objective owns the suite-level lifecycle (inventory, approval chain, review cadence, communication, exceptions).","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"A.5.1","coverage":"partial","delta":"Policies must also be acknowledged by relevant personnel and interested parties","framework":"iso-27001","relationship":"intersects_with"},{"control_id":"A.5.37","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"GV.PO-01","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"GV.PO-02","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"CC5.3","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"PL-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"500.3","coverage":"full","framework":"nydfs-500","relationship":"superset_of"},{"control_id":"NIS2-Art21a","coverage":"full","framework":"nis2","relationship":"superset_of"},{"control_id":"HIPAA-164.316","coverage":"full","framework":"hipaa","relationship":"superset_of"},{"control_id":"PCI-Req12","coverage":"partial","delta":"also requires awareness, screening, third-party management, and incident response program elements","framework":"pci-dss","relationship":"intersects_with"}],"statement":"Establish, approve, publish, and maintain the organization's information-security policy suite as a governed whole: a top-level policy plus the topic-specific policies, each with an accountable owner, board/management approval, planned review cycles, and communication to relevant parties. Domain-specific policy content is governed by its own unified control; this objective owns the suite-level lifecycle (inventory, approval chain, review cadence, communication, exceptions).","title":"Establish and maintain approved security policies and procedures","unified_id":"UC-GOV-14"},"direct":false,"htmlUrl":"/agents/records/uc-uc-gov-14-f4f2c470.html","id":"uc:UC-GOV-14","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-14","sourceIds":["hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"UC-GOV-14 — Establish and maintain approved security policies and procedures","type":"unified","url":"/assets/agent_record-uc-uc-gov-14-f4f2c470.c8b159b9592f605c.json"},{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-22","description":"Maintain a documented assessment and authorization policy with procedures, defined performance measures, and quality monitoring to regularly evaluate whether security policies, standards, and risk-management measures are implemented, complied with, and effective — including managers' reviews of compliance within their areas of responsibility. Feed assessment results into a formal, risk-based authorization process in which a senior official explicitly accepts residual risk before systems operate and at defined intervals thereafter, and track findings to closure.","details":{"control_category":"administrative","control_type":"detective","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"PM-6","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"CA-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PM-10","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.5.36","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"NIS2-Art21f","coverage":"full","framework":"nis2","relationship":"superset_of"},{"control_id":"APO11","coverage":"partial","delta":"embedding quality management practices across processes, projects, and deliverables","framework":"cobit-2019","relationship":"intersects_with"}],"statement":"Maintain a documented assessment and authorization policy with procedures, defined performance measures, and quality monitoring to regularly evaluate whether security policies, standards, and risk-management measures are implemented, complied with, and effective — including managers' reviews of compliance within their areas of responsibility. Feed assessment results into a formal, risk-based authorization process in which a senior official explicitly accepts residual risk before systems operate and at defined intervals thereafter, and track findings to closure.","title":"Assess control effectiveness and authorize systems","unified_id":"UC-GOV-22"},"direct":false,"htmlUrl":"/agents/records/uc-uc-gov-22-c0b503b4.html","id":"uc:UC-GOV-22","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-22","sourceIds":["cobit-2019","iso-27001","nis2","nist-800-53"],"sourceUrl":null,"title":"UC-GOV-22 — Assess control effectiveness and authorize systems","type":"unified","url":"/assets/agent_record-uc-uc-gov-22-c0b503b4.d832bc01f3b42328.json"},{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"corrective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-24","description":"Maintain documented procedures to notify supervisory and regulatory bodies of reportable cybersecurity events within mandated regulatory timelines, including any staged early-warning, detailed-notification, and final-report deadlines, and to submit required periodic compliance certifications and filings. Handle regulatory submissions and related materials confidentially, and retain evidence of all notifications, certifications, and supporting records.","details":{"control_category":"administrative","control_type":"corrective","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"500.17","coverage":"full","framework":"nydfs-500","relationship":"superset_of"},{"control_id":"NIS2-Art23","coverage":"partial","delta":"staged deadlines (early warning 24h, notification 72h, final report within one month); Art 23 also requires notifying service recipients of significant incidents and threat remedies","framework":"nis2","relationship":"intersects_with"},{"control_id":"500.18","coverage":"full","framework":"nydfs-500","relationship":"superset_of"}],"statement":"Maintain documented procedures to notify supervisory and regulatory bodies of reportable cybersecurity events within mandated regulatory timelines, including any staged early-warning, detailed-notification, and final-report deadlines, and to submit required periodic compliance certifications and filings. Handle regulatory submissions and related materials confidentially, and retain evidence of all notifications, certifications, and supporting records.","title":"Notify regulators of incidents and file required certifications","unified_id":"UC-GOV-24"},"direct":false,"htmlUrl":"/agents/records/uc-uc-gov-24-b737644b.html","id":"uc:UC-GOV-24","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-24","sourceIds":["nis2","nydfs-500"],"sourceUrl":null,"title":"UC-GOV-24 — Notify regulators of incidents and file required certifications","type":"unified","url":"/assets/agent_record-uc-uc-gov-24-b737644b.ba9c0ba105597023.json"},{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-29","description":"Establish, document, and disseminate policies and procedures governing security in system and services acquisition, in-house application development, configuration management, and system maintenance — including secure development standards, evaluation criteria for externally developed applications, and baseline configuration requirements. Review, assess, and update these policies and procedures at least annually under accountable security leadership and after significant changes.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"SA-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"CM-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"MA-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"500.8","coverage":"full","framework":"nydfs-500","relationship":"superset_of"},{"control_id":"NIS2-Art21e","coverage":"partial","delta":"operational vulnerability handling and coordinated disclosure processes","framework":"nis2","relationship":"intersects_with"}],"statement":"Establish, document, and disseminate policies and procedures governing security in system and services acquisition, in-house application development, configuration management, and system maintenance — including secure development standards, evaluation criteria for externally developed applications, and baseline configuration requirements. Review, assess, and update these policies and procedures at least annually under accountable security leadership and after significant changes.","title":"Maintain secure acquisition, development, and maintenance policies","unified_id":"UC-GOV-29"},"direct":false,"htmlUrl":"/agents/records/uc-uc-gov-29-7c321dee.html","id":"uc:UC-GOV-29","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-29","sourceIds":["nis2","nist-800-53","nydfs-500"],"sourceUrl":null,"title":"UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies","type":"unified","url":"/assets/agent_record-uc-uc-gov-29-7c321dee.e360ec1d107fbe3f.json"},{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-31","description":"Establish, document, and disseminate policies and procedures governing logical access control, identification and authentication, and personnel (human resources) security — covering authorization based on need-to-know and least privilege, credential and authenticator management, and personnel screening, transfer, and termination requirements. Communicate these policies to the workforce and review and update them at defined intervals and upon significant change.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"AC-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"IA-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PS-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"NIS2-Art21i","coverage":"partial","delta":"asset management policy and operational measures","framework":"nis2","relationship":"intersects_with"}],"statement":"Establish, document, and disseminate policies and procedures governing logical access control, identification and authentication, and personnel (human resources) security — covering authorization based on need-to-know and least privilege, credential and authenticator management, and personnel screening, transfer, and termination requirements. Communicate these policies to the workforce and review and update them at defined intervals and upon significant change.","title":"Maintain access control, identity, and personnel security policies","unified_id":"UC-GOV-31"},"direct":false,"htmlUrl":"/agents/records/uc-uc-gov-31-46e68199.html","id":"uc:UC-GOV-31","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-31","sourceIds":["nis2","nist-800-53"],"sourceUrl":null,"title":"UC-GOV-31 — Maintain access control, identity, and personnel security policies","type":"unified","url":"/assets/agent_record-uc-uc-gov-31-46e68199.e5c43f024a890c3f.json"},{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-32","description":"Establish, document, and disseminate policies and procedures for security awareness, training, and basic cyber-hygiene practices applicable to all personnel, defining required content, frequency, audiences, and completion tracking. Review and update the policy and program requirements at defined intervals and in response to changes in threats and incidents.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"AT-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"NIS2-Art21g","coverage":"partial","delta":"actual delivery of hygiene practices and training to all personnel","framework":"nis2","relationship":"intersects_with"}],"statement":"Establish, document, and disseminate policies and procedures for security awareness, training, and basic cyber-hygiene practices applicable to all personnel, defining required content, frequency, audiences, and completion tracking. Review and update the policy and program requirements at defined intervals and in response to changes in threats and incidents.","title":"Maintain security awareness and cyber-hygiene policies","unified_id":"UC-GOV-32"},"direct":false,"htmlUrl":"/agents/records/uc-uc-gov-32-948a4756.html","id":"uc:UC-GOV-32","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-32","sourceIds":["nis2","nist-800-53"],"sourceUrl":null,"title":"UC-GOV-32 — Maintain security awareness and cyber-hygiene policies","type":"unified","url":"/assets/agent_record-uc-uc-gov-32-948a4756.ecdd2a2bcff0b0de.json"},{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-34","description":"Establish, document, and disseminate contingency planning policy and procedures, identify risks arising from potential business disruptions — including to critical infrastructure and essential services — and select and develop mitigation activities (including consideration of insurance and other risk transfer) proportionate to those risks. Review and update the policy and the mitigation portfolio at defined intervals and after significant disruptions.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"CP-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PM-8","coverage":"partial","delta":"a dedicated critical-infrastructure and key-resources protection plan addressing security and privacy, beyond naming critical infrastructure as a disruption source","framework":"nist-800-53","relationship":"intersects_with"},{"control_id":"CC9.1","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"NIS2-Art21c","coverage":"partial","delta":"implemented backup, disaster recovery, and crisis management capabilities","framework":"nis2","relationship":"intersects_with"}],"statement":"Establish, document, and disseminate contingency planning policy and procedures, identify risks arising from potential business disruptions — including to critical infrastructure and essential services — and select and develop mitigation activities (including consideration of insurance and other risk transfer) proportionate to those risks. Review and update the policy and the mitigation portfolio at defined intervals and after significant disruptions.","title":"Maintain business continuity and contingency planning policy","unified_id":"UC-GOV-34"},"direct":false,"htmlUrl":"/agents/records/uc-uc-gov-34-3de22bbe.html","id":"uc:UC-GOV-34","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-34","sourceIds":["nis2","nist-800-53","soc2"],"sourceUrl":null,"title":"UC-GOV-34 — Maintain business continuity and contingency planning policy","type":"unified","url":"/assets/agent_record-uc-uc-gov-34-3de22bbe.5536cd0aca700484.json"},{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-35","description":"Establish, document, and disseminate an incident response policy and supporting procedures that define what constitutes a security incident, roles, responsibilities, and authorities, and requirements for detection, internal reporting, handling, escalation, and post-incident review. Review and update the policy and procedures at defined intervals and after significant incidents or exercises.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"IR-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"NIS2-Art21b","coverage":"partial","delta":"operational incident detection, handling, and response capability","framework":"nis2","relationship":"intersects_with"}],"statement":"Establish, document, and disseminate an incident response policy and supporting procedures that define what constitutes a security incident, roles, responsibilities, and authorities, and requirements for detection, internal reporting, handling, escalation, and post-incident review. Review and update the policy and procedures at defined intervals and after significant incidents or exercises.","title":"Maintain incident response policy and procedures","unified_id":"UC-GOV-35"},"direct":false,"htmlUrl":"/agents/records/uc-uc-gov-35-b003f925.html","id":"uc:UC-GOV-35","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-35","sourceIds":["nis2","nist-800-53"],"sourceUrl":null,"title":"UC-GOV-35 — Maintain incident response policy and procedures","type":"unified","url":"/assets/agent_record-uc-uc-gov-35-b003f925.6d7160871edd70a7.json"},{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-36","description":"Establish, document, and disseminate policies and procedures for system and communications protection, including the required use of cryptography and encryption, secured communication channels, and multi-factor and strong authentication expectations for remote and privileged access. Review and update these policies at defined intervals and as cryptographic standards and threats evolve.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"SC-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"NIS2-Art21h","coverage":"full","framework":"nis2","relationship":"superset_of"},{"control_id":"NIS2-Art21j","coverage":"partial","delta":"actual deployment of MFA and secured emergency communication systems","framework":"nis2","relationship":"intersects_with"}],"statement":"Establish, document, and disseminate policies and procedures for system and communications protection, including the required use of cryptography and encryption, secured communication channels, and multi-factor and strong authentication expectations for remote and privileged access. Review and update these policies at defined intervals and as cryptographic standards and threats evolve.","title":"Maintain communications security and cryptography policies","unified_id":"UC-GOV-36"},"direct":false,"htmlUrl":"/agents/records/uc-uc-gov-36-8eac71a2.html","id":"uc:UC-GOV-36","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-36","sourceIds":["nis2","nist-800-53"],"sourceUrl":null,"title":"UC-GOV-36 — Maintain communications security and cryptography policies","type":"unified","url":"/assets/agent_record-uc-uc-gov-36-8eac71a2.4b6c96834d275e71.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0829af2246a85e7e5cc486581d228bba50e080557016bad92e46f06a89d07cae","properties":{"rationale":"Maintaining policies required by HIPAA/PCI/regulators reduces enforcement exposure for missing governance documentation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/risk-compliance-litigation-enforcement-25e7935d.json","targetId":"risk:compliance-litigation-enforcement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:09fed3546986fe04fdec9059b5f846d64b5f3de14be1d43fc8e4e13b53da8c3f","properties":{},"sourceDetailPath":"/data/v1/records/wf-g10-3ef59294.json","sourceId":"wf:G10","targetDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","targetId":"uc:UC-GOV-05","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0c5d2f207b498cc309458da0f8f750182a4a9ec79417139ab3dc080ecd9d3b10","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","targetId":"uc:UC-GOV-29","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0d58933675deb17536728566a874266b15eab2225b772d92e95e86e6300632fc","properties":{},"sourceDetailPath":"/data/v1/records/wf-d49-307550b5.json","sourceId":"wf:D49","targetDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","targetId":"uc:UC-GOV-14","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:10a681e8bcc29f91944411fa2644e4b72af383ae4ec6b4c11fbbea05288cd30d","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","targetId":"uc:UC-GOV-14","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:13f6aa7b3ed4b184eafd7da0757ae79318f89b1a9d20ab92bf53261aceb57e32","properties":{"rationale":"Establishing, approving, and maintaining the security policy suite directly remedies missing approved policies.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:166855d3a2e2b69b9c4db7645bbfd56c9cc7d36d893b9f99cdfc09cd532b423c","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-36-8eac71a2.json","targetId":"uc:UC-GOV-36","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1761356601b0bff62e19bc5bb4f2f0214310024d0cb128365be184e18252f112","properties":{"control_id":"NIS2-Art21b","coverage":"partial","delta":"operational incident detection, handling, and response capability","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-35-b003f925.json","sourceId":"uc:UC-GOV-35","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21b-0635d82d.json","targetId":"ctrl:nis2:NIS2-Art21b","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:189b3985dfa4c056997dd2abf022b0f59bd800f8a62097d80e959879fc0e55b0","properties":{},"sourceDetailPath":"/data/v1/records/wf-g9-d1e65641.json","sourceId":"wf:G9","targetDetailPath":"/data/v1/records/uc-uc-gov-36-8eac71a2.json","targetId":"uc:UC-GOV-36","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1a663343145533a04509d71da542b53189545e4574b887ad8979570e55e3f323","properties":{},"sourceDetailPath":"/data/v1/records/wf-g9-d1e65641.json","sourceId":"wf:G9","targetDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","targetId":"uc:UC-GOV-29","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:20932a427a95372b27fc90b544fbd1756924bf884b185ab1e739d5a38ca2f7ad","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-32-948a4756.json","targetId":"uc:UC-GOV-32","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:21603a251d2391397ab6f7db5f8216489bc66134e16d8f6ad445269634bfc813","properties":{},"sourceDetailPath":"/data/v1/records/wf-g11-62e4fa80.json","sourceId":"wf:G11","targetDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","targetId":"uc:UC-GOV-05","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:242639094cff3d814b708b23b6a26846f3357325e2e8b12ff07bb70f5bf8b641","properties":{},"sourceDetailPath":"/data/v1/records/wf-r5-c423cac7.json","sourceId":"wf:R5","targetDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","targetId":"uc:UC-GOV-14","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:251c0e73768ca98fda93f31a33027edba793af39a97341f6031fd10d38f36631","properties":{"rationale":"Establishing communications-security and cryptography policies (encryption, MFA expectations) remedies missing policy for this domain.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-36-8eac71a2.json","sourceId":"uc:UC-GOV-36","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:28924eaf63c56558668827e696e6bcad38ab1711084f0eacb81df94d94ed5c11","properties":{},"sourceDetailPath":"/data/v1/records/wf-c26-0d7976b8.json","sourceId":"wf:C26","targetDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","targetId":"uc:UC-GOV-34","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:30b1b3877869e349fd75de8173872eeab37da6983ffe6aa5e2b21976f99e1488","properties":{},"sourceDetailPath":"/data/v1/records/wf-g9-d1e65641.json","sourceId":"wf:G9","targetDetailPath":"/data/v1/records/uc-uc-gov-32-948a4756.json","targetId":"uc:UC-GOV-32","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3182f8641789baa67de99c572edb2c8484ec8a2cff106b507f2dcbaf528d1b20","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21b-0635d82d.json","sourceId":"ctrl:nis2:NIS2-Art21b","targetDetailPath":"/data/v1/records/std-nis2-450f1237.json","targetId":"std:nis2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3a829b6ca593c3e21eebcb887c48edae239f0b3035f585ef88ce84c5d2c743b4","properties":{},"sourceDetailPath":"/data/v1/records/wf-c26-0d7976b8.json","sourceId":"wf:C26","targetDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","targetId":"uc:UC-GOV-29","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:41aaa7a64c3af985962f3ffbcae842e2e36a2e728a20575c4b0bc514d1fdc3ec","properties":{"control_id":"NIS2-Art21h","coverage":"full","delta":null,"framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-36-8eac71a2.json","sourceId":"uc:UC-GOV-36","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21h-59950523.json","targetId":"ctrl:nis2:NIS2-Art21h","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:443f786d43ee6948e95374e37c50e83b401cf7827e8bdb8d7420e4abd2529647","properties":{"rationale":"Embedding security requirements and audit/access rights, reviewing service agreements and supplier performance, and reassessing on a cycle directly counters unmonitored, unbound suppliers.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:46f35c5e592611f58485ac24a04b8f78888403062b9dc107fe469bf4f163a94f","properties":{"control_id":"NIS2-Art21g","coverage":"partial","delta":"actual delivery of hygiene practices and training to all personnel","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-32-948a4756.json","sourceId":"uc:UC-GOV-32","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21g-6280385a.json","targetId":"ctrl:nis2:NIS2-Art21g","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:478768bc2b6e32df7b2b4c0aa2727e33baa93896525bb45bd9f906eba92c730a","properties":{"rationale":"Establishing access-control, identity, and personnel-security policies remedies missing policies and undefined access duties.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-31-46e68199.json","sourceId":"uc:UC-GOV-31","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4a760fcc567e20c8fd330ef583b60f81d82c5562637becbcb37567687610101b","properties":{"rationale":"Establishing security-awareness and cyber-hygiene policies remedies missing policy for training content, cadence, and tracking.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-32-948a4756.json","sourceId":"uc:UC-GOV-32","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4b7629b69ae79728771d781567c1e53d132a8b38fcd0331d054068b0061d0a51","properties":{},"sourceDetailPath":"/data/v1/records/wf-c26-0d7976b8.json","sourceId":"wf:C26","targetDetailPath":"/data/v1/records/uc-uc-gov-32-948a4756.json","targetId":"uc:UC-GOV-32","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4c2ba99647f6e667f09390481d939ddc1fe0ad08efd344450e72c73ac84eca7e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21h-59950523.json","sourceId":"ctrl:nis2:NIS2-Art21h","targetDetailPath":"/data/v1/records/std-nis2-450f1237.json","targetId":"std:nis2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:513a140b237672d5a5a63a0b5a4d852b46b4a0f9b2d5f12623593bfafdb88983","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-22-c0b503b4.json","sourceId":"uc:UC-GOV-22","targetDetailPath":"/data/v1/records/risk-compliance-improper-market-practices-9c55cfe9.json","targetId":"risk:compliance-improper-market-practices","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5281390054b41163d7d644d1c520e88598f1a899f13fd5818c8d8839e14fa9c3","properties":{"rationale":"Board independence, expertise, and oversight of the control and risk program is the direct control against inadequate board oversight.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","sourceId":"uc:UC-GOV-05","targetDetailPath":"/data/v1/records/risk-gov-oversight-failure-d98ffc12.json","targetId":"risk:gov-oversight-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:54ae02c655fb37b48ab58ae5bfd03f6ed70d2b65e5cc5a91cc8080c54a182684","properties":{},"sourceDetailPath":"/data/v1/records/wf-d52-3f5d13a3.json","sourceId":"wf:D52","targetDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","targetId":"uc:UC-GOV-14","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:56dfe103e06ba3e03327b976baf2e7ccda67ac05f21e445799bcd6d251284b07","properties":{"rationale":"Assessing concentration and substitutability and maintaining exit strategies reduces the impact of a disrupted critical-input supplier.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-tprm-supply-chain-disruption-0d7e0959.json","targetId":"risk:tprm-supply-chain-disruption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5b5455de5c0de0b50a25afbc0350ba53f54669f70575e5c2acae37f5fa25ae67","properties":{"control_id":"NIS2-Art21i","coverage":"partial","delta":"asset management policy and operational measures","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-31-46e68199.json","sourceId":"uc:UC-GOV-31","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21i-d5158327.json","targetId":"ctrl:nis2:NIS2-Art21i","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:64cec82ce8f8b4225600cd32499d707bac17afc888e4e29680ac65b0ee214dfe","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21c-18adf13b.json","sourceId":"ctrl:nis2:NIS2-Art21c","targetDetailPath":"/data/v1/records/std-nis2-450f1237.json","targetId":"std:nis2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:65efa7cec7ad59e7c84b28f7447572d2dea3e666127e45163d267eae59a1d2b7","properties":{},"sourceDetailPath":"/data/v1/records/wf-g9-d1e65641.json","sourceId":"wf:G9","targetDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","targetId":"uc:UC-GOV-14","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:67dd2fc4c66a76dfb624ab150a468d8306a9c567880b097faf8097b944363c0d","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-gov-22-c0b503b4.json","targetId":"uc:UC-GOV-22","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:68d27ccb03fbd66b5674b0f14150c97a1d6a5d3e1d393a4cdac3d30ac979f1b5","properties":{"rationale":"Least-privilege authorization and personnel screening/termination requirements reduce insider-fraud opportunity.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-31-46e68199.json","sourceId":"uc:UC-GOV-31","targetDetailPath":"/data/v1/records/risk-fraud-internal-misappropriation-d235cd10.json","targetId":"risk:fraud-internal-misappropriation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:69a6c7f9bed48e02129fbab011819e3d8abc7f7cd2f0680cee3c0301c965118b","properties":{"rationale":"Assessing criticality, substitutability, and concentration before contracting and maintaining tested exit strategies for critical providers is the core defense against vendor failure and concentration.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-tprm-critical-vendor-failure-cb39c2bc.json","targetId":"risk:tprm-critical-vendor-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6a395e5bdd2e15e676e1508c2595987a0b3e68accf57e99be3b01eb9e860e818","properties":{"rationale":"Notifying regulators within mandated timelines and filing required certifications avoids penalties for late or missing regulatory reporting.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-24-b737644b.json","sourceId":"uc:UC-GOV-24","targetDetailPath":"/data/v1/records/risk-compliance-litigation-enforcement-25e7935d.json","targetId":"risk:compliance-litigation-enforcement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6b57a277a7d8f8fa698438f9358b04b4dfa0a04db4dcdaaeab3804dde976104c","properties":{"control_id":"NIS2-Art21j","coverage":"partial","delta":"actual deployment of MFA and secured emergency communication systems","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-36-8eac71a2.json","sourceId":"uc:UC-GOV-36","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21j-49982c35.json","targetId":"ctrl:nis2:NIS2-Art21j","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6f4aee545a5876c856bbabf8c732c3c8e6a772d7fa6fe334a523b19ac7da79fb","properties":{"rationale":"Timely, proper incident notification limits the reputational fallout of mishandled disclosure.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-24-b737644b.json","sourceId":"uc:UC-GOV-24","targetDetailPath":"/data/v1/records/risk-reputational-brand-crisis-4d7c293d.json","targetId":"risk:reputational-brand-crisis","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6f9e22b1dad061e1980d1b5110a30b626da841155819d2dabdb7f5f99ea36726","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21j-49982c35.json","sourceId":"ctrl:nis2:NIS2-Art21j","targetDetailPath":"/data/v1/records/std-nis2-450f1237.json","targetId":"std:nis2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:70688cb7d150ee99386a94479f65201517d189fb4ecc975352a921c4d8a36b3e","properties":{"rationale":"Defined detection, escalation, and post-incident review reduce the reputational damage of mishandled breaches.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-35-b003f925.json","sourceId":"uc:UC-GOV-35","targetDetailPath":"/data/v1/records/risk-reputational-brand-crisis-4d7c293d.json","targetId":"risk:reputational-brand-crisis","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:72ba8a5abe71532bacbb0d85adcf0d79ccb88c653f130984008cbbcfc38f3075","properties":{"rationale":"Concentration/substitutability assessment and exit strategies reduce the impact of geopolitically-driven supplier and supply-chain disruption.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-strategic-geopolitical-4e7aba30.json","targetId":"risk:strategic-geopolitical","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:84597e04a3c368bb0c99544fbdc2d416be456559ea49b7d5f8358d138ae4df6c","properties":{},"sourceDetailPath":"/data/v1/records/wf-c26-0d7976b8.json","sourceId":"wf:C26","targetDetailPath":"/data/v1/records/uc-uc-gov-36-8eac71a2.json","targetId":"uc:UC-GOV-36","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:880d8c2ef29e7b0626156dc437d965e6fadb6e2ff994b9803a267a3cd94fc4a8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21f-a9a69314.json","sourceId":"ctrl:nis2:NIS2-Art21f","targetDetailPath":"/data/v1/records/std-nis2-450f1237.json","targetId":"std:nis2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8826af7bcd4bdfeaf33eca5b5812a47ee268736e8e2a5e06cf93ef4480ed9ffc","properties":{"rationale":"Regularly assessing control effectiveness and tracking findings to closure detects and challenges deficiencies that would otherwise persist.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-22-c0b503b4.json","sourceId":"uc:UC-GOV-22","targetDetailPath":"/data/v1/records/risk-compliance-no-independent-audit-9e1acf0f.json","targetId":"risk:compliance-no-independent-audit","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:93817c15ca7c0c4a4f1c60da13e03e351009be1df0a08220e23ff8cbb387b35e","properties":{"control_id":"NIS2-Art21c","coverage":"partial","delta":"implemented backup, disaster recovery, and crisis management capabilities","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","sourceId":"uc:UC-GOV-34","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21c-18adf13b.json","targetId":"ctrl:nis2:NIS2-Art21c","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:97bf093cdd524720c56b30141ef55eaacea57cd6de66d78dd5666a1d4622b5ff","properties":{"control_id":"NIS2-Art20","coverage":"partial","delta":"management body members must approve measures and complete cybersecurity training","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","sourceId":"uc:UC-GOV-05","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art20-28d702ac.json","targetId":"ctrl:nis2:NIS2-Art20","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9e207b75bcd6c22f131d0cdb6b870204b38ef4a2fafd38a1010da47b8115eb6b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nis2-nis2-art20-28d702ac.json","sourceId":"ctrl:nis2:NIS2-Art20","targetDetailPath":"/data/v1/records/std-nis2-450f1237.json","targetId":"std:nis2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9f1bae1360f52521b0bc3a3c5c5c7e191cb4b6a0693f8212fb590551df6fe622","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21a-1dbcc08c.json","sourceId":"ctrl:nis2:NIS2-Art21a","targetDetailPath":"/data/v1/records/std-nis2-450f1237.json","targetId":"std:nis2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a07967c9377f5646dfdb472c254486f40ff70c05a9cc91aa40b3f4da38998b6f","properties":{},"sourceDetailPath":"/data/v1/records/wf-c26-0d7976b8.json","sourceId":"wf:C26","targetDetailPath":"/data/v1/records/uc-uc-gov-31-46e68199.json","targetId":"uc:UC-GOV-31","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a4c83f9347f2c3822f73444eab68928d9538e58c47af17c84256bc804e23f817","properties":{"rationale":"","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","sourceId":"uc:UC-GOV-34","targetDetailPath":"/data/v1/records/risk-esg-climate-transition-35e73915.json","targetId":"risk:esg-climate-transition","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a659b09b27d5b07efb91f9aaca819139b77c2cc0f116a857de472daf53dcfe62","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21i-d5158327.json","sourceId":"ctrl:nis2:NIS2-Art21i","targetDetailPath":"/data/v1/records/std-nis2-450f1237.json","targetId":"std:nis2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a89c79a6672efc48fb298105e405c7165cc81524aa26b7989eca143a45f465bf","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","targetId":"uc:UC-GOV-05","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a94821c88120c0a34de463ab23423da8d500d76388a26aef2a189d9cc82122f8","properties":{"control_id":"NIS2-Art23","coverage":"partial","delta":"staged deadlines (early warning 24h, notification 72h, final report within one month); Art 23 also requires notifying service recipients of significant incidents and threat remedies","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-24-b737644b.json","sourceId":"uc:UC-GOV-24","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art23-93f21077.json","targetId":"ctrl:nis2:NIS2-Art23","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ac8743ff250a1b216aa3f8579d8240bb903f102f806ab918b2c75df9724fd31d","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-35-b003f925.json","targetId":"uc:UC-GOV-35","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:adb73bf2fed2d22bf663bd2eb79023eb935d60f5669e776a5553e24dfa431eab","properties":{"control_id":"NIS2-Art21a","coverage":"full","delta":null,"framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21a-1dbcc08c.json","targetId":"ctrl:nis2:NIS2-Art21a","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b0f240d0bb2e0ebdc690ff63fa6b509a1063b8fad26027a37b7d9e376b2fe859","properties":{"rationale":"Risk-based due diligence, a criticality-ranked register, sub-outsourcing conditions, and reassessment reduce the N-tier compliance-failure exposure driving vicarious liability.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-tprm-vendor-compliance-vicarious-liability-0215657c.json","targetId":"risk:tprm-vendor-compliance-vicarious-liability","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b31cfc206efc91fc97e130dc732683be4fcbba6ff8e26ac0edd9f22c61b0ae4b","properties":{"rationale":"Establishing contingency/business-continuity policy and disruption-mitigation requirements remedies a missing resilience policy.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","sourceId":"uc:UC-GOV-34","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c623f681d3be563565b1b244d48a32f6019d9e35d4f80ae090bf48da70f94dfc","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21g-6280385a.json","sourceId":"ctrl:nis2:NIS2-Art21g","targetDetailPath":"/data/v1/records/std-nis2-450f1237.json","targetId":"std:nis2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ccd0e376207f2decfe033433db539cafbba762a294aff5120dfa29a56d500050","properties":{"rationale":"Defining, agreeing, and reviewing service agreements and supplier performance and operating lifecycle controls to address weaknesses directly targets non-performance.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-tprm-vendor-service-nonperformance-081f2fb9.json","targetId":"risk:tprm-vendor-service-nonperformance","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d15fa900a832be74bc553982907d1cc33136427e93e8504fc06518bfa803badd","properties":{},"sourceDetailPath":"/data/v1/records/wf-d05-2302db1f.json","sourceId":"wf:D05","targetDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","targetId":"uc:UC-GOV-14","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d1bc3d44abfcb1b212921d6c5e3323d0b33cf5166e5957cd9e0d160834fac695","properties":{"rationale":"A criticality-ranked third-party register plus concentration and exit-strategy assessment applies to AI API providers, reducing concentration and outage impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-ai-supply-chain-concentration-9f791f54.json","targetId":"risk:ai-supply-chain-concentration","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d51e0c2cff0f07ea472ce919c8211ae63ac98498cba09607ba2ea89d79975ebe","properties":{"rationale":"Board/audit-committee oversight of internal control provides challenge that helps surface ICFR material weaknesses.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","sourceId":"uc:UC-GOV-05","targetDetailPath":"/data/v1/records/risk-fin-icfr-material-weakness-cdd66323.json","targetId":"risk:fin-icfr-material-weakness","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d7cc1f08f27b6315ce2ec5eed4c8b0a4dc59776e29cddc1c7873e1fdeecb6d99","properties":{"rationale":"Assessing concentration risk and maintaining exit strategies for critical providers reduces the ecosystem single-point-of-failure impact from GPAI-capability concentration.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/risk-ai-gpai-systemic-transparency-7a746323.json","targetId":"risk:ai-gpai-systemic-transparency","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d8aac1873d520133a213756c6eb8159774ddd1d167378661f648c59faa3c9463","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","targetId":"uc:UC-GOV-34","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:de616a147b2365ba5faac5120a250503e61029343d6a45b71aaca9c9c83df528","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","targetId":"uc:UC-GOV-34","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e128b49ab78886cf2d4a9a1a526b51a15308cc2aa1cedac229bdcf6765ac54a5","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-22-c0b503b4.json","targetId":"uc:UC-GOV-22","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e2cc926abdc7649873b87687a8659072360f3dd3f0f646b09684185fe553d3a8","properties":{"rationale":"Establishing secure acquisition, development, configuration, and maintenance policies remedies missing policies for this domain.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","sourceId":"uc:UC-GOV-29","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e74461fd8134725e4382e89324b0401d067f371e2fdb2244355d6a61c95d2265","properties":{},"sourceDetailPath":"/data/v1/records/wf-g7-9762f11b.json","sourceId":"wf:G7","targetDetailPath":"/data/v1/records/uc-uc-gov-24-b737644b.json","targetId":"uc:UC-GOV-24","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ea99e0bc10e1ad122a64a42d4f501db2f9ba24124237d01361bd5841e31090d8","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","targetId":"uc:UC-GOV-14","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eaee02d29ac324222bdcbfadff33bb58c4a695fe03ec41900de9dec7895d3153","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-31-46e68199.json","targetId":"uc:UC-GOV-31","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ef7e9eb3408379b70f7651cde080d10ec50bb2a51fad191f16e42c98a67e42f2","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21e-ae62ba80.json","sourceId":"ctrl:nis2:NIS2-Art21e","targetDetailPath":"/data/v1/records/std-nis2-450f1237.json","targetId":"std:nis2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:efe87a3d98c9f4d13cec684366522ee57c67f4957369c307119cf4018d4e872d","properties":{"control_id":"NIS2-Art21f","coverage":"full","delta":null,"framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-22-c0b503b4.json","sourceId":"uc:UC-GOV-22","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21f-a9a69314.json","targetId":"ctrl:nis2:NIS2-Art21f","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f161121f24a878f107ad43ff7ae8ddca3eaa21fea212cd13fde4ae75071e0f4a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c26-0d7976b8.json","sourceId":"wf:C26","targetDetailPath":"/data/v1/records/uc-uc-gov-35-b003f925.json","targetId":"uc:UC-GOV-35","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f1b1da5d7d2f9272b8b80e1278376d72fa57638b9ab1d1e28438eebc4f9bf2f8","properties":{},"sourceDetailPath":"/data/v1/records/wf-g9-d1e65641.json","sourceId":"wf:G9","targetDetailPath":"/data/v1/records/uc-uc-gov-31-46e68199.json","targetId":"uc:UC-GOV-31","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f284418a1b6e2607a19c440df6684dab6a0206def8e6889a7704641ad827b848","properties":{},"sourceDetailPath":"/data/v1/records/wf-r1-a5f4fc75.json","sourceId":"wf:R1","targetDetailPath":"/data/v1/records/uc-uc-gov-24-b737644b.json","targetId":"uc:UC-GOV-24","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f2d3c58671aec19e31faee03ea3ae74ddbe8bca2ab26be3fb48fbdd0a95b8193","properties":{"rationale":"Evaluation criteria for externally developed applications set security requirements on acquired third-party software.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","sourceId":"uc:UC-GOV-29","targetDetailPath":"/data/v1/records/risk-tprm-weak-supplier-oversight-1baaa012.json","targetId":"risk:tprm-weak-supplier-oversight","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f302d6bc9aa84cc234fc1d08bb67cff3d6c9f21a4d211d1ea21e7dbfab631047","properties":{},"sourceDetailPath":"/data/v1/records/wf-g9-d1e65641.json","sourceId":"wf:G9","targetDetailPath":"/data/v1/records/uc-uc-gov-35-b003f925.json","targetId":"uc:UC-GOV-35","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f4777178aeb214339656c564928a20972f6832c6cbe980d78b1a8b0a2ddcc311","properties":{},"sourceDetailPath":"/data/v1/records/wf-g17-8c15d035.json","sourceId":"wf:G17","targetDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","targetId":"uc:UC-GOV-05","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f5f5c3095bc073d4b40da72a182f9a76677ba5bae590ec43c1c5d91d697cd9d4","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21d-9b82b64b.json","sourceId":"ctrl:nis2:NIS2-Art21d","targetDetailPath":"/data/v1/records/std-nis2-450f1237.json","targetId":"std:nis2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f62c3dd850999cd7501d541d730ce1297ebba264414e99059d7c5fc526e7df89","properties":{"control_id":"NIS2-Art21d","coverage":"partial","delta":"operational supplier security assessments and contractual safeguards per supplier","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21d-9b82b64b.json","targetId":"ctrl:nis2:NIS2-Art21d","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f830945fe84e4b0620e2bc65167b8a30c1a671e0059e5adab1f906d542a4879a","properties":{},"sourceDetailPath":"/data/v1/records/wf-g9-d1e65641.json","sourceId":"wf:G9","targetDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","targetId":"uc:UC-GOV-34","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f9446b4e5d94127ba7de8295a509cb5250ed22c30f5a8f17f0e38179284657f5","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nis2-nis2-art23-93f21077.json","sourceId":"ctrl:nis2:NIS2-Art23","targetDetailPath":"/data/v1/records/std-nis2-450f1237.json","targetId":"std:nis2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ff531a29006ff50ac533d73cfb7b5ad9408ec7a35f9e0191d02e032942133703","properties":{"control_id":"NIS2-Art21e","coverage":"partial","delta":"operational vulnerability handling and coordinated disclosure processes","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-29-7c321dee.json","sourceId":"uc:UC-GOV-29","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21e-ae62ba80.json","targetId":"ctrl:nis2:NIS2-Art21e","type":"maps_to"}],"schemaVersion":1,"scope":"sources","total":60}
