{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["risk:access-excess-privilege","risk:access-privilege-abuse-repudiation","risk:access-unauthorized-use-equipment","risk:access-weak-authentication","risk:asset-uncontrolled-copying-removable-media","risk:aware-phishing-social-engineering","risk:compliance-litigation-enforcement","risk:config-internet-exposed-misconfig","risk:config-poor-baseline-drift","risk:crypto-cleartext-credential-transfer","risk:crypto-counterfeit-certificates","risk:crypto-weak-or-absent-encryption","risk:data-exfiltration-espionage","risk:data-residual-media-disposal","risk:fin-journal-entry-management-override","risk:fin-revenue-recognition-misstatement","risk:fin-segregation-of-duties","risk:fraud-external","risk:gov-policy-absent","risk:hr-insufficient-screening","risk:log-missing-audit-trail","risk:log-no-monitoring-supervision","risk:net-cloud-multitenancy-exploit","risk:net-interception-mitm","risk:net-poor-perimeter-architecture","risk:net-remote-work-mobile-exposure","risk:phys-theft-of-equipment-media","risk:sdlc-insecure-privileged-apps"],"directIds":["ctrl:pci-dss:PCI-Req1","ctrl:pci-dss:PCI-Req10","ctrl:pci-dss:PCI-Req11","ctrl:pci-dss:PCI-Req12","ctrl:pci-dss:PCI-Req2","ctrl:pci-dss:PCI-Req3","ctrl:pci-dss:PCI-Req4","ctrl:pci-dss:PCI-Req5","ctrl:pci-dss:PCI-Req6","ctrl:pci-dss:PCI-Req7","ctrl:pci-dss:PCI-Req8","ctrl:pci-dss:PCI-Req9"],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"PCI DSS v4.0.1","next":"/assets/agent_sources-pci-dss-2.06e11ea020fcf34a.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"technical","framework":"pci-dss","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/pci-dss/","description":"Install and maintain network security controls","details":{"automation":"hybrid","control_category":"technical","control_id":"PCI-Req1","control_type":"preventive","domains":["Network & Communications Security","Secure Configuration & Change Management","Data Protection & Privacy","Cryptography & Key Management","Vulnerability & Patch Management","Secure Development (SDLC) & Application Security","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"pci-dss","group":"PCI DSS v4.0.1","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-pci-dss-pci-req1-c3c41ca4.html","id":"ctrl:pci-dss:PCI-Req1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Apci-dss%3APCI-Req1","sourceIds":["pci-dss"],"sourceUrl":null,"title":"PCI-Req1 — Install and maintain network security controls","type":"control","url":"/assets/agent_record-ctrl-pci-dss-pci-req1-c3c41ca4.8a456bdc2497c456.json"},{"attributes":{"category":"technical","framework":"pci-dss","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/pci-dss/","description":"Log and monitor all access to system components and cardholder data","details":{"automation":"automated","control_category":"technical","control_id":"PCI-Req10","control_type":"detective","domains":["Network & Communications Security","Secure Configuration & Change Management","Data Protection & Privacy","Cryptography & Key Management","Vulnerability & Patch Management","Secure Development (SDLC) & Application Security","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"pci-dss","group":"PCI DSS v4.0.1","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-pci-dss-pci-req10-c587ee2b.html","id":"ctrl:pci-dss:PCI-Req10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Apci-dss%3APCI-Req10","sourceIds":["pci-dss"],"sourceUrl":null,"title":"PCI-Req10 — Log and monitor all access to system components and cardholder data","type":"control","url":"/assets/agent_record-ctrl-pci-dss-pci-req10-c587ee2b.e7f863c138d933d9.json"},{"attributes":{"category":"technical","framework":"pci-dss","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/pci-dss/","description":"Test security of systems and networks regularly","details":{"automation":"hybrid","control_category":"technical","control_id":"PCI-Req11","control_type":"detective","domains":["Network & Communications Security","Secure Configuration & Change Management","Data Protection & Privacy","Cryptography & Key Management","Vulnerability & Patch Management","Secure Development (SDLC) & Application Security","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"pci-dss","group":"PCI DSS v4.0.1","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-pci-dss-pci-req11-ee0fcd89.html","id":"ctrl:pci-dss:PCI-Req11","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Apci-dss%3APCI-Req11","sourceIds":["pci-dss"],"sourceUrl":null,"title":"PCI-Req11 — Test security of systems and networks regularly","type":"control","url":"/assets/agent_record-ctrl-pci-dss-pci-req11-ee0fcd89.1c423694afa81e15.json"},{"attributes":{"category":"administrative","framework":"pci-dss","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/pci-dss/","description":"Support information security with organizational policies and programs","details":{"automation":"manual","control_category":"administrative","control_id":"PCI-Req12","control_type":"preventive","domains":["Network & Communications Security","Secure Configuration & Change Management","Data Protection & Privacy","Cryptography & Key Management","Vulnerability & Patch Management","Secure Development (SDLC) & Application Security","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"pci-dss","group":"PCI DSS v4.0.1","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-pci-dss-pci-req12-cd77be1e.html","id":"ctrl:pci-dss:PCI-Req12","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Apci-dss%3APCI-Req12","sourceIds":["pci-dss"],"sourceUrl":null,"title":"PCI-Req12 — Support information security with organizational policies and programs","type":"control","url":"/assets/agent_record-ctrl-pci-dss-pci-req12-cd77be1e.730fbafd0e6ac45d.json"},{"attributes":{"category":"technical","framework":"pci-dss","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/pci-dss/","description":"Apply secure configurations to all system components","details":{"automation":"hybrid","control_category":"technical","control_id":"PCI-Req2","control_type":"preventive","domains":["Network & Communications Security","Secure Configuration & Change Management","Data Protection & Privacy","Cryptography & Key Management","Vulnerability & Patch Management","Secure Development (SDLC) & Application Security","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"pci-dss","group":"PCI DSS v4.0.1","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-pci-dss-pci-req2-586d7ab1.html","id":"ctrl:pci-dss:PCI-Req2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Apci-dss%3APCI-Req2","sourceIds":["pci-dss"],"sourceUrl":null,"title":"PCI-Req2 — Apply secure configurations to all system components","type":"control","url":"/assets/agent_record-ctrl-pci-dss-pci-req2-586d7ab1.ef55a73cd7823921.json"},{"attributes":{"category":"technical","framework":"pci-dss","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/pci-dss/","description":"Protect stored account data","details":{"automation":"hybrid","control_category":"technical","control_id":"PCI-Req3","control_type":"preventive","domains":["Network & Communications Security","Secure Configuration & Change Management","Data Protection & Privacy","Cryptography & Key Management","Vulnerability & Patch Management","Secure Development (SDLC) & Application Security","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"pci-dss","group":"PCI DSS v4.0.1","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-pci-dss-pci-req3-e250c900.html","id":"ctrl:pci-dss:PCI-Req3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Apci-dss%3APCI-Req3","sourceIds":["pci-dss"],"sourceUrl":null,"title":"PCI-Req3 — Protect stored account data","type":"control","url":"/assets/agent_record-ctrl-pci-dss-pci-req3-e250c900.aacf1026a4750203.json"},{"attributes":{"category":"technical","framework":"pci-dss","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/pci-dss/","description":"Protect cardholder data with strong cryptography during transmission over open, public networks","details":{"automation":"automated","control_category":"technical","control_id":"PCI-Req4","control_type":"preventive","domains":["Network & Communications Security","Secure Configuration & Change Management","Data Protection & Privacy","Cryptography & Key Management","Vulnerability & Patch Management","Secure Development (SDLC) & Application Security","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"pci-dss","group":"PCI DSS v4.0.1","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-pci-dss-pci-req4-e571f282.html","id":"ctrl:pci-dss:PCI-Req4","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Apci-dss%3APCI-Req4","sourceIds":["pci-dss"],"sourceUrl":null,"title":"PCI-Req4 — Protect cardholder data with strong cryptography during transmission over open, public networks","type":"control","url":"/assets/agent_record-ctrl-pci-dss-pci-req4-e571f282.8ab354382b4994a8.json"},{"attributes":{"category":"technical","framework":"pci-dss","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/pci-dss/","description":"Protect all systems and networks from malicious software","details":{"automation":"automated","control_category":"technical","control_id":"PCI-Req5","control_type":"preventive","domains":["Network & Communications Security","Secure Configuration & Change Management","Data Protection & Privacy","Cryptography & Key Management","Vulnerability & Patch Management","Secure Development (SDLC) & Application Security","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"pci-dss","group":"PCI DSS v4.0.1","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-pci-dss-pci-req5-85f2abb2.html","id":"ctrl:pci-dss:PCI-Req5","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Apci-dss%3APCI-Req5","sourceIds":["pci-dss"],"sourceUrl":null,"title":"PCI-Req5 — Protect all systems and networks from malicious software","type":"control","url":"/assets/agent_record-ctrl-pci-dss-pci-req5-85f2abb2.20dfdee53f0bebba.json"},{"attributes":{"category":"technical","framework":"pci-dss","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/pci-dss/","description":"Develop and maintain secure systems and software","details":{"automation":"hybrid","control_category":"technical","control_id":"PCI-Req6","control_type":"preventive","domains":["Network & Communications Security","Secure Configuration & Change Management","Data Protection & Privacy","Cryptography & Key Management","Vulnerability & Patch Management","Secure Development (SDLC) & Application Security","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"pci-dss","group":"PCI DSS v4.0.1","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-pci-dss-pci-req6-f2566fc6.html","id":"ctrl:pci-dss:PCI-Req6","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Apci-dss%3APCI-Req6","sourceIds":["pci-dss"],"sourceUrl":null,"title":"PCI-Req6 — Develop and maintain secure systems and software","type":"control","url":"/assets/agent_record-ctrl-pci-dss-pci-req6-f2566fc6.f03d0cbacca7de34.json"},{"attributes":{"category":"technical","framework":"pci-dss","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/pci-dss/","description":"Restrict access to system components and cardholder data by business need to know","details":{"automation":"hybrid","control_category":"technical","control_id":"PCI-Req7","control_type":"preventive","domains":["Network & Communications Security","Secure Configuration & Change Management","Data Protection & Privacy","Cryptography & Key Management","Vulnerability & Patch Management","Secure Development (SDLC) & Application Security","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"pci-dss","group":"PCI DSS v4.0.1","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":7,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-pci-dss-pci-req7-e7336c72.html","id":"ctrl:pci-dss:PCI-Req7","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Apci-dss%3APCI-Req7","sourceIds":["pci-dss"],"sourceUrl":null,"title":"PCI-Req7 — Restrict access to system components and cardholder data by business need to know","type":"control","url":"/assets/agent_record-ctrl-pci-dss-pci-req7-e7336c72.4a20a0dd21e7ca04.json"},{"attributes":{"category":"technical","framework":"pci-dss","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/pci-dss/","description":"Identify users and authenticate access to system components","details":{"automation":"hybrid","control_category":"technical","control_id":"PCI-Req8","control_type":"preventive","domains":["Network & Communications Security","Secure Configuration & Change Management","Data Protection & Privacy","Cryptography & Key Management","Vulnerability & Patch Management","Secure Development (SDLC) & Application Security","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"pci-dss","group":"PCI DSS v4.0.1","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-pci-dss-pci-req8-fe6b4517.html","id":"ctrl:pci-dss:PCI-Req8","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Apci-dss%3APCI-Req8","sourceIds":["pci-dss"],"sourceUrl":null,"title":"PCI-Req8 — Identify users and authenticate access to system components","type":"control","url":"/assets/agent_record-ctrl-pci-dss-pci-req8-fe6b4517.5aff0737466f94ab.json"},{"attributes":{"category":"physical","framework":"pci-dss","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/pci-dss/","description":"Restrict physical access to cardholder data","details":{"automation":"hybrid","control_category":"physical","control_id":"PCI-Req9","control_type":"preventive","domains":["Network & Communications Security","Secure Configuration & Change Management","Data Protection & Privacy","Cryptography & Key Management","Vulnerability & Patch Management","Secure Development (SDLC) & Application Security","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"pci-dss","group":"PCI DSS v4.0.1","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-pci-dss-pci-req9-987072c1.html","id":"ctrl:pci-dss:PCI-Req9","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Apci-dss%3APCI-Req9","sourceIds":["pci-dss"],"sourceUrl":null,"title":"PCI-Req9 — Restrict physical access to cardholder data","type":"control","url":"/assets/agent_record-ctrl-pci-dss-pci-req9-987072c1.38ac86ca9f050146.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management","Data Protection & Privacy"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-excess-privilege","description":"Overly broad or wrongly assigned access rights, applications/services running with excessive privileges, and failure to enforce least privilege — a compromise or insider then gains broad access to systems and data.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"access-excess-privilege","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-access-excess-privilege-cd8adadc.html","id":"risk:access-excess-privilege","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-excess-privilege","sourceIds":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Excessive privilege and wrong assignment of access rights","type":"risk","url":"/assets/agent_record-risk-access-excess-privilege-cd8adadc.c154ceb8157b770a.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-privilege-abuse-repudiation","description":"Authorized users or administrators exploit legitimate access beyond permitted scope, fabricate or forge credentials/rights to gain privileges, and repudiate performed actions — undermining accountability and audit-trail integrity.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"access-privilege-abuse-repudiation","taxonomies":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-access-privilege-abuse-repudiation-343a8917.html","id":"risk:access-privilege-abuse-repudiation","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-privilege-abuse-repudiation","sourceIds":["aiuc-1","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Abuse of rights, forged rights, and repudiation of actions","type":"risk","url":"/assets/agent_record-risk-access-privilege-abuse-repudiation-343a8917.5dfe55c5d06b0530.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management"],"inherent_rating":"medium","taxonomy":["iso-27005-threat","nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-unauthorized-use-equipment","description":"Use of systems, networks, or devices without authorization, and users with authorized access reaching resources that exceed their authorization, potentially to exfiltrate data or conduct attacks.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"access-unauthorized-use-equipment","taxonomies":["iso-27005-threat","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-access-unauthorized-use-equipment-d2082944.html","id":"risk:access-unauthorized-use-equipment","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-unauthorized-use-equipment","sourceIds":["aiuc-1","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Unauthorized use of equipment and unauthorized access escalation","type":"risk","url":"/assets/agent_record-risk-access-unauthorized-use-equipment-d2082944.659ef798ce61ee67.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management","Network & Communications Security"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-weak-authentication","description":"Absent password policy, no MFA, credentials transmitted in clear text, and no session lock/logout on unattended workstations, making account compromise, brute-force login, and session hijacking easy.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"access-weak-authentication","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-access-weak-authentication-4e35bdb2.html","id":"risk:access-weak-authentication","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-weak-authentication","sourceIds":["hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss"],"sourceUrl":null,"title":"Weak authentication and password management","type":"risk","url":"/assets/agent_record-risk-access-weak-authentication-4e35bdb2.331f8d7ddbb6bd4e.json"},{"attributes":{"category":"cyber_security","domain":["Asset Management & Inventory","Secure Configuration & Change Management"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability","iso-27005-threat"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aasset-uncontrolled-copying-removable-media","description":"Absence of controls over copying data to removable devices, and users freely downloading/installing untested or unlicensed software, expands the attack surface and introduces malicious or unlicensed code into the environment.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"asset-uncontrolled-copying-removable-media","taxonomies":["iso-27005-vulnerability","iso-27005-threat"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-asset-uncontrolled-copying-removable-media-4a9604c7.html","id":"risk:asset-uncontrolled-copying-removable-media","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aasset-uncontrolled-copying-removable-media","sourceIds":["iso-27001","nist-800-53","nist-csf-2","pci-dss","soc2"],"sourceUrl":null,"title":"Uncontrolled copying to removable media / unmanaged software installs","type":"risk","url":"/assets/agent_record-risk-asset-uncontrolled-copying-removable-media-4a9604c7.712035880d24449f.json"},{"attributes":{"category":"cyber_security","domain":["Awareness & Training","Access Control & Identity Management"],"inherent_rating":"critical","taxonomy":["nist-800-30-threat-event","basel-operational-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaware-phishing-social-engineering","description":"Adversary counterfeits trustworthy communications (email, phone, spoofed websites) to trick individuals — including high-value executives — into revealing credentials or sensitive information, or into enabling wire-transfer/BEC fraud.","details":{"category":"cyber_security","impact":"high","inherent_rating":"critical","likelihood":"very_high","risk_id":"aware-phishing-social-engineering","taxonomies":["nist-800-30-threat-event","basel-operational-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-aware-phishing-social-engineering-bb9b7bd6.html","id":"risk:aware-phishing-social-engineering","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaware-phishing-social-engineering","sourceIds":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss"],"sourceUrl":null,"title":"Phishing, spear-phishing and social engineering","type":"risk","url":"/assets/agent_record-risk-aware-phishing-social-engineering-bb9b7bd6.04cc1eb066c178e1.json"},{"attributes":{"category":"compliance_regulatory","domain":["Compliance, Audit & Assurance","Governance, Policy & Oversight"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-litigation-enforcement","description":"Adverse judgments, class actions, contract/IP disputes, government subpoenas, DOJ/FTC/SEC investigations, consent decrees, or deferred-prosecution agreements imposing penalties, remediation, and management distraction.","details":{"category":"compliance_regulatory","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"compliance-litigation-enforcement","taxonomies":["enterprise-risk","coso-erm-risk"],"treatment":"transfer"},"direct":false,"htmlUrl":"/agents/records/risk-compliance-litigation-enforcement-25e7935d.html","id":"risk:compliance-litigation-enforcement","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acompliance-litigation-enforcement","sourceIds":["cobit-2019","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Litigation, investigation and enforcement exposure","type":"risk","url":"/assets/agent_record-risk-compliance-litigation-enforcement-25e7935d.963b6cccfc52b94e.json"},{"attributes":{"category":"cyber_security","domain":["Secure Configuration & Change Management","Network & Communications Security","Vulnerability & Patch Management"],"inherent_rating":"high","taxonomy":["nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aconfig-internet-exposed-misconfig","description":"Adversary gains access through the Internet to systems not authorized for Internet connectivity or that do not meet configuration requirements, and exploits attacks over unauthorized ports, protocols, and services.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"config-internet-exposed-misconfig","taxonomies":["nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-config-internet-exposed-misconfig-61b3613a.html","id":"risk:config-internet-exposed-misconfig","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aconfig-internet-exposed-misconfig","sourceIds":["aiuc-1","iso-27001","nist-800-53","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Internet-exposed or misconfigured systems","type":"risk","url":"/assets/agent_record-risk-config-internet-exposed-misconfig-61b3613a.784e8a1bdf681744.json"},{"attributes":{"category":"cyber_security","domain":["Secure Configuration & Change Management","Vulnerability & Patch Management"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aconfig-poor-baseline-drift","description":"Without documented, enforced baseline configurations and change control, systems drift into insecure states, contain unauthorized changes, or expose unnecessary network services, expanding attack surface.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"config-poor-baseline-drift","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-config-poor-baseline-drift-2dd66324.html","id":"risk:config-poor-baseline-drift","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aconfig-poor-baseline-drift","sourceIds":["coso-ic","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Poor configuration management and insecure baseline drift","type":"risk","url":"/assets/agent_record-risk-config-poor-baseline-drift-2dd66324.de11f6b9169c61ac.json"},{"attributes":{"category":"cyber_security","domain":["Cryptography & Key Management","Network & Communications Security"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acrypto-cleartext-credential-transfer","description":"Authentication credentials or sensitive system communications transmitted unencrypted over networks, and absence of mutual sender/receiver authentication, enable interception, credential theft, and spoofing.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"crypto-cleartext-credential-transfer","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-crypto-cleartext-credential-transfer-b88065a1.html","id":"risk:crypto-cleartext-credential-transfer","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acrypto-cleartext-credential-transfer","sourceIds":["aiuc-1","hipaa","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Credentials and sensitive data transmitted in clear text","type":"risk","url":"/assets/agent_record-risk-crypto-cleartext-credential-transfer-b88065a1.a9caa8149d5dd221.json"},{"attributes":{"category":"cyber_security","domain":["Cryptography & Key Management","Network & Communications Security"],"inherent_rating":"high","taxonomy":["nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acrypto-counterfeit-certificates","description":"Adversary counterfeits or compromises a certificate authority so that malware or connections appear legitimate, defeating trust in TLS and code-signing and enabling man-in-the-middle or malicious-code delivery.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"low","risk_id":"crypto-counterfeit-certificates","taxonomies":["nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-crypto-counterfeit-certificates-d9dcc5c5.html","id":"risk:crypto-counterfeit-certificates","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acrypto-counterfeit-certificates","sourceIds":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Compromised or counterfeit certificates / certificate authority","type":"risk","url":"/assets/agent_record-risk-crypto-counterfeit-certificates-d9dcc5c5.8f0926d32cdc4988.json"},{"attributes":{"category":"cyber_security","domain":["Cryptography & Key Management","Data Protection & Privacy","Network & Communications Security"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acrypto-weak-or-absent-encryption","description":"Sensitive data stored or transmitted without adequate encryption, or use of weak/flawed cryptography and poor key generation, storage, rotation, and destruction — enabling interception, disclosure, or tampering of data.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"crypto-weak-or-absent-encryption","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.html","id":"risk:crypto-weak-or-absent-encryption","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acrypto-weak-or-absent-encryption","sourceIds":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Weak or absent encryption and key management","type":"risk","url":"/assets/agent_record-risk-crypto-weak-or-absent-encryption-2fe7d24e.22e603984ef2659e.json"},{"attributes":{"category":"cyber_security","domain":["Data Protection & Privacy","Network & Communications Security","Logging, Monitoring & Detection"],"inherent_rating":"critical","taxonomy":["nist-800-30-threat-event","nist-800-30-threat-source","basel-operational-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-exfiltration-espionage","description":"Adversary (outsider, insider, nation-state, or competitor) installs malware or sniffers to locate and exfiltrate sensitive/proprietary information, or steals data by external actors — including systems-security losses from hacking.","details":{"category":"cyber_security","impact":"critical","inherent_rating":"critical","likelihood":"medium","risk_id":"data-exfiltration-espionage","taxonomies":["nist-800-30-threat-event","nist-800-30-threat-source","basel-operational-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-exfiltration-espionage-74803ebc.html","id":"risk:data-exfiltration-espionage","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-exfiltration-espionage","sourceIds":["aiuc-1","cobit-2019","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Data exfiltration and theft of information by attackers","type":"risk","url":"/assets/agent_record-risk-data-exfiltration-espionage-74803ebc.a1ef3e79ab006192.json"},{"attributes":{"category":"privacy","domain":["Data Protection & Privacy","Asset Management & Inventory"],"inherent_rating":"medium","taxonomy":["iso-27005-threat","iso-27005-vulnerability","nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-residual-media-disposal","description":"Retrieval of recycled or discarded media, and disposal/reuse of storage without proper erasure, exposes residual sensitive information; also insecure/incomplete data deletion in multi-tenant/cloud environments.","details":{"category":"privacy","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"data-residual-media-disposal","taxonomies":["iso-27005-threat","iso-27005-vulnerability","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-data-residual-media-disposal-92de3d1d.html","id":"risk:data-residual-media-disposal","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Adata-residual-media-disposal","sourceIds":["iso-27001","nist-800-53","nist-csf-2","pci-dss","soc2"],"sourceUrl":null,"title":"Residual data on improperly disposed or re-used media","type":"risk","url":"/assets/agent_record-risk-data-residual-media-disposal-92de3d1d.cb159efe6720ab90.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-journal-entry-management-override","description":"Manual/automated journal entries posted with transposition errors, wrong account codes, or amounts; recurring entries not updated; and top-side entries used to override controls and manage earnings at period-end.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fin-journal-entry-management-override","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-journal-entry-management-override-b0c0ed68.html","id":"risk:fin-journal-entry-management-override","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-journal-entry-management-override","sourceIds":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Manual journal entries and management-override risk","type":"risk","url":"/assets/agent_record-risk-fin-journal-entry-management-override-b0c0ed68.9d5e8f3457283361.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-revenue-recognition-misstatement","description":"Fictitious or channel-stuffed revenue, revenue not recorded for delivered goods, incorrect transaction-price allocation or percentage-of-completion, and principal-vs-agent gross/net errors — the highest-risk assertion cluster in the revenue cycle.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fin-revenue-recognition-misstatement","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-revenue-recognition-misstatement-5e181e17.html","id":"risk:fin-revenue-recognition-misstatement","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-revenue-recognition-misstatement","sourceIds":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc2","sox"],"sourceUrl":null,"title":"Revenue-recognition misstatement (fictitious, mis-timed, mis-measured)","type":"risk","url":"/assets/agent_record-risk-fin-revenue-recognition-misstatement-5e181e17.fb867057a18ccd94.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)","Access Control & Identity Management","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["coso-erm-risk","sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-segregation-of-duties","description":"Incompatible duties (initiate, approve, record, and custody) concentrated in one role or via broad system access enable unauthorized or fraudulent transactions to be recorded and concealed.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fin-segregation-of-duties","taxonomies":["coso-erm-risk","sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-segregation-of-duties-eb7ee015.html","id":"risk:fin-segregation-of-duties","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-segregation-of-duties","sourceIds":["aiuc-1","cobit-2019","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc2","sox"],"sourceUrl":null,"title":"Segregation-of-duties conflicts in financial processes","type":"risk","url":"/assets/agent_record-risk-fin-segregation-of-duties-eb7ee015.da25c6668c301894.json"},{"attributes":{"category":"operational","domain":["Access Control & Identity Management","Risk Assessment & Management"],"inherent_rating":"high","taxonomy":["basel-operational-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afraud-external","description":"Third parties defraud the entity: cheque/payment-card forgery, counterfeit currency, identity theft, account takeover with stolen credentials, fraudulent loan applications, and first-party (bust-out) fraud by customers.","details":{"category":"operational","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"fraud-external","taxonomies":["basel-operational-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fraud-external-c3ce412f.html","id":"risk:fraud-external","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afraud-external","sourceIds":["hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"External fraud — third-party theft, forgery, payment and account fraud","type":"risk","url":"/assets/agent_record-risk-fraud-external-c3ce412f.ed2b6629b6a7dc3a.json"},{"attributes":{"category":"compliance_regulatory","domain":["Governance, Policy & Oversight","Data Protection & Privacy"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Agov-policy-absent","description":"Because documented, approved, and enforced security and privacy policies are missing and roles and duties are undefined, personnel operate without guidance on required controls and behaviours, so controls are applied inconsistently and accountability gaps leave violations undetected and unaddressed.","details":{"category":"compliance_regulatory","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"gov-policy-absent","taxonomies":["iso-27005-vulnerability","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-gov-policy-absent-cf76dbbf.html","id":"risk:gov-policy-absent","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Agov-policy-absent","sourceIds":["cobit-2019","coso-erm","coso-ic","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Missing or insufficient security and privacy policies","type":"risk","url":"/assets/agent_record-risk-gov-policy-absent-cf76dbbf.643fca249d5d0d9c.json"},{"attributes":{"category":"people_hr","domain":["Human Resources / Personnel Security","Access Control & Identity Management"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Ahr-insufficient-screening","description":"Failure to vet employees, contractors, or third parties before granting access enables insider threats or introduces compromised individuals; adversaries may deliberately place subverted individuals into (privileged) positions.","details":{"category":"people_hr","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"hr-insufficient-screening","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-hr-insufficient-screening-bdce1f80.html","id":"risk:hr-insufficient-screening","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Ahr-insufficient-screening","sourceIds":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc2"],"sourceUrl":null,"title":"Insufficient personnel screening and vetting","type":"risk","url":"/assets/agent_record-risk-hr-insufficient-screening-bdce1f80.ac42852f3377014c.json"},{"attributes":{"category":"cyber_security","domain":["Logging, Monitoring & Detection","Incident Management & Response"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Alog-missing-audit-trail","description":"Absence of logging/audit trails means unauthorized activity cannot be detected, investigated, or attributed, and adversary actions (obfuscation of intrusion detection, tampering with logs) go unnoticed.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"log-missing-audit-trail","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-log-missing-audit-trail-37d1ba80.html","id":"risk:log-missing-audit-trail","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Alog-missing-audit-trail","sourceIds":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1"],"sourceUrl":null,"title":"Missing or insufficient logging and audit trails","type":"risk","url":"/assets/agent_record-risk-log-missing-audit-trail-37d1ba80.a56f64bcd1590fed.json"},{"attributes":{"category":"cyber_security","domain":["Logging, Monitoring & Detection","Incident Management & Response"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Alog-no-monitoring-supervision","description":"Absence of monitoring mechanisms and supervision of personnel actions (especially privileged users) allows undetected misuse, and no process exists to supervise and escalate detected security breaches.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"log-no-monitoring-supervision","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-log-no-monitoring-supervision-712fe573.html","id":"risk:log-no-monitoring-supervision","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Alog-no-monitoring-supervision","sourceIds":["cobit-2019","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2"],"sourceUrl":null,"title":"No security monitoring or supervision of privileged activity","type":"risk","url":"/assets/agent_record-risk-log-no-monitoring-supervision-712fe573.f68630a803345471.json"},{"attributes":{"category":"cyber_security","domain":["Network & Communications Security","Data Protection & Privacy","Secure Configuration & Change Management"],"inherent_rating":"medium","taxonomy":["nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Anet-cloud-multitenancy-exploit","description":"Adversary exploits multi-tenancy in a cloud environment to observe organizational processes, violates isolation mechanisms, or scavenges data used and deleted by cloud processes, compromising confidentiality and availability.","details":{"category":"cyber_security","impact":"high","inherent_rating":"medium","likelihood":"low","risk_id":"net-cloud-multitenancy-exploit","taxonomies":["nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-net-cloud-multitenancy-exploit-d98521d5.html","id":"risk:net-cloud-multitenancy-exploit","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Anet-cloud-multitenancy-exploit","sourceIds":["iso-27001","nist-800-53","nist-csf-2","pci-dss","soc2"],"sourceUrl":null,"title":"Cloud multi-tenancy isolation and data-scavenging exploits","type":"risk","url":"/assets/agent_record-risk-net-cloud-multitenancy-exploit-d98521d5.107ea0205a89f496.json"},{"attributes":{"category":"cyber_security","domain":["Network & Communications Security","Cryptography & Key Management","Data Protection & Privacy"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-event","iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Anet-interception-mitm","description":"Passive monitoring/sniffing of communications, interception of unencrypted or weakly encrypted channels, wireless interception, and man-in-the-middle attacks capture or corrupt transmitted data — including TEMPEST-type emanation capture.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"net-interception-mitm","taxonomies":["iso-27005-threat","nist-800-30-threat-event","iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-net-interception-mitm-2a226fa0.html","id":"risk:net-interception-mitm","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Anet-interception-mitm","sourceIds":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Communications interception, eavesdropping and man-in-the-middle","type":"risk","url":"/assets/agent_record-risk-net-interception-mitm-2a226fa0.8d3161e822e49154.json"},{"attributes":{"category":"cyber_security","domain":["Network & Communications Security","Secure Configuration & Change Management"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Anet-poor-perimeter-architecture","description":"Because externally-facing connections lack perimeter controls (firewalls, DMZ) and the network lacks segmentation, redundancy, and defense-in-depth, attackers can breach the boundary and move laterally and single points of failure go unmitigated, resulting in intrusion, data exfiltration, and outage.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"net-poor-perimeter-architecture","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-net-poor-perimeter-architecture-26b5f06f.html","id":"risk:net-poor-perimeter-architecture","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Anet-poor-perimeter-architecture","sourceIds":["iso-27001","nist-800-53","nist-csf-2","pci-dss","soc2"],"sourceUrl":null,"title":"Poor network architecture and unprotected public connections","type":"risk","url":"/assets/agent_record-risk-net-poor-perimeter-architecture-26b5f06f.5fb9869b237d206b.json"},{"attributes":{"category":"cyber_security","domain":["Network & Communications Security","Access Control & Identity Management","Data Protection & Privacy"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Anet-remote-work-mobile-exposure","description":"Uncontrolled work outside the premises, split-tunneling, and exploitation of mobile devices/personal systems outside physical and firewall protection expose information through insecure environments and reintroduce compromised devices into the enterprise.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"net-remote-work-mobile-exposure","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-net-remote-work-mobile-exposure-d7aab6d9.html","id":"risk:net-remote-work-mobile-exposure","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Anet-remote-work-mobile-exposure","sourceIds":["hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Remote-work, mobile and split-tunneling exposure","type":"risk","url":"/assets/agent_record-risk-net-remote-work-mobile-exposure-d7aab6d9.41714f7a4174b0a6.json"},{"attributes":{"category":"cyber_security","domain":["Physical & Environmental Security","Asset Management & Inventory","Data Protection & Privacy"],"inherent_rating":"medium","taxonomy":["iso-27005-threat","nist-800-30-threat-event","iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aphys-theft-of-equipment-media","description":"Physical stealing of storage media, printouts, or computing/network equipment (including unattended laptops outside the perimeter), potentially exposing stored data. Unprotected storage locations increase exposure.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"phys-theft-of-equipment-media","taxonomies":["iso-27005-threat","nist-800-30-threat-event","iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-phys-theft-of-equipment-media-c64433e7.html","id":"risk:phys-theft-of-equipment-media","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aphys-theft-of-equipment-media","sourceIds":["hipaa","iso-27001","nist-800-53","nist-csf-2","pci-dss","soc1","soc2"],"sourceUrl":null,"title":"Theft of equipment, media or unattended devices","type":"risk","url":"/assets/agent_record-risk-phys-theft-of-equipment-media-c64433e7.7787aba41dfbdeb8.json"},{"attributes":{"category":"cyber_security","domain":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Asdlc-insecure-privileged-apps","description":"Applications or services running under privileged accounts, opening unnecessary network connections, or lacking secure-by-design architecture mean a single compromise grants broad system access and expands attack surface.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"sdlc-insecure-privileged-apps","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-sdlc-insecure-privileged-apps-ce55ff82.html","id":"risk:sdlc-insecure-privileged-apps","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Asdlc-insecure-privileged-apps","sourceIds":["aiuc-1","cobit-2019","eu-ai-act","gdpr","iso-27001","nist-800-53","nist-csf-2","pci-dss","sox"],"sourceUrl":null,"title":"Applications running with excessive privilege / insecure design","type":"risk","url":"/assets/agent_record-risk-sdlc-insecure-privileged-apps-ce55ff82.5767a162eb94efe8.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:04e26852f85ae560cc2faefa344b240a5afd02d2203f703d89c20ee38b4211de","properties":{"rationale":"Segregation of duties across the revenue cycle directly prevents one party initiating and recording fictitious or mis-timed revenue.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/risk-fin-revenue-recognition-misstatement-5e181e17.json","targetId":"risk:fin-revenue-recognition-misstatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:063060d7603f6af8c065329c0c8eefd22436f7e6a4e260f64eee291743bcc704","properties":{"control_id":"PCI-Req5","coverage":"full","delta":null,"framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-05-5870fcee.json","sourceId":"uc:UC-VULN-05","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req5-85f2abb2.json","targetId":"ctrl:pci-dss:PCI-Req5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0829af2246a85e7e5cc486581d228bba50e080557016bad92e46f06a89d07cae","properties":{"rationale":"Maintaining policies required by HIPAA/PCI/regulators reduces enforcement exposure for missing governance documentation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/risk-compliance-litigation-enforcement-25e7935d.json","targetId":"risk:compliance-litigation-enforcement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0dce2b553d8180d563cc2e7c6531b355e611e4d980a6a281d29355e9bca8080d","properties":{"control_id":"PCI-Req3","coverage":"partial","delta":"key-management requirements (3.6-3.7) satisfied by the key lifecycle control; SAD-not-stored-after-authorization (3.3) and PAN display masking (3.4) also fall outside this control's scope","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req3-e250c900.json","targetId":"ctrl:pci-dss:PCI-Req3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1206dd825a735b202f1e7ac664fecccb42ae6ebd257bbebb8dfa10c8a0900d59","properties":{"control_id":"PCI-Req1","coverage":"partial","delta":"also mandates dedicated network security controls and periodic ruleset reviews","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-config-01-8f911a32.json","sourceId":"uc:UC-CONFIG-01","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req1-c3c41ca4.json","targetId":"ctrl:pci-dss:PCI-Req1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:13f64e9bd86f0bc703948908c3cf78914b528e48bfb571ac0392522a46ce644f","properties":{"rationale":"Requires trusted certificates and rejects insecure fallback, helping reject rogue certs in MITM; the operative approved-CA/revocation defense sits in UC-CRYPTO-03.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/risk-crypto-counterfeit-certificates-d9dcc5c5.json","targetId":"risk:crypto-counterfeit-certificates","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:13f6aa7b3ed4b184eafd7da0757ae79318f89b1a9d20ab92bf53261aceb57e32","properties":{"rationale":"Establishing, approving, and maintaining the security policy suite directly remedies missing approved policies.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:15e92c1e1284f358205d750de51a3b8c7690252a0cb5ba2023fe594b59986692","properties":{"rationale":"Hardening network security controls (e.g., firewall baselines) contributes to boundary protection, but segmentation/DMZ architecture is the operative defense.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-config-01-8f911a32.json","sourceId":"uc:UC-CONFIG-01","targetDetailPath":"/data/v1/records/risk-net-poor-perimeter-architecture-26b5f06f.json","targetId":"risk:net-poor-perimeter-architecture","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1a84fcd4490ea6a7bf0096c5b200da0f8e1abc61657a295dcfc63076d89063ab","properties":{"rationale":"Secure baselines plus least functionality (disabling unnecessary ports/protocols/services) remove the misconfigurations and unauthorized services attackers exploit.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-config-01-8f911a32.json","sourceId":"uc:UC-CONFIG-01","targetDetailPath":"/data/v1/records/risk-config-internet-exposed-misconfig-61b3613a.json","targetId":"risk:config-internet-exposed-misconfig","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1b2737972642d38c22017c0d989ded07cce70c5b3b2852d363f78b49ce6fb84b","properties":{"rationale":"Sanitizing/destroying media before disposal or reuse and verifying unrecoverability directly prevents residual-data exposure.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/risk-data-residual-media-disposal-92de3d1d.json","targetId":"risk:data-residual-media-disposal","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2074d0f084b76bdfe167ce45000d2fa46b45add1329409e1674eafb21bddefe8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req12-cd77be1e.json","sourceId":"ctrl:pci-dss:PCI-Req12","targetDetailPath":"/data/v1/records/std-pci-dss-5d652b0a.json","targetId":"std:pci-dss","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:34cbd2a80158a94ce449d2367d9e0b1460197c30e637e3b46447d5bd42550b40","properties":{"control_id":"PCI-Req10","coverage":"partial","delta":"also requires daily review, 12-month retention, time synchronization, log protection","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req10-c587ee2b.json","targetId":"ctrl:pci-dss:PCI-Req10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:371713ad7bcf1d0ad6654e3d9c27a8204a0ecedb98b6b08e53ca86bb0aaaa12d","properties":{"control_id":"PCI-Req11","coverage":"partial","delta":"also requires quarterly vulnerability scans, intrusion detection, and change-detection mechanisms","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req11-ee0fcd89.json","targetId":"ctrl:pci-dss:PCI-Req11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3bf918c221bc66e61850d0f674e98237a85a435c9d46d7d5a5942917da92de86","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req2-586d7ab1.json","sourceId":"ctrl:pci-dss:PCI-Req2","targetDetailPath":"/data/v1/records/std-pci-dss-5d652b0a.json","targetId":"std:pci-dss","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4aa9422606d9d7c9b4dd311d484e6623d18475b48439149993fc9f3b1012f244","properties":{"rationale":"Enforced MFA for remote access reduces credential compromise from insecure off-premises environments.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/risk-net-remote-work-mobile-exposure-d7aab6d9.json","targetId":"risk:net-remote-work-mobile-exposure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4d9e30332c1330449ba99b94d0056178c956e25dd133bf900db6b7d45bee4bf9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req6-f2566fc6.json","sourceId":"ctrl:pci-dss:PCI-Req6","targetDetailPath":"/data/v1/records/std-pci-dss-5d652b0a.json","targetId":"std:pci-dss","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:539d6269f1b8d523fe4babe83874b06eea8bd7b7f12e4aceead61cb24f28f376","properties":{"rationale":"Establishing enforced baselines and monitoring/remediating deviations is the direct defense against insecure configuration drift.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-config-01-8f911a32.json","sourceId":"uc:UC-CONFIG-01","targetDetailPath":"/data/v1/records/risk-config-poor-baseline-drift-2dd66324.json","targetId":"risk:config-poor-baseline-drift","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5ad2c6406f9f0fa7498762738fb631294c5b18cc81d5f508ed69dc896e35b3cc","properties":{"control_id":"PCI-Req8","coverage":"partial","delta":"account lockout and idle timeout satisfied by session/logon controls; credential lifecycle parameters (8.3.5-8.3.9), MFA implementation integrity (8.5), and shared/system/application account controls (8.2.2, 8.6) satisfied by companion credential- and account-management controls","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req8-fe6b4517.json","targetId":"ctrl:pci-dss:PCI-Req8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5d617594d25b8a41b14088d5998a1bdf055119fb9f57b2e22f2d2fb80e0dae91","properties":{"rationale":"MFA with credential validation only over protected channels directly remediates absent MFA and clear-text authentication.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/risk-access-weak-authentication-4e35bdb2.json","targetId":"risk:access-weak-authentication","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5e83cddd96642d47f06584770147e7c8a8b81733d53e3509362bfb8cb0dbed9d","properties":{"control_id":"PCI-Req12","coverage":"partial","delta":"also requires awareness, screening, third-party management, and incident response program elements","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req12-cd77be1e.json","targetId":"ctrl:pci-dss:PCI-Req12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5f5809d49ab7f3abff72cccb34db613597c34c29670145f4ce754792d2714710","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req7-e7336c72.json","sourceId":"ctrl:pci-dss:PCI-Req7","targetDetailPath":"/data/v1/records/std-pci-dss-5d652b0a.json","targetId":"std:pci-dss","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5fbee0dc9cf1b50558899bd4b0743fd057e10740ff2bb8167d4af02f95b7e669","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req11-ee0fcd89.json","sourceId":"ctrl:pci-dss:PCI-Req11","targetDetailPath":"/data/v1/records/std-pci-dss-5d652b0a.json","targetId":"std:pci-dss","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6b0e2907e13d46998e9376b605eb08b0908bcf8798a0c6534b3b58c78bacb4be","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req9-987072c1.json","sourceId":"ctrl:pci-dss:PCI-Req9","targetDetailPath":"/data/v1/records/std-pci-dss-5d652b0a.json","targetId":"std:pci-dss","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:70e5368a60517c7d1a5a902712327d0eeb1490207b7cd6b11878bae290665e84","properties":{"rationale":"Enabling audit logging across all systems for a defined security-event catalog directly eliminates absent/insufficient audit trails.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/risk-log-missing-audit-trail-37d1ba80.json","targetId":"risk:log-missing-audit-trail","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:72f2f56ed842044eb3de32bf36817661690a614e723a5968076b33ae0a52bed4","properties":{"control_id":"PCI-Req4","coverage":"full","delta":null,"framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req4-e571f282.json","targetId":"ctrl:pci-dss:PCI-Req4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:741c673d16a15884ad61fe5b0caa052bafebadd5eb06fda10e428c43b3c7042b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req3-e250c900.json","sourceId":"ctrl:pci-dss:PCI-Req3","targetDetailPath":"/data/v1/records/std-pci-dss-5d652b0a.json","targetId":"std:pci-dss","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7b637a77c95000088af42201ef97e2c4fe6da67e45bbee83d5897628dcb29bc4","properties":{"rationale":"Least privilege constrains authorized users from reaching resources beyond their authorization.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/risk-access-unauthorized-use-equipment-d2082944.json","targetId":"risk:access-unauthorized-use-equipment","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:890bf8da11cb7f136445bc7254e5e059e3be8727c721c89359c4465a8164c786","properties":{"control_id":"PCI-Req9","coverage":"partial","delta":"media lifecycle (9.4) is covered; facility entry controls and personnel/visitor access management (9.2-9.3) satisfied by physical-access companion controls; POI terminal anti-tampering and periodic inspection (9.5) not covered by this control","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req9-987072c1.json","targetId":"ctrl:pci-dss:PCI-Req9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:89434b84abc1f459e41807615c2b707092e06b2fa2b207ade2d05148cff70535","properties":{"control_id":"PCI-Req2","coverage":"full","delta":null,"framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-config-01-8f911a32.json","sourceId":"uc:UC-CONFIG-01","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req2-586d7ab1.json","targetId":"ctrl:pci-dss:PCI-Req2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8970c33bddd154c3cef76c7c7d82e5a8d118c74e982d2ab08a338dc51797f3fa","properties":{"rationale":"Renders data at rest unreadable and encrypts data in transit with strong cryptography, directly closing the absent/inadequate-encryption exposure for stored and transmitted data.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.json","targetId":"risk:crypto-weak-or-absent-encryption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8a1bedef1aaa9b750d6d6bf268da2b0d3ff78a02e84946ef8bb3957f919e4f0f","properties":{"rationale":"Engineering security from design onward with secure-coding standards is the secure-by-design defense against insecurely designed, over-privileged applications.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-config-04-ed033b30.json","sourceId":"uc:UC-CONFIG-04","targetDetailPath":"/data/v1/records/risk-sdlc-insecure-privileged-apps-ce55ff82.json","targetId":"risk:sdlc-insecure-privileged-apps","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:915450fe437de9c41fe1f09784091126bfa1e23305d0e0648e4424113fa2f41e","properties":{"control_id":"PCI-Req6","coverage":"partial","delta":"also requires protections for public-facing web applications","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-config-04-ed033b30.json","sourceId":"uc:UC-CONFIG-04","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req6-f2566fc6.json","targetId":"ctrl:pci-dss:PCI-Req6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:916199d011646f8082ba3af42d5417a6a764bb27e8b965336bc420149a59b858","properties":{"rationale":"A defined, system-enforced SoD conflict matrix directly prevents concentration of incompatible duties.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/risk-fin-segregation-of-duties-eb7ee015.json","targetId":"risk:fin-segregation-of-duties","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9935945393513b4a14485399044b0e20fcd76d7f8984dea1d888d1ee0dab2967","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req8-fe6b4517.json","sourceId":"ctrl:pci-dss:PCI-Req8","targetDetailPath":"/data/v1/records/std-pci-dss-5d652b0a.json","targetId":"std:pci-dss","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a7da59065613ede3740dad783a788bcdc502c2f193696c8d8be8b2a3c5f70637","properties":{"rationale":"Logging authentication and privileged actions creates the accountability record that detects rights abuse and defeats repudiation of actions.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/risk-access-privilege-abuse-repudiation-343a8917.json","targetId":"risk:access-privilege-abuse-repudiation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a852fde1f10ba35688d3624c699877fc476765a55836e189ab22c6a7568cf5d4","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req5-85f2abb2.json","sourceId":"ctrl:pci-dss:PCI-Req5","targetDetailPath":"/data/v1/records/std-pci-dss-5d652b0a.json","targetId":"std:pci-dss","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:aebdccc9f405dd52e0939ff45911ee81ee0c822ba4c9b24413cee228d2f87b03","properties":{"rationale":"Least privilege bounds the blast radius of an inadequately vetted insider, reducing impact if a poorly screened individual turns malicious.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/risk-hr-insufficient-screening-bdce1f80.json","targetId":"risk:hr-insufficient-screening","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b312a3465956656f933a2d24079ffb3960496f2c22e14a96ad449d31cfe0d456","properties":{"rationale":"Mandates strong encryption of data in transit over all public/external networks and rejects fallback to insecure protocols, directly preventing credentials and sensitive comms from crossing the wire in clear text.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/risk-crypto-cleartext-credential-transfer-b88065a1.json","targetId":"risk:crypto-cleartext-credential-transfer","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c8436cf942803f6684548623379ec24ed1adf724f2ef38897a2c22b83c5b428f","properties":{"rationale":"MFA blocks account takeover even when a password is phished, the canonical defense against credential-harvesting social engineering.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/risk-aware-phishing-social-engineering-bb9b7bd6.json","targetId":"risk:aware-phishing-social-engineering","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c89ca9f8771af20ad6582655b50cfedd03f5d1d4da698ac229900503a4b30e76","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req1-c3c41ca4.json","sourceId":"ctrl:pci-dss:PCI-Req1","targetDetailPath":"/data/v1/records/std-pci-dss-5d652b0a.json","targetId":"std:pci-dss","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cd2cecf6fd40aa5ecd4bd0d4f288a3f5036c7caf45a3b46720179be93733e7b9","properties":{"rationale":"Roles defaulting to least privilege on need-to-know are the direct defense against overly broad or wrongly assigned access rights.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/risk-access-excess-privilege-cd8adadc.json","targetId":"risk:access-excess-privilege","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d19474d3402dfb5476a670d3319f08ffa741445f35f34dc56aa1e45ffac22ae5","properties":{"rationale":"Need-to-know least privilege directly limits the scope available for abuse of rights and privilege escalation.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/risk-access-privilege-abuse-repudiation-343a8917.json","targetId":"risk:access-privilege-abuse-repudiation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d3158996dd1e69959ea6479d7a90da8f3611ca01ebed079ea2d3c5711e71f800","properties":{"rationale":"Physically securing media by classification and restricting access to it directly reduces theft of stored media.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/risk-phys-theft-of-equipment-media-c64433e7.json","targetId":"risk:phys-theft-of-equipment-media","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d6f3a676ea5fc6d8be8471d019e11b8f3759794f143c882b6037de97615de4d8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req10-c587ee2b.json","sourceId":"ctrl:pci-dss:PCI-Req10","targetDetailPath":"/data/v1/records/std-pci-dss-5d652b0a.json","targetId":"std:pci-dss","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d88f15573d6e7e64057fe96be5cebce989059e30170983ede39fb2c3dabe10b6","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req4-e571f282.json","sourceId":"ctrl:pci-dss:PCI-Req4","targetDetailPath":"/data/v1/records/std-pci-dss-5d652b0a.json","targetId":"std:pci-dss","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d8d42bf85ad8b78bd895f84c62c95e0675bfd71b283e9534f0fc444210b33e94","properties":{"rationale":"Logging access to sensitive/regulated (e.g., cardholder) data provides a targeted detection input for locating and investigating exfiltration.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/risk-data-exfiltration-espionage-74803ebc.json","targetId":"risk:data-exfiltration-espionage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:da4a8461f4f084180b5ecbd3cb3d3ddda5a44a288eb2010d2de3b81ddbaea663","properties":{"rationale":"SoD separating request from approve limits any one person posting and approving unauthorized journal entries.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/risk-fin-journal-entry-management-override-b0c0ed68.json","targetId":"risk:fin-journal-entry-management-override","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e4632b900396dc6c7410ef9ed56bae45ef8e045dfe089098dd265a1e59338d80","properties":{"rationale":"Strong in-transit encryption defeats passive sniffing/eavesdropping while trusted certificates and no-insecure-fallback block man-in-the-middle on public networks.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/risk-net-interception-mitm-2a226fa0.json","targetId":"risk:net-interception-mitm","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e87c480c0bb2933a8509552f48ac75c5ade41b1458f0d7bab2cd9adfe1f5aeb6","properties":{"rationale":"Logging privileged actions is the prerequisite record that makes supervision of privileged activity possible.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/risk-log-no-monitoring-supervision-712fe573.json","targetId":"risk:log-no-monitoring-supervision","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ed3d957ba80b91b31fcbf1893ac766437567bfb612d054b4a1771afe8da54715","properties":{"control_id":"PCI-Req7","coverage":"partial","delta":"semiannual review of all user accounts and privileges (7.2.4) not covered","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req7-e7336c72.json","targetId":"ctrl:pci-dss:PCI-Req7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f07963e4887c624ba43be5f12f38e718a2d0613f0c67a2f78dee9e8379a08d9c","properties":{"rationale":"Restricting removable-media use to authorized personnel and approved types directly prevents uncontrolled copying to removable devices.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/risk-asset-uncontrolled-copying-removable-media-4a9604c7.json","targetId":"risk:asset-uncontrolled-copying-removable-media","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f62bc12363b88d2a2532db52ba69792e4010cf7b96f0aa647a145a846a23c2a7","properties":{"rationale":"MFA directly defeats account takeover using stolen credentials.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/risk-fraud-external-c3ce412f.json","targetId":"risk:fraud-external","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fc5893a398befb9e8398d5b226f2e2a3c6b6847c478d429db61ecc678d2acf00","properties":{"rationale":"Enforcing secure configuration baselines reduces the cloud/IAM misconfigurations that break tenant isolation, though platform isolation is the operative defense.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-config-01-8f911a32.json","sourceId":"uc:UC-CONFIG-01","targetDetailPath":"/data/v1/records/risk-net-cloud-multitenancy-exploit-d98521d5.json","targetId":"risk:net-cloud-multitenancy-exploit","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fd93e502fdfb4e7f9ef0a6fc557d02f6b10e37e080f75bef72d5722fcaa80939","properties":{"rationale":"External-perspective testing directly probes and discovers internet-exposed and misconfigured systems.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/risk-config-internet-exposed-misconfig-61b3613a.json","targetId":"risk:config-internet-exposed-misconfig","type":"mitigates"}],"schemaVersion":1,"scope":"sources","total":84}
