{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["risk:access-excess-privilege","risk:access-privilege-abuse-repudiation","risk:access-provisioning-review-gap","risk:access-unauthorized-use-equipment","risk:ai-emergent-integration-risk","risk:aware-user-error-mishandling","risk:bcdr-it-resilience-outage","risk:bcdr-no-tested-continuity-plan","risk:config-poor-baseline-drift","risk:config-weak-change-control","risk:cyber-adversary-threat-sources","risk:fin-accuracy-measurement-errors","risk:fin-completeness-understatement","risk:fin-cutoff-period-errors","risk:fin-data-quality-reporting-integrity","risk:fin-existence-overstatement","risk:fin-journal-entry-management-override","risk:log-missing-audit-trail","risk:log-no-monitoring-supervision","risk:ops-process-execution-errors","risk:phys-cyber-physical-facility-attack","risk:phys-environmental-degradation","risk:phys-fire-water-suppression-gap","risk:phys-inadequate-facility-access","risk:phys-theft-of-equipment-media","risk:tech-hardware-equipment-failure","risk:tech-loss-essential-services","risk:tech-software-system-failure"],"directIds":["ctrl:soc1:SOC1-1","ctrl:soc1:SOC1-10","ctrl:soc1:SOC1-11","ctrl:soc1:SOC1-12","ctrl:soc1:SOC1-2","ctrl:soc1:SOC1-3","ctrl:soc1:SOC1-4","ctrl:soc1:SOC1-5","ctrl:soc1:SOC1-6","ctrl:soc1:SOC1-7","ctrl:soc1:SOC1-8","ctrl:soc1:SOC1-9"],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"SOC 1","next":"/assets/agent_sources-soc1-2.0fa6a91afec11114.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"technical","framework":"soc1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc1/","description":"Logical access — controls provide reasonable assurance that logical access to applications, data, and infrastructure is restricted to authorized and appropriate users (authentication, authorization, provisioning/deprovisioning, periodic access review, privileged access).","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-1","control_type":"preventive","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc1-soc1-1-bfab4a41.html","id":"ctrl:soc1:SOC1-1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc1%3ASOC1-1","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-1 — Logical access — controls provide reasonable assurance that logical access to applications, data, and infrastructure is restricted to authorized and appropriate users (authentication, authorization, provisioning/deprovisioning, periodic access review, privileged access).","type":"control","url":"/assets/agent_record-ctrl-soc1-soc1-1-bfab4a41.0bd41e0356b74e62.json"},{"attributes":{"category":"physical","framework":"soc1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc1/","description":"Physical security and environmental controls — controls provide reasonable assurance that physical access to facilities and data centers is restricted and that environmental protections safeguard systems.","details":{"automation":"hybrid","control_category":"physical","control_id":"SOC1-10","control_type":"preventive","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc1-soc1-10-43ef0cd6.html","id":"ctrl:soc1:SOC1-10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc1%3ASOC1-10","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-10 — Physical security and environmental controls — controls provide reasonable assurance that physical access to facilities and data centers is restricted and that environmental protections safeguard systems.","type":"control","url":"/assets/agent_record-ctrl-soc1-soc1-10-43ef0cd6.f01976eb0f3ede92.json"},{"attributes":{"category":"technical","framework":"soc1","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/soc1/","description":"System monitoring and incident management — controls provide reasonable assurance that system performance, security events, and incidents are monitored, identified, and resolved.","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-11","control_type":"detective","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc1-soc1-11-9b7842c1.html","id":"ctrl:soc1:SOC1-11","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc1%3ASOC1-11","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-11 — System monitoring and incident management — controls provide reasonable assurance that system performance, security events, and incidents are monitored, identified, and resolved.","type":"control","url":"/assets/agent_record-ctrl-soc1-soc1-11-9b7842c1.1638e69d469ee9eb.json"},{"attributes":{"category":"administrative","framework":"soc1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc1/","description":"Vendor / subservice organization management — controls provide reasonable assurance that subservice organizations relevant to user entities' ICFR are appropriately managed and monitored.","details":{"automation":"manual","control_category":"administrative","control_id":"SOC1-12","control_type":"preventive","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc1-soc1-12-05ba06e4.html","id":"ctrl:soc1:SOC1-12","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc1%3ASOC1-12","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-12 — Vendor / subservice organization management — controls provide reasonable assurance that subservice organizations relevant to user entities' ICFR are appropriately managed and monitored.","type":"control","url":"/assets/agent_record-ctrl-soc1-soc1-12-05ba06e4.9efb1c9f3412e320.json"},{"attributes":{"category":"technical","framework":"soc1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc1/","description":"Change management — controls provide reasonable assurance that changes to applications and infrastructure are authorized, tested, approved, and migrated to production appropriately.","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-2","control_type":"preventive","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc1-soc1-2-7fcfb329.html","id":"ctrl:soc1:SOC1-2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc1%3ASOC1-2","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-2 — Change management — controls provide reasonable assurance that changes to applications and infrastructure are authorized, tested, approved, and migrated to production appropriately.","type":"control","url":"/assets/agent_record-ctrl-soc1-soc1-2-7fcfb329.a00cc3b0cd8a9d3a.json"},{"attributes":{"category":"technical","framework":"soc1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc1/","description":"Program development / SDLC — controls provide reasonable assurance that new systems and applications are developed, tested, approved, and implemented in accordance with management's intent.","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-3","control_type":"preventive","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc1-soc1-3-762891cb.html","id":"ctrl:soc1:SOC1-3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc1%3ASOC1-3","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-3 — Program development / SDLC — controls provide reasonable assurance that new systems and applications are developed, tested, approved, and implemented in accordance with management's intent.","type":"control","url":"/assets/agent_record-ctrl-soc1-soc1-3-762891cb.a48f46a87c75672f.json"},{"attributes":{"category":"technical","framework":"soc1","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/soc1/","description":"Computer operations / job scheduling — controls provide reasonable assurance that production batch jobs and scheduled processing are appropriately defined, executed, monitored, and that exceptions/failures are identified and resolved.","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-4","control_type":"detective","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc1-soc1-4-2584ed29.html","id":"ctrl:soc1:SOC1-4","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc1%3ASOC1-4","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-4 — Computer operations / job scheduling — controls provide reasonable assurance that production batch jobs and scheduled processing are appropriately defined, executed, monitored, and that exceptions/failures are identified and resolved.","type":"control","url":"/assets/agent_record-ctrl-soc1-soc1-4-2584ed29.8fb3e293f112f68a.json"},{"attributes":{"category":"technical","framework":"soc1","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/soc1/","description":"Backup and recovery — controls provide reasonable assurance that data is backed up, retained, and recoverable, and that restoration is tested.","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-5","control_type":"corrective","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc1-soc1-5-d064ade6.html","id":"ctrl:soc1:SOC1-5","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc1%3ASOC1-5","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-5 — Backup and recovery — controls provide reasonable assurance that data is backed up, retained, and recoverable, and that restoration is tested.","type":"control","url":"/assets/agent_record-ctrl-soc1-soc1-5-d064ade6.9c65a331c11ac30f.json"},{"attributes":{"category":"technical","framework":"soc1","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/soc1/","description":"Data transmission / interface controls — controls provide reasonable assurance that data transmitted to and from the system and across interfaces is complete, accurate, authorized, and timely.","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-6","control_type":"detective","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":7,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc1-soc1-6-b85280f6.html","id":"ctrl:soc1:SOC1-6","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc1%3ASOC1-6","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-6 — Data transmission / interface controls — controls provide reasonable assurance that data transmitted to and from the system and across interfaces is complete, accurate, authorized, and timely.","type":"control","url":"/assets/agent_record-ctrl-soc1-soc1-6-b85280f6.694a0ddb3471c014.json"},{"attributes":{"category":"technical","framework":"soc1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc1/","description":"Data input — controls provide reasonable assurance that transactions and data input into the system are complete, accurate, and authorized.","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-7","control_type":"preventive","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":7,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc1-soc1-7-20ea752e.html","id":"ctrl:soc1:SOC1-7","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc1%3ASOC1-7","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-7 — Data input — controls provide reasonable assurance that transactions and data input into the system are complete, accurate, and authorized.","type":"control","url":"/assets/agent_record-ctrl-soc1-soc1-7-20ea752e.9010e2b07e6101f5.json"},{"attributes":{"category":"technical","framework":"soc1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc1/","description":"Data processing — controls provide reasonable assurance that transactions are processed completely, accurately, and in the proper period.","details":{"automation":"automated","control_category":"technical","control_id":"SOC1-8","control_type":"preventive","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":7,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc1-soc1-8-9602488c.html","id":"ctrl:soc1:SOC1-8","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc1%3ASOC1-8","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-8 — Data processing — controls provide reasonable assurance that transactions are processed completely, accurately, and in the proper period.","type":"control","url":"/assets/agent_record-ctrl-soc1-soc1-8-9602488c.dfdcee41ee83d723.json"},{"attributes":{"category":"technical","framework":"soc1","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/soc1/","description":"Data output / reporting — controls provide reasonable assurance that output and reports provided to user entities are complete, accurate, and distributed only to authorized recipients.","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-9","control_type":"detective","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":7,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc1-soc1-9-7278adb1.html","id":"ctrl:soc1:SOC1-9","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc1%3ASOC1-9","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-9 — Data output / reporting — controls provide reasonable assurance that output and reports provided to user entities are complete, accurate, and distributed only to authorized recipients.","type":"control","url":"/assets/agent_record-ctrl-soc1-soc1-9-7278adb1.9e9afb495d038730.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management","Data Protection & Privacy"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-excess-privilege","description":"Overly broad or wrongly assigned access rights, applications/services running with excessive privileges, and failure to enforce least privilege — a compromise or insider then gains broad access to systems and data.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"access-excess-privilege","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-access-excess-privilege-cd8adadc.html","id":"risk:access-excess-privilege","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-excess-privilege","sourceIds":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Excessive privilege and wrong assignment of access rights","type":"risk","url":"/assets/agent_record-risk-access-excess-privilege-cd8adadc.c154ceb8157b770a.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-privilege-abuse-repudiation","description":"Authorized users or administrators exploit legitimate access beyond permitted scope, fabricate or forge credentials/rights to gain privileges, and repudiate performed actions — undermining accountability and audit-trail integrity.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"access-privilege-abuse-repudiation","taxonomies":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-access-privilege-abuse-repudiation-343a8917.html","id":"risk:access-privilege-abuse-repudiation","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-privilege-abuse-repudiation","sourceIds":["aiuc-1","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Abuse of rights, forged rights, and repudiation of actions","type":"risk","url":"/assets/agent_record-risk-access-privilege-abuse-repudiation-343a8917.5dfe55c5d06b0530.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-provisioning-review-gap","description":"No formal user registration/de-registration procedure and no periodic access-rights review, so orphaned or excessive accounts accumulate and access is not revoked when roles change or personnel leave.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"access-provisioning-review-gap","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-access-provisioning-review-gap-dc152038.html","id":"risk:access-provisioning-review-gap","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-provisioning-review-gap","sourceIds":["iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","soc1","soc2","sox"],"sourceUrl":null,"title":"Weak account provisioning/de-registration and access review","type":"risk","url":"/assets/agent_record-risk-access-provisioning-review-gap-dc152038.95f8a2aeb24acc6e.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management"],"inherent_rating":"medium","taxonomy":["iso-27005-threat","nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-unauthorized-use-equipment","description":"Use of systems, networks, or devices without authorization, and users with authorized access reaching resources that exceed their authorization, potentially to exfiltrate data or conduct attacks.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"access-unauthorized-use-equipment","taxonomies":["iso-27005-threat","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-access-unauthorized-use-equipment-d2082944.html","id":"risk:access-unauthorized-use-equipment","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-unauthorized-use-equipment","sourceIds":["aiuc-1","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Unauthorized use of equipment and unauthorized access escalation","type":"risk","url":"/assets/agent_record-risk-access-unauthorized-use-equipment-d2082944.659ef798ce61ee67.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Secure Development (SDLC) & Application Security"],"inherent_rating":"medium","taxonomy":["iso-23894-ai-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-emergent-integration-risk","description":"Large-scale or multi-model pipelines exhibit emergent capabilities/failures not present in any component and not predictable from component testing; integration with legacy systems introduces interface mismatches and configuration errors.","details":{"category":"ai_governance","impact":"high","inherent_rating":"medium","likelihood":"medium","risk_id":"ai-emergent-integration-risk","taxonomies":["iso-23894-ai-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ai-emergent-integration-risk-8490271c.html","id":"risk:ai-emergent-integration-risk","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-emergent-integration-risk","sourceIds":["aiuc-1","cobit-2019","eu-ai-act","iso-27001","iso-42001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","soc1","soc2","sox"],"sourceUrl":null,"title":"Emergent behaviour and unsafe AI system integration","type":"risk","url":"/assets/agent_record-risk-ai-emergent-integration-risk-8490271c.7c427d5d71af8a3d.json"},{"attributes":{"category":"operational","domain":["Awareness & Training","Data Protection & Privacy","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source","iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaware-user-error-mishandling","description":"Authorized users make mistakes — incorrect data entry, misconfiguration, improper procedures, incorrect privilege settings, or spilling/mishandling sensitive information — causing harm to information assets without malicious intent.","details":{"category":"operational","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"aware-user-error-mishandling","taxonomies":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source","iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-aware-user-error-mishandling-149a1d3b.html","id":"risk:aware-user-error-mishandling","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaware-user-error-mishandling","sourceIds":["aiuc-1","gdpr","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"User error and mishandling of sensitive information","type":"risk","url":"/assets/agent_record-risk-aware-user-error-mishandling-149a1d3b.111c3fa544df22a0.json"},{"attributes":{"category":"business_continuity","domain":["Business Continuity & Disaster Recovery","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["coso-erm-risk","basel-operational-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Abcdr-it-resilience-outage","description":"Critical technology infrastructure or applications experience unplanned outages, data loss, or prolonged recovery times — including failure of DR systems to activate — disrupting operations and harming stakeholders.","details":{"category":"business_continuity","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"bcdr-it-resilience-outage","taxonomies":["coso-erm-risk","basel-operational-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-bcdr-it-resilience-outage-18dfc108.html","id":"risk:bcdr-it-resilience-outage","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Abcdr-it-resilience-outage","sourceIds":["cobit-2019","dora","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"sourceUrl":null,"title":"IT resilience failure — unplanned outage, data loss, slow recovery","type":"risk","url":"/assets/agent_record-risk-bcdr-it-resilience-outage-18dfc108.676c731632e2a885.json"},{"attributes":{"category":"business_continuity","domain":["Business Continuity & Disaster Recovery","Risk Assessment & Management"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk","iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Abcdr-no-tested-continuity-plan","description":"No BCP/DR plan, or plans that exist but have never been exercised end-to-end, so a natural disaster, pandemic, civil unrest, or infrastructure failure disables critical processes with no tested recovery path.","details":{"category":"business_continuity","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"bcdr-no-tested-continuity-plan","taxonomies":["enterprise-risk","coso-erm-risk","iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-bcdr-no-tested-continuity-plan-d4d9e7a9.html","id":"risk:bcdr-no-tested-continuity-plan","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Abcdr-no-tested-continuity-plan","sourceIds":["cobit-2019","dora","iso-27001","nist-800-53","nydfs-500","soc1","soc2","sox"],"sourceUrl":null,"title":"Absent or untested business continuity / disaster recovery plan","type":"risk","url":"/assets/agent_record-risk-bcdr-no-tested-continuity-plan-d4d9e7a9.2e628816044d5241.json"},{"attributes":{"category":"cyber_security","domain":["Secure Configuration & Change Management","Vulnerability & Patch Management"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aconfig-poor-baseline-drift","description":"Without documented, enforced baseline configurations and change control, systems drift into insecure states, contain unauthorized changes, or expose unnecessary network services, expanding attack surface.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"config-poor-baseline-drift","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-config-poor-baseline-drift-2dd66324.html","id":"risk:config-poor-baseline-drift","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aconfig-poor-baseline-drift","sourceIds":["coso-ic","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Poor configuration management and insecure baseline drift","type":"risk","url":"/assets/agent_record-risk-config-poor-baseline-drift-2dd66324.de11f6b9169c61ac.json"},{"attributes":{"category":"cyber_security","domain":["Secure Configuration & Change Management","Secure Development (SDLC) & Application Security"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aconfig-weak-change-control","description":"Changes to systems, software, hardware, or configurations without formal approval and testing (including unauthorized or poorly tested hardware/config changes) introduce new vulnerabilities, instability, or failed releases.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"config-weak-change-control","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-config-weak-change-control-e7d90eaf.html","id":"risk:config-weak-change-control","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aconfig-weak-change-control","sourceIds":["cobit-2019","coso-ic","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"sourceUrl":null,"title":"Absent or weak change-control procedures","type":"risk","url":"/assets/agent_record-risk-config-weak-change-control-e7d90eaf.0118c76865b2782b.json"},{"attributes":{"category":"cyber_security","domain":["Risk Assessment & Management","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["nist-800-30-threat-source"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acyber-adversary-threat-sources","description":"Because capable, motivated threat actors - outsiders, privileged and non-privileged insiders, organized groups, competitors, malicious partners or suppliers, and nation-states - actively target the organization's cyber resources, deliberate attacks are attempted against its systems and data, resulting in compromise, disruption, or theft when defenses are outmatched.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"cyber-adversary-threat-sources","taxonomies":["nist-800-30-threat-source"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-cyber-adversary-threat-sources-fa9e3003.html","id":"risk:cyber-adversary-threat-sources","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acyber-adversary-threat-sources","sourceIds":["aiuc-1","cobit-2019","coso-ic","gdpr","iso-27001","iso-31000","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2","sox"],"sourceUrl":null,"title":"Attacks by capable, motivated threat actors","type":"risk","url":"/assets/agent_record-risk-cyber-adversary-threat-sources-fa9e3003.8ace32770a775a42.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)"],"inherent_rating":"medium","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-accuracy-measurement-errors","description":"Errors in revenue recognition amounts, cost of goods sold, depreciation/amortization, payroll calculations, fair-value measurement, journal-entry posting, tax provision, and foreign-currency translation misstating the financial statements.","details":{"category":"financial_reporting","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"fin-accuracy-measurement-errors","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-accuracy-measurement-errors-fd727255.html","id":"risk:fin-accuracy-measurement-errors","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-accuracy-measurement-errors","sourceIds":["cobit-2019","soc1","soc2","sox"],"sourceUrl":null,"title":"Measurement and calculation errors (accuracy)","type":"risk","url":"/assets/agent_record-risk-fin-accuracy-measurement-errors-fd727255.4628396b1fcc6cf6.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)"],"inherent_rating":"high","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-completeness-understatement","description":"Unrecorded payables (cut-off failure), accrued expenses, unrecorded revenue for delivered goods, off-balance-sheet obligations, uncaptured inventory write-downs, and understated payroll/tax liabilities — understating obligations and overstating income.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fin-completeness-understatement","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-completeness-understatement-4b9388d1.html","id":"risk:fin-completeness-understatement","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-completeness-understatement","sourceIds":["cobit-2019","soc1","soc2","sox"],"sourceUrl":null,"title":"Understatement of liabilities/expenses (completeness)","type":"risk","url":"/assets/agent_record-risk-fin-completeness-understatement-4b9388d1.ae76e179265f879b.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)"],"inherent_rating":"medium","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-cutoff-period-errors","description":"Revenue, vendor invoices, payroll, capital expenditure, treasury transactions, or tax provisions recorded in the wrong period — deliberately shifted to meet targets or erroneously mis-timed — distorting period results.","details":{"category":"financial_reporting","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"fin-cutoff-period-errors","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-cutoff-period-errors-180e8bcf.html","id":"risk:fin-cutoff-period-errors","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-cutoff-period-errors","sourceIds":["cobit-2019","soc1","soc2","sox"],"sourceUrl":null,"title":"Period cut-off errors","type":"risk","url":"/assets/agent_record-risk-fin-cutoff-period-errors-180e8bcf.3601f2d8b43b607f.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)","Data Protection & Privacy","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-data-quality-reporting-integrity","description":"Poor data lineage, inconsistent master-data definitions, or uncontrolled data transformation (weak IPE completeness/accuracy) cause management decisions and regulatory reports to rest on inaccurate or incomplete data.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fin-data-quality-reporting-integrity","taxonomies":["enterprise-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-data-quality-reporting-integrity-276baaa6.html","id":"risk:fin-data-quality-reporting-integrity","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-data-quality-reporting-integrity","sourceIds":["cobit-2019","iso-27001","soc1","soc2","sox"],"sourceUrl":null,"title":"Data-quality and IPE integrity failures in reporting","type":"risk","url":"/assets/agent_record-risk-fin-data-quality-reporting-integrity-276baaa6.94785b86a662b514.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)"],"inherent_rating":"high","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-existence-overstatement","description":"Revenue, receivables, inventory, capitalized assets, prepaid expenses, treasury investments, or tax assets recorded without underlying existence or occurrence — inflating the balance sheet and income statement.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fin-existence-overstatement","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-existence-overstatement-0e009631.html","id":"risk:fin-existence-overstatement","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-existence-overstatement","sourceIds":["cobit-2019","nist-800-53","soc1","soc2","sox"],"sourceUrl":null,"title":"Overstatement of assets/revenue (existence & occurrence)","type":"risk","url":"/assets/agent_record-risk-fin-existence-overstatement-0e009631.e106ea3635dc71b6.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-journal-entry-management-override","description":"Manual/automated journal entries posted with transposition errors, wrong account codes, or amounts; recurring entries not updated; and top-side entries used to override controls and manage earnings at period-end.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fin-journal-entry-management-override","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-fin-journal-entry-management-override-b0c0ed68.html","id":"risk:fin-journal-entry-management-override","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Afin-journal-entry-management-override","sourceIds":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Manual journal entries and management-override risk","type":"risk","url":"/assets/agent_record-risk-fin-journal-entry-management-override-b0c0ed68.9d5e8f3457283361.json"},{"attributes":{"category":"cyber_security","domain":["Logging, Monitoring & Detection","Incident Management & Response"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Alog-missing-audit-trail","description":"Absence of logging/audit trails means unauthorized activity cannot be detected, investigated, or attributed, and adversary actions (obfuscation of intrusion detection, tampering with logs) go unnoticed.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"log-missing-audit-trail","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-log-missing-audit-trail-37d1ba80.html","id":"risk:log-missing-audit-trail","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Alog-missing-audit-trail","sourceIds":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1"],"sourceUrl":null,"title":"Missing or insufficient logging and audit trails","type":"risk","url":"/assets/agent_record-risk-log-missing-audit-trail-37d1ba80.a56f64bcd1590fed.json"},{"attributes":{"category":"cyber_security","domain":["Logging, Monitoring & Detection","Incident Management & Response"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Alog-no-monitoring-supervision","description":"Absence of monitoring mechanisms and supervision of personnel actions (especially privileged users) allows undetected misuse, and no process exists to supervise and escalate detected security breaches.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"log-no-monitoring-supervision","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-log-no-monitoring-supervision-712fe573.html","id":"risk:log-no-monitoring-supervision","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Alog-no-monitoring-supervision","sourceIds":["cobit-2019","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2"],"sourceUrl":null,"title":"No security monitoring or supervision of privileged activity","type":"risk","url":"/assets/agent_record-risk-log-no-monitoring-supervision-712fe573.f68630a803345471.json"},{"attributes":{"category":"operational","domain":["Risk Assessment & Management","Financial Reporting Controls (SOX)"],"inherent_rating":"medium","taxonomy":["basel-operational-risk","coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aops-process-execution-errors","description":"Data-entry (fat-finger) errors, incorrect settlement instructions, collateral-management errors, reconciliation failures, and mis-application of corporate actions cause failed settlement, penalties, and undetected position discrepancies.","details":{"category":"operational","impact":"medium","inherent_rating":"medium","likelihood":"high","risk_id":"ops-process-execution-errors","taxonomies":["basel-operational-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-ops-process-execution-errors-530a1b11.html","id":"risk:ops-process-execution-errors","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aops-process-execution-errors","sourceIds":["cobit-2019","soc1","soc2","sox"],"sourceUrl":null,"title":"Transaction-processing and execution errors","type":"risk","url":"/assets/agent_record-risk-ops-process-execution-errors-530a1b11.6c821519a993921d.json"},{"attributes":{"category":"cyber_security","domain":["Physical & Environmental Security","Business Continuity & Disaster Recovery"],"inherent_rating":"medium","taxonomy":["nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aphys-cyber-physical-facility-attack","description":"Adversary conducts physical attacks on facilities (arson) or supporting infrastructure (cuts power/water), or cyber-physical attacks (remotely altering HVAC), damaging systems and supporting utilities.","details":{"category":"cyber_security","impact":"high","inherent_rating":"medium","likelihood":"low","risk_id":"phys-cyber-physical-facility-attack","taxonomies":["nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-phys-cyber-physical-facility-attack-e372d06e.html","id":"risk:phys-cyber-physical-facility-attack","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aphys-cyber-physical-facility-attack","sourceIds":["hipaa","iso-27001","nist-800-53","nist-csf-2","soc1","soc2"],"sourceUrl":null,"title":"Physical and cyber-physical attacks on facilities and infrastructure","type":"risk","url":"/assets/agent_record-risk-phys-cyber-physical-facility-attack-e372d06e.be9947b26b99ce0b.json"},{"attributes":{"category":"operational","domain":["Physical & Environmental Security"],"inherent_rating":"medium","taxonomy":["iso-27005-threat","iso-27005-vulnerability","nist-800-30-threat-source"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aphys-environmental-degradation","description":"Equipment sited without environmental controls suffers from dust, corrosion, freezing, humidity, voltage or temperature variation, and electromagnetic/thermal radiation or EMP, causing malfunction or failure.","details":{"category":"operational","impact":"medium","inherent_rating":"medium","likelihood":"low","risk_id":"phys-environmental-degradation","taxonomies":["iso-27005-threat","iso-27005-vulnerability","nist-800-30-threat-source"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-phys-environmental-degradation-137ba6a3.html","id":"risk:phys-environmental-degradation","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aphys-environmental-degradation","sourceIds":["iso-27001","nist-800-53","nist-csf-2","soc1"],"sourceUrl":null,"title":"Environmental degradation of equipment (dust, humidity, temperature, EMI)","type":"risk","url":"/assets/agent_record-risk-phys-environmental-degradation-137ba6a3.e65c4c54210784b8.json"},{"attributes":{"category":"operational","domain":["Physical & Environmental Security","Business Continuity & Disaster Recovery"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability","iso-27005-threat"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aphys-fire-water-suppression-gap","description":"Absence of fire suppression, smoke detection, flood barriers, or drainage in facilities housing information assets, and poor cabling infrastructure susceptible to damage, tapping, or accidental disconnection.","details":{"category":"operational","impact":"high","inherent_rating":"medium","likelihood":"low","risk_id":"phys-fire-water-suppression-gap","taxonomies":["iso-27005-vulnerability","iso-27005-threat"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-phys-fire-water-suppression-gap-ac966b92.html","id":"risk:phys-fire-water-suppression-gap","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aphys-fire-water-suppression-gap","sourceIds":["iso-27001","nist-800-53","nist-csf-2","soc1"],"sourceUrl":null,"title":"Inadequate protection against fire, flood and physical hazards","type":"risk","url":"/assets/agent_record-risk-phys-fire-water-suppression-gap-ac966b92.579f361af3a3360a.json"},{"attributes":{"category":"cyber_security","domain":["Physical & Environmental Security","Access Control & Identity Management"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aphys-inadequate-facility-access","description":"Buildings and sensitive areas lacking perimeter security, key-card/lock/mantrap controls, or supervision of visitors and cleaning/outside staff allow unauthorized physical access to equipment and media — including tailgating past physical checks.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"phys-inadequate-facility-access","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-phys-inadequate-facility-access-a83f3330.html","id":"risk:phys-inadequate-facility-access","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aphys-inadequate-facility-access","sourceIds":["hipaa","iso-27001","nist-800-53","nist-csf-2","soc1","soc2"],"sourceUrl":null,"title":"Inadequate physical protection and access controls","type":"risk","url":"/assets/agent_record-risk-phys-inadequate-facility-access-a83f3330.178b8b48cf8dd2b2.json"},{"attributes":{"category":"cyber_security","domain":["Physical & Environmental Security","Asset Management & Inventory","Data Protection & Privacy"],"inherent_rating":"medium","taxonomy":["iso-27005-threat","nist-800-30-threat-event","iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aphys-theft-of-equipment-media","description":"Physical stealing of storage media, printouts, or computing/network equipment (including unattended laptops outside the perimeter), potentially exposing stored data. Unprotected storage locations increase exposure.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"phys-theft-of-equipment-media","taxonomies":["iso-27005-threat","nist-800-30-threat-event","iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-phys-theft-of-equipment-media-c64433e7.html","id":"risk:phys-theft-of-equipment-media","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aphys-theft-of-equipment-media","sourceIds":["hipaa","iso-27001","nist-800-53","nist-csf-2","pci-dss","soc1","soc2"],"sourceUrl":null,"title":"Theft of equipment, media or unattended devices","type":"risk","url":"/assets/agent_record-risk-phys-theft-of-equipment-media-c64433e7.7787aba41dfbdeb8.json"},{"attributes":{"category":"operational","domain":["Business Continuity & Disaster Recovery","Asset Management & Inventory"],"inherent_rating":"medium","taxonomy":["iso-27005-threat","nist-800-30-threat-source","nist-800-30-threat-event","basel-operational-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atech-hardware-equipment-failure","description":"Malfunction or breakdown of storage, processing, communications, sensor, controller, or display equipment (aging, resource depletion, disk errors) disrupting availability or integrity — including intermittent/degraded operation producing incorrect results.","details":{"category":"operational","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"tech-hardware-equipment-failure","taxonomies":["iso-27005-threat","nist-800-30-threat-source","nist-800-30-threat-event","basel-operational-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tech-hardware-equipment-failure-25948451.html","id":"risk:tech-hardware-equipment-failure","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atech-hardware-equipment-failure","sourceIds":["cobit-2019","dora","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"sourceUrl":null,"title":"Hardware and equipment failure","type":"risk","url":"/assets/agent_record-risk-tech-hardware-equipment-failure-25948451.3a7e6b9d681e4d45.json"},{"attributes":{"category":"business_continuity","domain":["Business Continuity & Disaster Recovery","Physical & Environmental Security"],"inherent_rating":"high","taxonomy":["iso-27005-threat","iso-27005-vulnerability","nist-800-30-threat-source","basel-operational-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atech-loss-essential-services","description":"Interruption of power supply, air-conditioning/water utilities, or telecommunications — from unstable grids, single power feeds, UPS/generator failure, or carrier/fiber outages — stops operations or harms equipment and personnel.","details":{"category":"business_continuity","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"tech-loss-essential-services","taxonomies":["iso-27005-threat","iso-27005-vulnerability","nist-800-30-threat-source","basel-operational-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tech-loss-essential-services-b7feae05.html","id":"risk:tech-loss-essential-services","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atech-loss-essential-services","sourceIds":["cobit-2019","iso-27001","nist-800-53","nist-csf-2","nydfs-500","soc1"],"sourceUrl":null,"title":"Loss of essential services (power, HVAC, telecoms)","type":"risk","url":"/assets/agent_record-risk-tech-loss-essential-services-b7feae05.5c3a92c68419528d.json"},{"attributes":{"category":"operational","domain":["Business Continuity & Disaster Recovery","Secure Development (SDLC) & Application Security"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-source","basel-operational-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Atech-software-system-failure","description":"Failure or malfunction of operating-system, networking, or application software (defects, resource depletion, failed releases) causing loss of availability/integrity and impeding mission/business functions — including core banking/payments outages.","details":{"category":"operational","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"tech-software-system-failure","taxonomies":["iso-27005-threat","nist-800-30-threat-source","basel-operational-risk"],"treatment":"mitigate"},"direct":false,"htmlUrl":"/agents/records/risk-tech-software-system-failure-2e2c5364.html","id":"risk:tech-software-system-failure","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Atech-software-system-failure","sourceIds":["cobit-2019","dora","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"sourceUrl":null,"title":"Software and information-system failure","type":"risk","url":"/assets/agent_record-risk-tech-software-system-failure-2e2c5364.025addde30ebc5e9.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:082ce7de28fdc456c8e68f7bf2b6f2f2af4a25425c80e8e87c82e9d347e259f9","properties":{"rationale":"Auto-disabling dormant accounts and prompt termination removal close the orphaned-account vector for unauthorized access.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/risk-access-unauthorized-use-equipment-d2082944.json","targetId":"risk:access-unauthorized-use-equipment","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:11fe9a986e34244ae40027d08cce29410f0ad1ec4a74cb082300df6f05ac6c05","properties":{"rationale":"Access authorization plus review of physical/environmental events deters and detects an adversary physically reaching and sabotaging infrastructure.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-19-08a17359.json","sourceId":"uc:UC-ACCESS-19","targetDetailPath":"/data/v1/records/risk-phys-cyber-physical-facility-attack-e372d06e.json","targetId":"risk:phys-cyber-physical-facility-attack","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1448b5981f0f84eae0edf17bdeddb04df6bb1bab4d08fb48d84c2c8e23575315","properties":{"rationale":"Owner-approved provisioning with role-based entitlements and 1-business-day deprovisioning on termination directly eliminates orphaned accounts and un-revoked access.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/risk-access-provisioning-review-gap-dc152038.json","targetId":"risk:access-provisioning-review-gap","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1453ec0d0a9b31e2eb4d51ab3c43a632bc169a42bdb8336f101fea32af775363","properties":{"control_id":"SOC1-12","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-21-14f45683.json","sourceId":"uc:UC-ACCESS-21","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-12-05ba06e4.json","targetId":"ctrl:soc1:SOC1-12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1c5ed5869ef6bfd8447a6778631af2d091fa13a9f89c7c6007ac2e5129a61405","properties":{"control_id":"SOC1-7","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-7-20ea752e.json","targetId":"ctrl:soc1:SOC1-7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:303f150d8121d11f1a7baaf39d40fc40dd40ba0a7fcaab174fafe354a8d4b648","properties":{"control_id":"SOC1-9","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-9-7278adb1.json","targetId":"ctrl:soc1:SOC1-9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:33dcd40af1a39867875bc4253e4c8c4a79e06449acbc0d315f7104aeab6b3ad2","properties":{"control_id":"SOC1-6","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-6-b85280f6.json","targetId":"ctrl:soc1:SOC1-6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3482f940501c517a67197f708fd3cb684305fd5024709ad7e5dffbade6b03082","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-4-2584ed29.json","sourceId":"ctrl:soc1:SOC1-4","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:35e1dfb346a72fd0c22d2413ff5a7d57a2ebd258234bdaa359d941754b0c242b","properties":{"rationale":"Systems generate protected log records made available for continuous monitoring, directly remedying absent/insufficient audit trails.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/risk-log-missing-audit-trail-37d1ba80.json","targetId":"risk:log-missing-audit-trail","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3b26f5b7dd3ea6d611ce3884e501d07d1c17144ae41c092fef0c7588ce3ad15b","properties":{"control_id":"SOC1-3","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-3-762891cb.json","targetId":"ctrl:soc1:SOC1-3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3cb85a07ecd989ddfb977e2e28f315672ff6498a55a05836692b3add9de727a7","properties":{"rationale":"Temperature/humidity control and power conditioning directly prevent equipment degradation from thermal and voltage variation.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-19-08a17359.json","sourceId":"uc:UC-ACCESS-19","targetDetailPath":"/data/v1/records/risk-phys-environmental-degradation-137ba6a3.json","targetId":"risk:phys-environmental-degradation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3eeba4eca39f8b884fcc75287de1c376d7cadac924a9d21760d4842cca42dee5","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-7-20ea752e.json","sourceId":"ctrl:soc1:SOC1-7","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4987cfed4954248b8ed56bc0bbc3dca0d46b95d8bbd753c0fa0c8c6fab25422e","properties":{"rationale":"Incident identification and capacity/performance monitoring surface error- and misconfiguration-driven incidents, enabling correction that limits impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/risk-aware-user-error-mishandling-149a1d3b.json","targetId":"risk:aware-user-error-mishandling","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:522207fd6d9b165c0039e3025b319ff4c0759411ea7c5ea4bfad8a4296747421","properties":{"rationale":"scheduled protected backups with tested restoration confirm recoverability within objectives, reducing outage/data-loss/slow-recovery","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-17-c9ecd00d.json","sourceId":"uc:UC-ACCESS-17","targetDetailPath":"/data/v1/records/risk-bcdr-it-resilience-outage-18dfc108.json","targetId":"risk:bcdr-it-resilience-outage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:53321dcf48fee33a1e4347c5d958372eed452f042a342ec40af6ad00679f46f6","properties":{"rationale":"Input edit checks catch journal-entry transposition and format errors before posting.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/risk-fin-journal-entry-management-override-b0c0ed68.json","targetId":"risk:fin-journal-entry-management-override","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5797f2efd8a8cd404420f154f4e500255e3e960ce54c6b7d097051edc40f6b05","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-11-9b7842c1.json","sourceId":"ctrl:soc1:SOC1-11","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5a89cf0f679caeba093b024d4116046089f748f6c912e73e2e281611062987af","properties":{"rationale":"Operating fire detection and suppression directly mitigates the fire hazard to systems that is the core gap this risk names.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-19-08a17359.json","sourceId":"uc:UC-ACCESS-19","targetDetailPath":"/data/v1/records/risk-phys-fire-water-suppression-gap-ac966b92.json","targetId":"risk:phys-fire-water-suppression-gap","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5e0f088619589520d16d49dc65833d9f48229353895adf2f6420f1f71b6db42b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-1-bfab4a41.json","sourceId":"ctrl:soc1:SOC1-1","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5f22736e12ef926d9b071321940afbdc54d6227b4d46ccb66c91d0bf3f5c3c89","properties":{"rationale":"Interface reconciliation and output validation preserve completeness/accuracy of data used in reporting.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/risk-fin-data-quality-reporting-integrity-276baaa6.json","targetId":"risk:fin-data-quality-reporting-integrity","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:610a50fbfce562d7abb329df448ae492410a9a88750151ea34b93e955dfdf08a","properties":{"rationale":"Requiring authorized, documented changes reduces the unauthorized changes that drive drift, though baseline monitoring is the operative control.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/risk-config-poor-baseline-drift-2dd66324.json","targetId":"risk:config-poor-baseline-drift","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:681a6786c06c86e379fe0f4643d18c70bf76177ccd58a2185be021943a45e9f3","properties":{"control_id":"SOC1-4","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-17-c9ecd00d.json","sourceId":"uc:UC-ACCESS-17","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-4-2584ed29.json","targetId":"ctrl:soc1:SOC1-4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6b710d6a56e7a4b07aefe80567fefddc69ff19c8c060fa0f70b307e36aa1b835","properties":{"rationale":"monitoring batch/scheduled processing and resolving logged failures directly limits system-failure impact","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-17-c9ecd00d.json","sourceId":"uc:UC-ACCESS-17","targetDetailPath":"/data/v1/records/risk-tech-software-system-failure-2e2c5364.json","targetId":"risk:tech-software-system-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6c815b812ba264ef62d6cf7e0c231c815cef0e6891cd1d8eb074d6564b155aa3","properties":{"rationale":"Continuously monitors security events against thresholds with alert triage and tracked incident resolution, filling the no-monitoring gap.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/risk-log-no-monitoring-supervision-712fe573.json","targetId":"risk:log-no-monitoring-supervision","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7140895cb754da3b3fb1b55b2fb55668cb267adc5c21b8e8bd64f92de8e68b2d","properties":{"rationale":"Proper-period processing contributes, but ACCESS-20 centers on input/interface completeness and accuracy; the operative cut-off controls are period-end close review and automated processing period enforcement.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/risk-fin-cutoff-period-errors-180e8bcf.json","targetId":"risk:fin-cutoff-period-errors","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7c3a185818b8aa491bee8c358ee5433277ecf04932f4c54f7a61ebd250cc7cf1","properties":{"rationale":"Monitors performance/capacity against thresholds and projects/tunes resource use, directly reducing capacity-driven outages; incident tracking shortens recovery.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/risk-bcdr-it-resilience-outage-18dfc108.json","targetId":"risk:bcdr-it-resilience-outage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7d87c2ca05792ba32958cff58e1fbded7b657cfdb235299ba395db1effbd517e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-12-05ba06e4.json","sourceId":"ctrl:soc1:SOC1-12","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8042e50c8400feb9ba8232e6e9b8b7dba985fb195e97a397d35b5d09e90e8b9b","properties":{"control_id":"SOC1-11","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-11-9b7842c1.json","targetId":"ctrl:soc1:SOC1-11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:82c5c2a6412b6bd1788c545deba7ea85028834f492e55e2af8ed87fe97ac2c8e","properties":{"rationale":"Power conditioning and backup directly sustain systems through power disruption, reducing loss-of-power impact.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-19-08a17359.json","sourceId":"uc:UC-ACCESS-19","targetDetailPath":"/data/v1/records/risk-tech-loss-essential-services-b7feae05.json","targetId":"risk:tech-loss-essential-services","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:897843185d2d78e8517e151151b9b8afc945cd5abe90f11f8a076f64364ee8a4","properties":{"rationale":"Authorizing, badging, logging, monitoring, and revoking physical access is the direct control preventing unauthorized entry to facilities and secure areas.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-19-08a17359.json","sourceId":"uc:UC-ACCESS-19","targetDetailPath":"/data/v1/records/risk-phys-inadequate-facility-access-a83f3330.json","targetId":"risk:phys-inadequate-facility-access","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8e6742e480b41e66a020b38a90eb94480944cbf497754834c3ddda5bec65dd58","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-5-d064ade6.json","sourceId":"ctrl:soc1:SOC1-5","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8e9356e1aafa162e56d7ec0b8878ef0e0ae86695d6b9ef63446429a8dc7225a0","properties":{"rationale":"Authorization validation of inputs reduces unauthorized/fictitious entries entering processing.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/risk-fin-existence-overstatement-0e009631.json","targetId":"risk:fin-existence-overstatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:916a5f73c86982a998a42038eb41a19435b88179395ca277226a86d2ec11a2dc","properties":{"rationale":"Restricting and revoking physical access keeps unauthorized persons away from equipment and media, directly preventing on-site theft.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-19-08a17359.json","sourceId":"uc:UC-ACCESS-19","targetDetailPath":"/data/v1/records/risk-phys-theft-of-equipment-media-c64433e7.json","targetId":"risk:phys-theft-of-equipment-media","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:98442e227966546c39abf81dc0d410be51413eae6b905290fba01ac8719022de","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-9-7278adb1.json","sourceId":"ctrl:soc1:SOC1-9","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9cd63182cb1af7f6e50ef091319214c504b8f5863b32de90be1c597a0e551ac6","properties":{"control_id":"SOC1-5","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-17-c9ecd00d.json","sourceId":"uc:UC-ACCESS-17","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-5-d064ade6.json","targetId":"ctrl:soc1:SOC1-5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a2e1805733a26b7d9aa4907769037519f52061354e3a99da55492a7950b96b53","properties":{"control_id":"SOC1-10","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-19-08a17359.json","sourceId":"uc:UC-ACCESS-19","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-10-43ef0cd6.json","targetId":"ctrl:soc1:SOC1-10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a2e38565659d2389482f09121d6f3a226ad91bb51d3f4a289a62de12de94f513","properties":{"rationale":"Pre-production testing and approval gates catch legacy-integration interface mismatches and configuration errors before they reach production.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/risk-ai-emergent-integration-risk-8490271c.json","targetId":"risk:ai-emergent-integration-risk","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a306a3d84f530dae589def12cc9c1cd68e204ef07784a630b04381d253540b95","properties":{"rationale":"periodic restoration testing exercises the recovery path","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-17-c9ecd00d.json","sourceId":"uc:UC-ACCESS-17","targetDetailPath":"/data/v1/records/risk-bcdr-no-tested-continuity-plan-d4d9e7a9.json","targetId":"risk:bcdr-no-tested-continuity-plan","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a8e947d41b9ce280ec46a8aa353bc1de04d27649e8737ad3a268cd54ef74a093","properties":{"control_id":"SOC1-1","coverage":"partial","delta":"authentication, periodic review, and privileged access satisfied by companion unified controls","framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-1-bfab4a41.json","targetId":"ctrl:soc1:SOC1-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a91da0cf407c7f7f8372e3661427e45682359b9adc643c7ec5dc243ac1c57827","properties":{"rationale":"Edit checks and batch totals validate processing accuracy, catching calculation and posting errors.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/risk-fin-accuracy-measurement-errors-fd727255.json","targetId":"risk:fin-accuracy-measurement-errors","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ac926831df5567af31dda7687bb08beb6241ad883936c5e38dcee1bd556bd753","properties":{"control_id":"SOC1-2","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-2-7fcfb329.json","targetId":"ctrl:soc1:SOC1-2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:afd5822474b74e64ccfb40b345a7188165ef1ab0e454c5bab35471af16ebd43f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-8-9602488c.json","sourceId":"ctrl:soc1:SOC1-8","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b1fdc19aba428a2f288414f58d4c6877e17f56f919f2846fa8743e5b6d745dc5","properties":{"rationale":"Batch totals and completeness validation ensure all transactions are captured, preventing unrecorded items.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/risk-fin-completeness-understatement-4b9388d1.json","targetId":"risk:fin-completeness-understatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b4d92548374a81b2bfd10351d0d6bffa2a829e747b1b01b0bee88a2e14ceeaf5","properties":{"rationale":"backup and tested restoration recover data lost to equipment failure","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-17-c9ecd00d.json","sourceId":"uc:UC-ACCESS-17","targetDetailPath":"/data/v1/records/risk-tech-hardware-equipment-failure-25948451.json","targetId":"risk:tech-hardware-equipment-failure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b588dd72669f70c111b1d540bb1db20d3797bdc9d35338d28ec08de5a1eb9352","properties":{"control_id":"SOC1-8","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-8-9602488c.json","targetId":"ctrl:soc1:SOC1-8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bac757e49dbfd195de7f3e65ab597d65874a137a35603edf85a19f35c554b40b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-10-43ef0cd6.json","sourceId":"ctrl:soc1:SOC1-10","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:be88249853f99703d19cefb0ad41a99cd93d410c5b64fd1ff7f47b7359d6cb3f","properties":{"rationale":"The authorize->test->approve->independent-migration gate IS the change-control process, directly preventing unapproved or untested changes.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/risk-config-weak-change-control-e7d90eaf.json","targetId":"risk:config-weak-change-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c98f016859301db5b87ab34820a1c012b990ef0f66df57ae7d30bb94bbca3443","properties":{"rationale":"Edit checks, batch totals and interface reconciliation catch data-entry and processing execution errors.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/risk-ops-process-execution-errors-530a1b11.json","targetId":"risk:ops-process-execution-errors","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cf137512b108434acb4692dc06fe51fba1530cd3829a3ef8b1904e30510f8527","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-6-b85280f6.json","sourceId":"ctrl:soc1:SOC1-6","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d0d07d418148d734088375ce0012f28de40045ab3411397bfc3bd43059407743","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-3-762891cb.json","sourceId":"ctrl:soc1:SOC1-3","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dfc315612c713723a50c9d8914f9a7dbc9a9d82d7da7ce0cca39ac67d98d100a","properties":{"rationale":"Role-based, owner-approved provisioning and modify-on-role-change help limit wrong assignment and accumulation, but the operative least-privilege defense is role design (UC-03) and periodic access review (UC-02).","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/risk-access-excess-privilege-cd8adadc.json","targetId":"risk:access-excess-privilege","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f346a38d911d1f90dd9b17be32550423e8663599fe22040b606f95ea7a3cb858","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-2-7fcfb329.json","sourceId":"ctrl:soc1:SOC1-2","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f58e9acd1374bdbce84d3819c1f1ddf398cf90c365abed4378c3b5e88b182afd","properties":{"rationale":"Security-event monitoring with alert triage contributes to detecting attacks, though specialized detection sits in dedicated SIEM/IDS controls.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f67ff06fb773d0f1089d4819b048691037c347f94ad9b19a46047afa3f3ca5fb","properties":{"rationale":"Accounts uniquely attributable to individuals plus logged provisioning/modification events underpin the accountability that counters repudiation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/risk-access-privilege-abuse-repudiation-343a8917.json","targetId":"risk:access-privilege-abuse-repudiation","type":"mitigates"}],"schemaVersion":1,"scope":"sources","total":80}
