{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":[],"directIds":["ctrl:soc2:A1.1","ctrl:soc2:A1.2","ctrl:soc2:A1.3","ctrl:soc2:C1.1","ctrl:soc2:C1.2","ctrl:soc2:CC1.1","ctrl:soc2:CC1.2","ctrl:soc2:CC1.3","ctrl:soc2:CC1.4","ctrl:soc2:CC1.5","ctrl:soc2:CC2.1","ctrl:soc2:CC2.2","ctrl:soc2:CC2.3","ctrl:soc2:CC3.1","ctrl:soc2:CC3.2","ctrl:soc2:CC3.3","ctrl:soc2:CC3.4","ctrl:soc2:CC4.1","ctrl:soc2:CC4.2","ctrl:soc2:CC5.1","ctrl:soc2:CC5.2","ctrl:soc2:CC5.3","ctrl:soc2:CC6.1","ctrl:soc2:CC6.2","ctrl:soc2:CC6.3","ctrl:soc2:CC6.4","ctrl:soc2:CC6.5","ctrl:soc2:CC6.6","ctrl:soc2:CC6.7","ctrl:soc2:CC6.8","ctrl:soc2:CC7.1","ctrl:soc2:CC7.2","ctrl:soc2:CC7.3","ctrl:soc2:CC7.4","ctrl:soc2:CC7.5","ctrl:soc2:CC8.1","ctrl:soc2:CC9.1","ctrl:soc2:CC9.2","ctrl:soc2:P1.1","ctrl:soc2:P2.1"],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"SOC 2 (TSC)","next":"/assets/agent_sources-soc2-2.e86d5c613b985783.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"technical","framework":"soc2","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity maintains, monitors, and evaluates current processing capacity and use of system components (infrastructure, data, and software) to manage capacity demand and to enable the implementation of additional capacity to help meet its objectives.","details":{"automation":"hybrid","control_category":"technical","control_id":"A1.1","control_type":"detective","domains":["Business Continuity & Disaster Recovery"],"framework":"soc2","group":"Availability","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-a1-1-a9048d7a.html","id":"ctrl:soc2:A1.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3AA1.1","sourceIds":["soc2"],"sourceUrl":null,"title":"A1.1 — The entity maintains, monitors, and evaluates current processing capacity and use of system components (infrastructure, data, and software) to manage capacity demand and to enable the implementation of additional capacity to help meet its objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-a1-1-a9048d7a.263b14652c317bc5.json"},{"attributes":{"category":"physical","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity authorizes, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data back-up processes, and recovery infrastructure to meet its objectives.","details":{"automation":"hybrid","control_category":"physical","control_id":"A1.2","control_type":"preventive","domains":["Business Continuity & Disaster Recovery"],"framework":"soc2","group":"Availability","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-a1-2-d4182682.html","id":"ctrl:soc2:A1.2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3AA1.2","sourceIds":["soc2"],"sourceUrl":null,"title":"A1.2 — The entity authorizes, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data back-up processes, and recovery infrastructure to meet its objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-a1-2-d4182682.d4e036e812218d01.json"},{"attributes":{"category":"technical","framework":"soc2","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity tests recovery plan procedures supporting system recovery to meet its objectives.","details":{"automation":"manual","control_category":"technical","control_id":"A1.3","control_type":"detective","domains":["Business Continuity & Disaster Recovery"],"framework":"soc2","group":"Availability","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-a1-3-b64a7d41.html","id":"ctrl:soc2:A1.3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3AA1.3","sourceIds":["soc2"],"sourceUrl":null,"title":"A1.3 — The entity tests recovery plan procedures supporting system recovery to meet its objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-a1-3-b64a7d41.d0892cd88f134caf.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity identifies and maintains confidential information to meet the entity's objectives related to confidentiality.","details":{"automation":"manual","control_category":"administrative","control_id":"C1.1","control_type":"preventive","domains":["Asset Management & Inventory","Data Protection & Privacy"],"framework":"soc2","group":"Confidentiality","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-c1-1-d20576fd.html","id":"ctrl:soc2:C1.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3AC1.1","sourceIds":["soc2"],"sourceUrl":null,"title":"C1.1 — The entity identifies and maintains confidential information to meet the entity's objectives related to confidentiality.","type":"control","url":"/assets/agent_record-ctrl-soc2-c1-1-d20576fd.667a0cf11536736a.json"},{"attributes":{"category":"technical","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity disposes of confidential information to meet the entity's objectives related to confidentiality.","details":{"automation":"manual","control_category":"technical","control_id":"C1.2","control_type":"preventive","domains":["Data Protection & Privacy"],"framework":"soc2","group":"Confidentiality","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-c1-2-e6a223bc.html","id":"ctrl:soc2:C1.2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3AC1.2","sourceIds":["soc2"],"sourceUrl":null,"title":"C1.2 — The entity disposes of confidential information to meet the entity's objectives related to confidentiality.","type":"control","url":"/assets/agent_record-ctrl-soc2-c1-2-e6a223bc.a47aee6952e646cd.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity demonstrates a commitment to integrity and ethical values.","details":{"automation":"manual","control_category":"administrative","control_id":"CC1.1","control_type":"preventive","domains":["Governance, Policy & Oversight"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc1-1-ad48e3c3.html","id":"ctrl:soc2:CC1.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC1.1","sourceIds":["soc2"],"sourceUrl":null,"title":"CC1.1 — The entity demonstrates a commitment to integrity and ethical values.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc1-1-ad48e3c3.f629ecde76b6fa6a.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.","details":{"automation":"manual","control_category":"administrative","control_id":"CC1.2","control_type":"preventive","domains":["Governance, Policy & Oversight"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc1-2-f5deb30e.html","id":"ctrl:soc2:CC1.2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC1.2","sourceIds":["soc2"],"sourceUrl":null,"title":"CC1.2 — The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc1-2-f5deb30e.efbce5cf3675e32b.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.","details":{"automation":"manual","control_category":"administrative","control_id":"CC1.3","control_type":"preventive","domains":["Governance, Policy & Oversight"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc1-3-05d9fef7.html","id":"ctrl:soc2:CC1.3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC1.3","sourceIds":["soc2"],"sourceUrl":null,"title":"CC1.3 — Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc1-3-05d9fef7.859847ec9ccc8283.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.","details":{"automation":"manual","control_category":"administrative","control_id":"CC1.4","control_type":"preventive","domains":["Awareness & Training","Human Resources / Personnel Security"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc1-4-6e16c0ae.html","id":"ctrl:soc2:CC1.4","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC1.4","sourceIds":["soc2"],"sourceUrl":null,"title":"CC1.4 — The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc1-4-6e16c0ae.220d4d8ee8864655.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives.","details":{"automation":"manual","control_category":"administrative","control_id":"CC1.5","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight","Human Resources / Personnel Security"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc1-5-ce418f10.html","id":"ctrl:soc2:CC1.5","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC1.5","sourceIds":["soc2"],"sourceUrl":null,"title":"CC1.5 — The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc1-5-ce418f10.11b641643164facb.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.","details":{"automation":"manual","control_category":"administrative","control_id":"CC2.1","control_type":"preventive","domains":["Compliance, Audit & Assurance"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc2-1-83b34ada.html","id":"ctrl:soc2:CC2.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC2.1","sourceIds":["soc2"],"sourceUrl":null,"title":"CC2.1 — The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc2-1-83b34ada.cf393a22d2fc4383.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.","details":{"automation":"manual","control_category":"administrative","control_id":"CC2.2","control_type":"preventive","domains":["Awareness & Training","Governance, Policy & Oversight","Human Resources / Personnel Security"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc2-2-2736ed02.html","id":"ctrl:soc2:CC2.2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC2.2","sourceIds":["soc2"],"sourceUrl":null,"title":"CC2.2 — The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc2-2-2736ed02.dac5d989edfea204.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity communicates with external parties regarding matters affecting the functioning of internal control.","details":{"automation":"manual","control_category":"administrative","control_id":"CC2.3","control_type":"preventive","domains":["Governance, Policy & Oversight","Third-Party / Supply-Chain Risk"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc2-3-b0ace578.html","id":"ctrl:soc2:CC2.3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC2.3","sourceIds":["soc2"],"sourceUrl":null,"title":"CC2.3 — The entity communicates with external parties regarding matters affecting the functioning of internal control.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc2-3-b0ace578.aae69860f5e6be21.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.","details":{"automation":"manual","control_category":"administrative","control_id":"CC3.1","control_type":"preventive","domains":["AI Governance","Financial Reporting Controls (SOX)","Risk Assessment & Management"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc3-1-4fb807c4.html","id":"ctrl:soc2:CC3.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC3.1","sourceIds":["soc2"],"sourceUrl":null,"title":"CC3.1 — The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc3-1-4fb807c4.dfae110d3bef8d62.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed.","details":{"automation":"manual","control_category":"administrative","control_id":"CC3.2","control_type":"preventive","domains":["Asset Management & Inventory","Risk Assessment & Management"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc3-2-18f9e8ee.html","id":"ctrl:soc2:CC3.2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC3.2","sourceIds":["soc2"],"sourceUrl":null,"title":"CC3.2 — The entity identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc3-2-18f9e8ee.3d3c87b91bdc5ae2.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity considers the potential for fraud in assessing risks to the achievement of objectives.","details":{"automation":"manual","control_category":"administrative","control_id":"CC3.3","control_type":"preventive","domains":["Risk Assessment & Management"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc3-3-ae6eeb77.html","id":"ctrl:soc2:CC3.3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC3.3","sourceIds":["soc2"],"sourceUrl":null,"title":"CC3.3 — The entity considers the potential for fraud in assessing risks to the achievement of objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc3-3-ae6eeb77.f7c5de22e4bddb03.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity identifies and assesses changes that could significantly impact the system of internal control.","details":{"automation":"manual","control_category":"administrative","control_id":"CC3.4","control_type":"preventive","domains":["AI Governance","Risk Assessment & Management","Third-Party / Supply-Chain Risk"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc3-4-a6d03c70.html","id":"ctrl:soc2:CC3.4","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC3.4","sourceIds":["soc2"],"sourceUrl":null,"title":"CC3.4 — The entity identifies and assesses changes that could significantly impact the system of internal control.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc3-4-a6d03c70.2e38bcfcd1ff7801.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.","details":{"automation":"manual","control_category":"administrative","control_id":"CC4.1","control_type":"detective","domains":["Compliance, Audit & Assurance","Logging, Monitoring & Detection","Risk Assessment & Management","Vulnerability & Patch Management"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc4-1-12630f31.html","id":"ctrl:soc2:CC4.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC4.1","sourceIds":["soc2"],"sourceUrl":null,"title":"CC4.1 — The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc4-1-12630f31.c3490143c1f29b9a.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate.","details":{"automation":"manual","control_category":"administrative","control_id":"CC4.2","control_type":"detective","domains":["Compliance, Audit & Assurance","Risk Assessment & Management"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc4-2-1538fe1e.html","id":"ctrl:soc2:CC4.2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC4.2","sourceIds":["soc2"],"sourceUrl":null,"title":"CC4.2 — The entity evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc4-2-1538fe1e.9014aa1636c2f0af.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.","details":{"automation":"manual","control_category":"administrative","control_id":"CC5.1","control_type":"preventive","domains":["AI Governance","Financial Reporting Controls (SOX)","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc5-1-b6b93caa.html","id":"ctrl:soc2:CC5.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC5.1","sourceIds":["soc2"],"sourceUrl":null,"title":"CC5.1 — The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc5-1-b6b93caa.df584a4eeb22a387.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity also selects and develops general control activities over technology to support the achievement of objectives.","details":{"automation":"manual","control_category":"administrative","control_id":"CC5.2","control_type":"preventive","domains":["Financial Reporting Controls (SOX)","Governance, Policy & Oversight"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc5-2-2d184a95.html","id":"ctrl:soc2:CC5.2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC5.2","sourceIds":["soc2"],"sourceUrl":null,"title":"CC5.2 — The entity also selects and develops general control activities over technology to support the achievement of objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc5-2-2d184a95.661d8bc9f49ef541.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity deploys control activities through policies that establish what is expected and in procedures that put policies into action.","details":{"automation":"manual","control_category":"administrative","control_id":"CC5.3","control_type":"preventive","domains":["Financial Reporting Controls (SOX)","Governance, Policy & Oversight"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc5-3-46feecd1.html","id":"ctrl:soc2:CC5.3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC5.3","sourceIds":["soc2"],"sourceUrl":null,"title":"CC5.3 — The entity deploys control activities through policies that establish what is expected and in procedures that put policies into action.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc5-3-46feecd1.8836991860a4779b.json"},{"attributes":{"category":"technical","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events to meet the entity's objectives.","details":{"automation":"automated","control_category":"technical","control_id":"CC6.1","control_type":"preventive","domains":["Access Control & Identity Management","Asset Management & Inventory","Cryptography & Key Management","Network & Communications Security"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc6-1-683a2035.html","id":"ctrl:soc2:CC6.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC6.1","sourceIds":["soc2"],"sourceUrl":null,"title":"CC6.1 — The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events to meet the entity's objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc6-1-683a2035.7ead9bd0e1c4a5a3.json"},{"attributes":{"category":"technical","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users whose access is administered by the entity. For those users whose access is administered by the entity, user system credentials are removed when user access is no longer authorized.","details":{"automation":"hybrid","control_category":"technical","control_id":"CC6.2","control_type":"preventive","domains":["Access Control & Identity Management"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc6-2-639c148c.html","id":"ctrl:soc2:CC6.2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC6.2","sourceIds":["soc2"],"sourceUrl":null,"title":"CC6.2 — Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users whose access is administered by the entity. For those users whose access is administered by the entity, user system credentials are removed when user access is no longer authorized.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc6-2-639c148c.2401ea7213750023.json"},{"attributes":{"category":"technical","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties, to meet the entity's objectives.","details":{"automation":"hybrid","control_category":"technical","control_id":"CC6.3","control_type":"preventive","domains":["Access Control & Identity Management"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":7,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc6-3-4ade392f.html","id":"ctrl:soc2:CC6.3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC6.3","sourceIds":["soc2"],"sourceUrl":null,"title":"CC6.3 — The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties, to meet the entity's objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc6-3-4ade392f.d5890b07eca244bf.json"},{"attributes":{"category":"physical","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives.","details":{"automation":"hybrid","control_category":"physical","control_id":"CC6.4","control_type":"preventive","domains":["Physical & Environmental Security"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc6-4-4132a487.html","id":"ctrl:soc2:CC6.4","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC6.4","sourceIds":["soc2"],"sourceUrl":null,"title":"CC6.4 — The entity restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc6-4-4132a487.73700e8c4ac27fe0.json"},{"attributes":{"category":"physical","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required to meet the entity's objectives.","details":{"automation":"manual","control_category":"physical","control_id":"CC6.5","control_type":"preventive","domains":["Asset Management & Inventory","Physical & Environmental Security"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc6-5-449f6335.html","id":"ctrl:soc2:CC6.5","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC6.5","sourceIds":["soc2"],"sourceUrl":null,"title":"CC6.5 — The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required to meet the entity's objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc6-5-449f6335.2f06a959353b3c95.json"},{"attributes":{"category":"technical","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity implements logical access security measures to protect against threats from sources outside its system boundaries.","details":{"automation":"automated","control_category":"technical","control_id":"CC6.6","control_type":"preventive","domains":["Network & Communications Security"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc6-6-31bdbb9f.html","id":"ctrl:soc2:CC6.6","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC6.6","sourceIds":["soc2"],"sourceUrl":null,"title":"CC6.6 — The entity implements logical access security measures to protect against threats from sources outside its system boundaries.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc6-6-31bdbb9f.e86742a11916426e.json"},{"attributes":{"category":"technical","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission, movement, or removal to meet the entity's objectives.","details":{"automation":"automated","control_category":"technical","control_id":"CC6.7","control_type":"preventive","domains":["Cryptography & Key Management","Network & Communications Security"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc6-7-f815d553.html","id":"ctrl:soc2:CC6.7","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC6.7","sourceIds":["soc2"],"sourceUrl":null,"title":"CC6.7 — The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission, movement, or removal to meet the entity's objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc6-7-f815d553.415b5992d8bfb895.json"},{"attributes":{"category":"technical","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity's objectives.","details":{"automation":"automated","control_category":"technical","control_id":"CC6.8","control_type":"preventive","domains":["Secure Configuration & Change Management"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc6-8-dc7a8dc8.html","id":"ctrl:soc2:CC6.8","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC6.8","sourceIds":["soc2"],"sourceUrl":null,"title":"CC6.8 — The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity's objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc6-8-dc7a8dc8.68986ae50e161e57.json"},{"attributes":{"category":"technical","framework":"soc2","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities.","details":{"automation":"automated","control_category":"technical","control_id":"CC7.1","control_type":"detective","domains":["Logging, Monitoring & Detection","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Vulnerability & Patch Management"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc7-1-a0583d17.html","id":"ctrl:soc2:CC7.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC7.1","sourceIds":["soc2"],"sourceUrl":null,"title":"CC7.1 — To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc7-1-a0583d17.7beb2464f47f782b.json"},{"attributes":{"category":"technical","framework":"soc2","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are analyzed to determine whether they represent security events.","details":{"automation":"hybrid","control_category":"technical","control_id":"CC7.2","control_type":"detective","domains":["Logging, Monitoring & Detection"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc7-2-7ca85bf1.html","id":"ctrl:soc2:CC7.2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC7.2","sourceIds":["soc2"],"sourceUrl":null,"title":"CC7.2 — The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are analyzed to determine whether they represent security events.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc7-2-7ca85bf1.16b21fa341d7be07.json"},{"attributes":{"category":"technical","framework":"soc2","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives (security incidents) and, if so, takes actions to prevent or address such failures.","details":{"automation":"hybrid","control_category":"technical","control_id":"CC7.3","control_type":"detective","domains":["Incident Management & Response","Logging, Monitoring & Detection"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc7-3-00826815.html","id":"ctrl:soc2:CC7.3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC7.3","sourceIds":["soc2"],"sourceUrl":null,"title":"CC7.3 — The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives (security incidents) and, if so, takes actions to prevent or address such failures.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc7-3-00826815.a32045584e545dee.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity responds to identified security incidents by executing a defined incident response program to understand, contain, remediate, and communicate security incidents, as appropriate.","details":{"automation":"manual","control_category":"administrative","control_id":"CC7.4","control_type":"corrective","domains":["Incident Management & Response"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc7-4-4e5ce771.html","id":"ctrl:soc2:CC7.4","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC7.4","sourceIds":["soc2"],"sourceUrl":null,"title":"CC7.4 — The entity responds to identified security incidents by executing a defined incident response program to understand, contain, remediate, and communicate security incidents, as appropriate.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc7-4-4e5ce771.e7d117d0db997690.json"},{"attributes":{"category":"technical","framework":"soc2","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity identifies, develops, and implements activities to recover from identified security incidents.","details":{"automation":"manual","control_category":"technical","control_id":"CC7.5","control_type":"corrective","domains":["Business Continuity & Disaster Recovery","Incident Management & Response"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc7-5-580af9de.html","id":"ctrl:soc2:CC7.5","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC7.5","sourceIds":["soc2"],"sourceUrl":null,"title":"CC7.5 — The entity identifies, develops, and implements activities to recover from identified security incidents.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc7-5-580af9de.9bf00df4b3927390.json"},{"attributes":{"category":"technical","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures to meet its objectives.","details":{"automation":"hybrid","control_category":"technical","control_id":"CC8.1","control_type":"preventive","domains":["Secure Configuration & Change Management","Secure Development (SDLC) & Application Security"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc8-1-2a7ddd54.html","id":"ctrl:soc2:CC8.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC8.1","sourceIds":["soc2"],"sourceUrl":null,"title":"CC8.1 — The entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures to meet its objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc8-1-2a7ddd54.cbc0e965fa722d3b.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions.","details":{"automation":"manual","control_category":"administrative","control_id":"CC9.1","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Access Control & Identity Management","Logging, Monitoring & Detection","Incident Management & Response","Secure Configuration & Change Management","Compliance, Audit & Assurance","Third-Party / Supply-Chain Risk"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc9-1-6178c12c.html","id":"ctrl:soc2:CC9.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC9.1","sourceIds":["soc2"],"sourceUrl":null,"title":"CC9.1 — The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc9-1-6178c12c.9d24bf2b979e48c0.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity assesses and manages risks associated with vendors and business partners.","details":{"automation":"manual","control_category":"administrative","control_id":"CC9.2","control_type":"preventive","domains":["Third-Party / Supply-Chain Risk"],"framework":"soc2","group":"Common Criteria (Security)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":7,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-cc9-2-b2000c2a.html","id":"ctrl:soc2:CC9.2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC9.2","sourceIds":["soc2"],"sourceUrl":null,"title":"CC9.2 — The entity assesses and manages risks associated with vendors and business partners.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc9-2-b2000c2a.13b99e0f0822b807.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity provides notice to data subjects about its privacy practices to meet the entity's objectives related to privacy. The notice is updated and communicated to data subjects in a timely manner for changes to the entity's privacy practices, including changes in the use of personal information, to meet the entity's objectives related to privacy.","details":{"automation":"manual","control_category":"administrative","control_id":"P1.1","control_type":"preventive","domains":["Data Protection & Privacy"],"framework":"soc2","group":"Privacy","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-p1-1-c08fea86.html","id":"ctrl:soc2:P1.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3AP1.1","sourceIds":["soc2"],"sourceUrl":null,"title":"P1.1 — The entity provides notice to data subjects about its privacy practices to meet the entity's objectives related to privacy. The notice is updated and communicated to data subjects in a timely manner for changes to the entity's privacy practices, including changes in the use of personal information, to meet the entity's objectives related to privacy.","type":"control","url":"/assets/agent_record-ctrl-soc2-p1-1-c08fea86.a463f80bf1fc3643.json"},{"attributes":{"category":"administrative","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information to the data subjects and the consequences, if any, of each choice. Explicit consent for the collection, use, retention, disclosure, and disposal of personal information is obtained from data subjects or other authorized persons, if required. Such consent is obtained only for the intended purpose of the information to meet the entity's objectives related to privacy. The entity's basis for determining implicit consent for the collection, use, retention, disclosure, and disposal of personal information is documented.","details":{"automation":"manual","control_category":"administrative","control_id":"P2.1","control_type":"preventive","domains":["Data Protection & Privacy"],"framework":"soc2","group":"Privacy","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"htmlUrl":"/agents/records/ctrl-soc2-p2-1-3e8a1b5b.html","id":"ctrl:soc2:P2.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3AP2.1","sourceIds":["soc2"],"sourceUrl":null,"title":"P2.1 — The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information to the data subjects and the consequences, if any, of each choice. Explicit consent for the collection, use, retention, disclosure, and disposal of personal information is obtained from data subjects or other authorized persons, if required. Such consent is obtained only for the intended purpose of the information to meet the entity's objectives related to privacy. The entity's basis for determining implicit consent for the collection, use, retention, disclosure, and disposal of personal information is documented.","type":"control","url":"/assets/agent_record-ctrl-soc2-p2-1-3e8a1b5b.b86913a672d6ae6f.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:00a6acd87d36a2b9e49833a233080bd85f93be3a284785c4166c7f2054db546b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc5-2-2d184a95.json","sourceId":"ctrl:soc2:CC5.2","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:02a5d2a50715f32e9243fb01416fdf6f45de0691dafff6497fd17e060a3ef5f7","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-p2-1-3e8a1b5b.json","sourceId":"ctrl:soc2:P2.1","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:04b1cbcb9aa6448f5ba2bb6969cc6fe6b63c542aaf032ff56f7d837be725b8a8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc5-3-46feecd1.json","sourceId":"ctrl:soc2:CC5.3","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0606dc7c984e0f797f0315cf5364be8e7cd6bce773466787adb2c299473264d0","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc1-3-05d9fef7.json","sourceId":"ctrl:soc2:CC1.3","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0c6ef72ce50fea52ce2bb9889053328161ea0284d14ed9a7df0c1a16329cdfcf","properties":{"control_id":"CC6.4","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-4-4132a487.json","targetId":"ctrl:soc2:CC6.4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0d32a23302f8a9d5ade7d9d2e1255ee237df593019fdbf2136c96bc15ee4f853","properties":{"control_id":"CC2.3","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-21-8c5d79f9.json","sourceId":"uc:UC-GOV-21","targetDetailPath":"/data/v1/records/ctrl-soc2-cc2-3-b0ace578.json","targetId":"ctrl:soc2:CC2.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:125a06279b89f21754fb1b340d7c1c8f71f2a576d096754aeed05bf361d07aad","properties":{"control_id":"CC6.5","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-5-449f6335.json","targetId":"ctrl:soc2:CC6.5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1555972e90283c5fbfc60bf63f89b6b11806e52c80363142885e9c303a9af02f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-c1-1-d20576fd.json","sourceId":"ctrl:soc2:C1.1","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:160ed925d84e1fcbb90636e2e5b69b2fa89aa199794d42a3971fb54df6938c64","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc7-2-7ca85bf1.json","sourceId":"ctrl:soc2:CC7.2","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1d05fc488bb82a51f8853521d1fcbfae211372a2da40addc5f037bee16a37d1c","properties":{"control_id":"CC9.1","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-34-3de22bbe.json","sourceId":"uc:UC-GOV-34","targetDetailPath":"/data/v1/records/ctrl-soc2-cc9-1-6178c12c.json","targetId":"ctrl:soc2:CC9.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1f3943c0d3b59f6a7630f5166f3bc0d6df0f0c6310741a964dcba79a4b03a5e2","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc6-6-31bdbb9f.json","sourceId":"ctrl:soc2:CC6.6","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1ffa1b9a4f7392dad928a080fcb54d34c08c9839b31b6508e8e63587e7163858","properties":{"control_id":"CC6.3","coverage":"partial","delta":"modifying/removing access on change and periodic role review handled by companion controls","framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-3-4ade392f.json","targetId":"ctrl:soc2:CC6.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:202e5a48b02726723affa45ada5a4321cf8ea30b4231d1be2b787e8afaafe5bc","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc2-1-83b34ada.json","sourceId":"ctrl:soc2:CC2.1","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:20eeaaa70c3d13f426d734d1fd904439aac7d50aff227060a9c8f6190f54b204","properties":{"control_id":"CC6.1","coverage":"partial","delta":"logical access architecture and enforcement addressed by access-control domain","framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-1-683a2035.json","targetId":"ctrl:soc2:CC6.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:223c1f1a2554f514f0d3d655b729ada39c9b1111614479cbe1e0ad17f4cd1044","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc3-2-18f9e8ee.json","sourceId":"ctrl:soc2:CC3.2","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:24092cdfb69568d26f2bb13fc48e3fb4256eca15150f7ba2828356c1dcfb477c","properties":{"control_id":"CC5.3","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/ctrl-soc2-cc5-3-46feecd1.json","targetId":"ctrl:soc2:CC5.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2474df81197fea9038d7c242b4ccd27c39ee5cfeb8fd73d2855f9224389aa0fb","properties":{"control_id":"CC1.1","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/ctrl-soc2-cc1-1-ad48e3c3.json","targetId":"ctrl:soc2:CC1.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:24b869c67dad40c5667ffef07d50f6bc774dfca61aa04e40c75efeca9f9d9ba8","properties":{"control_id":"CC4.1","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-13-75b9f6c7.json","sourceId":"uc:UC-RISK-13","targetDetailPath":"/data/v1/records/ctrl-soc2-cc4-1-12630f31.json","targetId":"ctrl:soc2:CC4.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:26233caa920ef10f9afe736421dac96d7acf434a1c33a60f2ce9b78aeaa125d9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc2-3-b0ace578.json","sourceId":"ctrl:soc2:CC2.3","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:277573eae90fe379a15933c63c520341ef0445025e5043a4b9a67eb28eae1b2b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc4-1-12630f31.json","sourceId":"ctrl:soc2:CC4.1","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3041c237576a80539c8e6a1d5d685d3a5fcf03ece53aabe7377d12a8faaac8db","properties":{"control_id":"CC2.1","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-25-e23c8618.json","sourceId":"uc:UC-AUDIT-25","targetDetailPath":"/data/v1/records/ctrl-soc2-cc2-1-83b34ada.json","targetId":"ctrl:soc2:CC2.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:35acc0742fe766708ad03b93b836214d4e90afe798caf06b44994877b7dfca12","properties":{"control_id":"CC3.1","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-04-1a2bee69.json","sourceId":"uc:UC-RISK-04","targetDetailPath":"/data/v1/records/ctrl-soc2-cc3-1-4fb807c4.json","targetId":"ctrl:soc2:CC3.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:35f968a4c679ca801deafd807d768f88e3a721618bff69da66b19b70fea1c3bd","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc7-1-a0583d17.json","sourceId":"ctrl:soc2:CC7.1","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3c83d27d46c0508a1f21ca605e37869a18ecca86c2ddd41df9af37c3a25f6409","properties":{"control_id":"CC3.4","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-11-3f5d23ea.json","sourceId":"uc:UC-RISK-11","targetDetailPath":"/data/v1/records/ctrl-soc2-cc3-4-a6d03c70.json","targetId":"ctrl:soc2:CC3.4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3ed5941b73dd7874c840cb8bad70c3600f18763b07c45b4b69a2e628d5923309","properties":{"control_id":"A1.2","coverage":"partial","delta":"environmental protections and recovery-infrastructure operation satisfied by companion controls","framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-03-d30f4ccf.json","sourceId":"uc:UC-BCDR-03","targetDetailPath":"/data/v1/records/ctrl-soc2-a1-2-d4182682.json","targetId":"ctrl:soc2:A1.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:46bb0f25ee9e847f6aa85930a4d80b7a18cedcd6d6d54d06acf3fef21232ab89","properties":{"control_id":"CC1.2","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","sourceId":"uc:UC-GOV-05","targetDetailPath":"/data/v1/records/ctrl-soc2-cc1-2-f5deb30e.json","targetId":"ctrl:soc2:CC1.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4882f091e28b3b9056302a734101095ffbddbce2ea27b6aa406ae94d126e0bc3","properties":{"control_id":"CC7.5","coverage":"partial","delta":"root-cause determination, changes to prevent recurrence, and recovery-plan improvement and testing satisfied by the post-incident review and contingency-testing companion controls","framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-09-6caefe96.json","sourceId":"uc:UC-IR-09","targetDetailPath":"/data/v1/records/ctrl-soc2-cc7-5-580af9de.json","targetId":"ctrl:soc2:CC7.5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4ee0089acbdf1d0e8565a4ffa2e7291588b25371743b391fa62faf8fbc177232","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc6-2-639c148c.json","sourceId":"ctrl:soc2:CC6.2","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:50cee16f195e4a53819356af00385ef79f1d3e77022d081c5855674b8db3ad87","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-c1-2-e6a223bc.json","sourceId":"ctrl:soc2:C1.2","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:553ac6e7596b2e003f27a92290e7074e418a0269b77d041ed15d91b64d95204d","properties":{"control_id":"CC6.8","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-config-05-84d5ee43.json","sourceId":"uc:UC-CONFIG-05","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-8-dc7a8dc8.json","targetId":"ctrl:soc2:CC6.8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5b8340bd225a67f59c4b316b677dc08327288d4fe131ebd24917dd6f79e8925f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-a1-2-d4182682.json","sourceId":"ctrl:soc2:A1.2","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5d52f2055953fe737ee10babb032dda07f79f43ac7836cee7524f79c717db230","properties":{"control_id":"CC7.1","coverage":"partial","delta":"also requires monitoring susceptibility to newly discovered vulnerabilities","framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-config-01-8f911a32.json","sourceId":"uc:UC-CONFIG-01","targetDetailPath":"/data/v1/records/ctrl-soc2-cc7-1-a0583d17.json","targetId":"ctrl:soc2:CC7.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5ef044c90953e65e85bb8fe7788a7872e66f0f10f11ccde8103e0c5dadc04622","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc3-1-4fb807c4.json","sourceId":"ctrl:soc2:CC3.1","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6117926bb515257ea47cd345ef189a9f142cbfa7449115ed1f3f4253ea3ec625","properties":{"control_id":"CC6.2","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-2-639c148c.json","targetId":"ctrl:soc2:CC6.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:634b009ac7a014847974c4c5f736979ba7b567e5024b9875e385e2d9bae38978","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc1-1-ad48e3c3.json","sourceId":"ctrl:soc2:CC1.1","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:64327e7d0d70619115ccc7e9c40086be1ab209bb36a6f2989105f88e8a3ed5ed","properties":{"control_id":"A1.1","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-05-f73361f2.json","sourceId":"uc:UC-BCDR-05","targetDetailPath":"/data/v1/records/ctrl-soc2-a1-1-a9048d7a.json","targetId":"ctrl:soc2:A1.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:658aee58abbb2690bfab6bb13e22dc2730250054b2b221e1a1eac0a39340b357","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-a1-1-a9048d7a.json","sourceId":"ctrl:soc2:A1.1","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:66ae9a7d90cd5afd661b1a7a480575f945aec911b7b7d946692e98743faf9220","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc7-5-580af9de.json","sourceId":"ctrl:soc2:CC7.5","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:70676750bd6879fd40a2faf14afa3200ede764d0931ad976dccfc0a71a8cc412","properties":{"control_id":"P2.1","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-data-02-56e3d60a.json","sourceId":"uc:UC-DATA-02","targetDetailPath":"/data/v1/records/ctrl-soc2-p2-1-3e8a1b5b.json","targetId":"ctrl:soc2:P2.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:755930a2267db14151071e27c7edf890aabd6da76eb71af9ba66b69b52bbe266","properties":{"control_id":"A1.3","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-10-602160e4.json","sourceId":"uc:UC-BCDR-10","targetDetailPath":"/data/v1/records/ctrl-soc2-a1-3-b64a7d41.json","targetId":"ctrl:soc2:A1.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7cf87b06c30e40a2d936d2bd84d5d9efd540c28c42a1974998f2158f00a4e73e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc8-1-2a7ddd54.json","sourceId":"ctrl:soc2:CC8.1","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8276e3e5266d232aa63fa0040d134624c83cf0a1352d83ca16b366c66aa81d4c","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc6-7-f815d553.json","sourceId":"ctrl:soc2:CC6.7","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:865977e459181fd80ca2236c5e70cb45907c4b5ff1d1b2a4e29884339c904142","properties":{"control_id":"CC1.3","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-06-f1eb1346.json","sourceId":"uc:UC-GOV-06","targetDetailPath":"/data/v1/records/ctrl-soc2-cc1-3-05d9fef7.json","targetId":"ctrl:soc2:CC1.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:93b44e6858da80f81994a73c500022027de052979a4b0c71a71fc262f5ce440a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc7-4-4e5ce771.json","sourceId":"ctrl:soc2:CC7.4","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:93c7b4ecafc7357939d7211611c3815656b5f01ce4be2df9e7bbd7d1239fc127","properties":{"control_id":"CC7.2","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","sourceId":"uc:UC-LOG-04","targetDetailPath":"/data/v1/records/ctrl-soc2-cc7-2-7ca85bf1.json","targetId":"ctrl:soc2:CC7.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:94433ff2f6ecf4d45cab4f60a72dd3669b3b631d02d90ce8497493a32dbe35c0","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc2-2-2736ed02.json","sourceId":"ctrl:soc2:CC2.2","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:981c400816049b849cc0babc2e238f4d180f187b7f170d0ad03bf744d4d27a5d","properties":{"control_id":"C1.2","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-data-09-f83a01a3.json","sourceId":"uc:UC-DATA-09","targetDetailPath":"/data/v1/records/ctrl-soc2-c1-2-e6a223bc.json","targetId":"ctrl:soc2:C1.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9a8e31395f1a0aa9f088751b51c22c60cbbc9f1726ba19240d1c674702db153e","properties":{"control_id":"CC2.2","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-21-8c5d79f9.json","sourceId":"uc:UC-GOV-21","targetDetailPath":"/data/v1/records/ctrl-soc2-cc2-2-2736ed02.json","targetId":"ctrl:soc2:CC2.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9d279613be481937a2f722e1369cdc349cfc498b12f01c1e439ba7dfc26bd75d","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc7-3-00826815.json","sourceId":"ctrl:soc2:CC7.3","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a3786d1fae3f34d11e7a2fc4c134dbe3e4f8f11415e81f9e89098ff07b83c3fa","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc4-2-1538fe1e.json","sourceId":"ctrl:soc2:CC4.2","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a3c663135f7d8a8d57cfb4f9bb8a39ed982452307c90150956220f5c9c06bbaf","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-a1-3-b64a7d41.json","sourceId":"ctrl:soc2:A1.3","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a4b177747cf7fca0d42d421fb31eaf92700c261981bde96dd419d161d49b028b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc6-1-683a2035.json","sourceId":"ctrl:soc2:CC6.1","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ad0a7f92ed019cfadbee8cca5e7b258f735ec0336ddf667f2a538e17bb9665c7","properties":{"control_id":"CC1.5","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-07-2a8998f7.json","sourceId":"uc:UC-GOV-07","targetDetailPath":"/data/v1/records/ctrl-soc2-cc1-5-ce418f10.json","targetId":"ctrl:soc2:CC1.5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b1c905c690707c5e5b1808360bd40c7cd93ac373d9eb4d23cabedda2c2e3fe3d","properties":{"control_id":"CC6.6","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","sourceId":"uc:UC-NET-01","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-6-31bdbb9f.json","targetId":"ctrl:soc2:CC6.6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b1e0fadedb57c20d3ea67fbd9e84dca3abeffb503857bdef4a04f5cc656382c4","properties":{"control_id":"CC3.2","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-06-e9599494.json","sourceId":"uc:UC-RISK-06","targetDetailPath":"/data/v1/records/ctrl-soc2-cc3-2-18f9e8ee.json","targetId":"ctrl:soc2:CC3.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b37d4589579a81430878968dce3969f9fd85cf8caa2e68cd14a3642c3acda619","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc6-8-dc7a8dc8.json","sourceId":"ctrl:soc2:CC6.8","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:baa62d7911b5a63df9a179a2a3f8cd4c2da2f87e34ead389fb8ab12a79907568","properties":{"control_id":"CC5.2","coverage":"partial","delta":"developing and operating the specific technology general controls (infrastructure, security management, acquisition/development/maintenance) satisfied by dedicated ITGC companion controls; this UC delivers their selection into the baseline","framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-16-694834ac.json","sourceId":"uc:UC-GOV-16","targetDetailPath":"/data/v1/records/ctrl-soc2-cc5-2-2d184a95.json","targetId":"ctrl:soc2:CC5.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bc99e007c71e42cc3d4bf6b9ab664fe75460620a0232604a96df35d258564241","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc6-5-449f6335.json","sourceId":"ctrl:soc2:CC6.5","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c19721fc7c566d0344c00c9bf5527f1d7d6fe3c11dc112cf1db4c698954e2681","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc9-2-b2000c2a.json","sourceId":"ctrl:soc2:CC9.2","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c1fbcea3921a16b9e7385d64cfdea26afb335b35891013fa7b3be8e731582774","properties":{"control_id":"P1.1","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-data-05-3244ac25.json","sourceId":"uc:UC-DATA-05","targetDetailPath":"/data/v1/records/ctrl-soc2-p1-1-c08fea86.json","targetId":"ctrl:soc2:P1.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c32b3778a69afd89df946c6c57476030f88c4e0b2610085353e7f87ac4812f2c","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc6-3-4ade392f.json","sourceId":"ctrl:soc2:CC6.3","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c4aede063404f15c4aee018871d0a4b458aee737dcef9711460cb006ed3e43b9","properties":{"control_id":"CC7.3","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","sourceId":"uc:UC-LOG-06","targetDetailPath":"/data/v1/records/ctrl-soc2-cc7-3-00826815.json","targetId":"ctrl:soc2:CC7.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c5d760a449feda01f47e31c45e8ddc213d3c4565c6561064234d6f5844e715a0","properties":{"control_id":"CC4.2","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-14-a5d6281b.json","sourceId":"uc:UC-RISK-14","targetDetailPath":"/data/v1/records/ctrl-soc2-cc4-2-1538fe1e.json","targetId":"ctrl:soc2:CC4.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c636f5bd82f576a260f48b6af0bdfc244af6af024886cbd0bcc4a882d50b6355","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc9-1-6178c12c.json","sourceId":"ctrl:soc2:CC9.1","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c6b7a150cb296f8a9ed43aae0b1ffa79c70c4d2bc56ea7ad7afe13fc2d1d0bb7","properties":{"control_id":"CC6.7","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-7-f815d553.json","targetId":"ctrl:soc2:CC6.7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d56d7a17f6d5732e2343735df501f59f10c4f0b0b2ebf4086549e0e839c5744c","properties":{"control_id":"CC9.2","coverage":"partial","delta":"ongoing monitoring, termination handling, and contractual security/confidentiality commitments satisfied by companion vendor-management and vendor-contract controls","framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","sourceId":"uc:UC-TPRM-02","targetDetailPath":"/data/v1/records/ctrl-soc2-cc9-2-b2000c2a.json","targetId":"ctrl:soc2:CC9.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d79376504a3a081bdd5b95030688cee8fa169ecab628887667d8350c038b0f2a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc1-5-ce418f10.json","sourceId":"ctrl:soc2:CC1.5","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e1cc704ea09d6634277a60ba8859bd51a1fbd57912095356311b703b6b16e2aa","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc1-4-6e16c0ae.json","sourceId":"ctrl:soc2:CC1.4","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e6898673f73ec6c2c52ac2d0a6b02ae79c6b507573fb96d6f74d5fd137d5ff6e","properties":{"control_id":"C1.1","coverage":"partial","delta":"also requires retaining and protecting confidential information per commitments","framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","sourceId":"uc:UC-ASSET-03","targetDetailPath":"/data/v1/records/ctrl-soc2-c1-1-d20576fd.json","targetId":"ctrl:soc2:C1.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e6a3c49e98b53bab84e8306adb559798b22552b85dfd7457f49fa17571803d6b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-p1-1-c08fea86.json","sourceId":"ctrl:soc2:P1.1","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ea943c0a016fd53ff5a51c77514c247b92c3e81bb00f580878b9a66411e142a1","properties":{"control_id":"CC3.3","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-12-210e108b.json","sourceId":"uc:UC-RISK-12","targetDetailPath":"/data/v1/records/ctrl-soc2-cc3-3-ae6eeb77.json","targetId":"ctrl:soc2:CC3.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ebba965077a399da6c58b738353a45bd27c5b41ac9f316d5d400094500489f8c","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc3-3-ae6eeb77.json","sourceId":"ctrl:soc2:CC3.3","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eee175d1643d80beca9bb14d6c6a26c300e0257e140779f9e67825e4b2568c77","properties":{"control_id":"CC7.4","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-06-0b166c2a.json","sourceId":"uc:UC-IR-06","targetDetailPath":"/data/v1/records/ctrl-soc2-cc7-4-4e5ce771.json","targetId":"ctrl:soc2:CC7.4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ef7ae699e0aa18ae537aebc15a418c10d908014487032a4ef1f89108edf45655","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc3-4-a6d03c70.json","sourceId":"ctrl:soc2:CC3.4","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f26be9d13e80f2bb9eedddc4166c4d95422b613204e8e240c059a7ed504b8893","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc1-2-f5deb30e.json","sourceId":"ctrl:soc2:CC1.2","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fabab7d79d61fa4786d125223a5e61eb8061bedbdd845b7f9eaae877b4e9a322","properties":{"control_id":"CC8.1","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-config-02-175d55b0.json","sourceId":"uc:UC-CONFIG-02","targetDetailPath":"/data/v1/records/ctrl-soc2-cc8-1-2a7ddd54.json","targetId":"ctrl:soc2:CC8.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fc722ea274f3cc0d81a8a299f7e39497596df0bfc462a5ff1ab14c7eca25c467","properties":{"control_id":"CC1.4","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-06-36a1f4aa.json","sourceId":"uc:UC-HR-06","targetDetailPath":"/data/v1/records/ctrl-soc2-cc1-4-6e16c0ae.json","targetId":"ctrl:soc2:CC1.4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fcadeddf8322233770fecd4b7e33a5b6ffc7ddd7fd4dba5f8882b8470f5119af","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc5-1-b6b93caa.json","sourceId":"ctrl:soc2:CC5.1","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ff53461ebd7baefda3430830c2703050a34ef52547441cdc32b97c0a0532e271","properties":{"control_id":"CC5.1","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-16-694834ac.json","sourceId":"uc:UC-GOV-16","targetDetailPath":"/data/v1/records/ctrl-soc2-cc5-1-b6b93caa.json","targetId":"ctrl:soc2:CC5.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ff84623659b413281813d71f841f68682ce761d624df5d1084fb4cdce9373c9f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc6-4-4132a487.json","sourceId":"ctrl:soc2:CC6.4","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"}],"schemaVersion":1,"scope":"sources","total":319}
