{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["ctrl:cobit-2019:DSS01","ctrl:cobit-2019:DSS02","ctrl:cobit-2019:DSS03","ctrl:cobit-2019:MEA03","ctrl:coso-ic:P13","ctrl:dora:DORA-Art17-23","ctrl:gdpr:GDPR-Art30","ctrl:gdpr:GDPR-Art6","ctrl:hipaa:HIPAA-164.310","ctrl:iso-27001:A.5.10","ctrl:iso-27001:A.5.11","ctrl:iso-27001:A.5.12","ctrl:iso-27001:A.5.13","ctrl:iso-27001:A.5.14","ctrl:iso-27001:A.5.32","ctrl:iso-27001:A.5.9","ctrl:iso-27001:A.7.1","ctrl:iso-27001:A.7.10","ctrl:iso-27001:A.7.14","ctrl:iso-27001:A.7.2","ctrl:iso-27001:A.7.3","ctrl:iso-27001:A.7.4","ctrl:iso-27001:A.7.6","ctrl:iso-27001:A.7.9","ctrl:iso-27001:A.8.1","ctrl:iso-27001:A.8.10","ctrl:iso-27001:A.8.13","ctrl:iso-27001:A.8.14","ctrl:iso-27001:A.8.19","ctrl:nist-800-53:AC-20","ctrl:nist-800-53:CM-10","ctrl:nist-800-53:CM-11","ctrl:nist-800-53:CM-14","ctrl:nist-800-53:CM-8","ctrl:nist-800-53:CP-10","ctrl:nist-800-53:CP-6","ctrl:nist-800-53:CP-7","ctrl:nist-800-53:CP-8","ctrl:nist-800-53:CP-9","ctrl:nist-800-53:MA-3"],"directIds":[],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"Asset Management & Inventory","next":"/assets/agent_topics-asset-management-inventory-2.9b4ad71358a47f44.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Operations","details":{"automation":"hybrid","control_category":"administrative","control_id":"DSS01","control_type":"preventive","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"cobit-2019","group":"Deliver, Service and Support","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-dss01-d3ff2961.html","id":"ctrl:cobit-2019:DSS01","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ADSS01","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"DSS01 — Managed Operations","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-dss01-d3ff2961.90fbf85675339668.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Service Requests and Incidents","details":{"automation":"hybrid","control_category":"administrative","control_id":"DSS02","control_type":"corrective","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"cobit-2019","group":"Deliver, Service and Support","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-dss02-af5bca5d.html","id":"ctrl:cobit-2019:DSS02","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ADSS02","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"DSS02 — Managed Service Requests and Incidents","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-dss02-af5bca5d.d9fabf94aa20dc7d.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Problems","details":{"automation":"manual","control_category":"administrative","control_id":"DSS03","control_type":"corrective","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"cobit-2019","group":"Deliver, Service and Support","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-dss03-2540740f.html","id":"ctrl:cobit-2019:DSS03","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ADSS03","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"DSS03 — Managed Problems","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-dss03-2540740f.0983703d1904b1c5.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Compliance With External Requirements","details":{"automation":"manual","control_category":"administrative","control_id":"MEA03","control_type":"detective","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"cobit-2019","group":"Monitor, Evaluate and Assess","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-mea03-99c7dcca.html","id":"ctrl:cobit-2019:MEA03","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3AMEA03","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"MEA03 — Managed Compliance With External Requirements","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-mea03-99c7dcca.fefbe693d563ef85.json"},{"attributes":{"category":"administrative","framework":"coso-ic","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-ic/","description":"The organization obtains or generates and uses relevant, quality information to support the functioning of internal control.","details":{"automation":"manual","control_category":"administrative","control_id":"P13","control_type":"preventive","domains":["Asset Management & Inventory","Data Protection & Privacy","Financial Reporting Controls (SOX)"],"framework":"coso-ic","group":"Information & Communication","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-ic-p13-0c70843b.html","id":"ctrl:coso-ic:P13","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-ic%3AP13","sourceIds":["coso-ic"],"sourceUrl":null,"title":"P13 — The organization obtains or generates and uses relevant, quality information to support the functioning of internal control.","type":"control","url":"/assets/agent_record-ctrl-coso-ic-p13-0c70843b.fc063ba70f8a75b7.json"},{"attributes":{"category":"administrative","framework":"dora","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/dora/","description":"ICT-related incident management, classification and reporting","details":{"automation":"hybrid","control_category":"administrative","control_id":"DORA-Art17-23","control_type":"corrective","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Third-Party / Supply-Chain Risk","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"dora","group":"EU DORA (Digital Operational Resilience Act)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-dora-dora-art17-23-9aa7977f.html","id":"ctrl:dora:DORA-Art17-23","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Adora%3ADORA-Art17-23","sourceIds":["dora"],"sourceUrl":null,"title":"DORA-Art17-23 — ICT-related incident management, classification and reporting","type":"control","url":"/assets/agent_record-ctrl-dora-dora-art17-23-9aa7977f.313cf7638f5cfdb3.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Records of processing activities (RoPA)","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art30","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art30-e7db10f3.html","id":"ctrl:gdpr:GDPR-Art30","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art30","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art30 — Records of processing activities (RoPA)","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art30-e7db10f3.1bae307ce9713d40.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Lawfulness of processing","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art6","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art6-cbe66aa0.html","id":"ctrl:gdpr:GDPR-Art6","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art6","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art6 — Lawfulness of processing","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art6-cbe66aa0.b28f5e1b1bc8659e.json"},{"attributes":{"category":"physical","framework":"hipaa","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/hipaa/","description":"Physical safeguards (facility access controls, workstation use/security, device and media controls)","details":{"automation":"hybrid","control_category":"physical","control_id":"HIPAA-164.310","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Data Protection & Privacy"],"framework":"hipaa","group":"HIPAA Security Rule","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-hipaa-hipaa-164-310-9cf84fad.html","id":"ctrl:hipaa:HIPAA-164.310","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Ahipaa%3AHIPAA-164.310","sourceIds":["hipaa"],"sourceUrl":null,"title":"HIPAA-164.310 — Physical safeguards (facility access controls, workstation use/security, device and media controls)","type":"control","url":"/assets/agent_record-ctrl-hipaa-hipaa-164-310-9cf84fad.0d7044dffd909ae9.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Acceptable use of information and other associated assets","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.10","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-10-2d5f0877.html","id":"ctrl:iso-27001:A.5.10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.10","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.10 — Acceptable use of information and other associated assets","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-10-2d5f0877.67fb64be930936a4.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Return of assets","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.11","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-11-07680424.html","id":"ctrl:iso-27001:A.5.11","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.11","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.11 — Return of assets","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-11-07680424.e29c61129efc0ae8.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Classification of information","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.12","control_type":"preventive","domains":["Asset Management & Inventory","Data Protection & Privacy"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-12-eb4887b2.html","id":"ctrl:iso-27001:A.5.12","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.12","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.12 — Classification of information","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-12-eb4887b2.f3a76354a77f1a7f.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Labelling of information","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.13","control_type":"preventive","domains":["Asset Management & Inventory","Data Protection & Privacy"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-13-b1e84751.html","id":"ctrl:iso-27001:A.5.13","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.13","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.13 — Labelling of information","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-13-b1e84751.a5267f95b7149451.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Information transfer","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.14","control_type":"preventive","domains":["Asset Management & Inventory","Network & Communications Security"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-14-c427daf1.html","id":"ctrl:iso-27001:A.5.14","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.14","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.14 — Information transfer","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-14-c427daf1.d7457a44e46ee804.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Intellectual property rights","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.32","control_type":"preventive","domains":["Compliance, Audit & Assurance"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-32-7342e3f4.html","id":"ctrl:iso-27001:A.5.32","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.32","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.32 — Intellectual property rights","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-32-7342e3f4.528c5cd3488b2ecc.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Inventory of information and other associated assets","details":{"automation":"hybrid","control_category":"administrative","control_id":"A.5.9","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-9-64706ee7.html","id":"ctrl:iso-27001:A.5.9","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.9","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.9 — Inventory of information and other associated assets","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-9-64706ee7.4127a3f45cfb1299.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Physical security perimeters","details":{"automation":"manual","control_category":"physical","control_id":"A.7.1","control_type":"preventive","domains":["Physical & Environmental Security"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-1-a327b00e.html","id":"ctrl:iso-27001:A.7.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.1","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.1 — Physical security perimeters","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-7-1-a327b00e.7551706bb69779cc.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Storage media","details":{"automation":"manual","control_category":"physical","control_id":"A.7.10","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-10-2bfc8971.html","id":"ctrl:iso-27001:A.7.10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.10","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.10 — Storage media","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-7-10-2bfc8971.36c105414741e977.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Secure disposal or re-use of equipment","details":{"automation":"manual","control_category":"physical","control_id":"A.7.14","control_type":"preventive","domains":["Asset Management & Inventory","Physical & Environmental Security"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-14-5ada9a8e.html","id":"ctrl:iso-27001:A.7.14","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.14","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.14 — Secure disposal or re-use of equipment","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-7-14-5ada9a8e.6ece171fd37d329a.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Physical entry","details":{"automation":"hybrid","control_category":"physical","control_id":"A.7.2","control_type":"preventive","domains":["Physical & Environmental Security"],"framework":"iso-27001","group":"Physical controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-2-7f774ee6.html","id":"ctrl:iso-27001:A.7.2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.2","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.2 — Physical entry","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-7-2-7f774ee6.ea167e51a16a3695.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Securing offices, rooms and facilities","details":{"automation":"manual","control_category":"physical","control_id":"A.7.3","control_type":"preventive","domains":["Physical & Environmental Security"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-3-1b2f4ae0.html","id":"ctrl:iso-27001:A.7.3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.3","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.3 — Securing offices, rooms and facilities","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-7-3-1b2f4ae0.d6e9be0fa6209938.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Physical security monitoring","details":{"automation":"hybrid","control_category":"physical","control_id":"A.7.4","control_type":"detective","domains":["Physical & Environmental Security"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-4-9f51f324.html","id":"ctrl:iso-27001:A.7.4","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.4","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.4 — Physical security monitoring","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-7-4-9f51f324.e9114519c20d6a8f.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Working in secure areas","details":{"automation":"manual","control_category":"physical","control_id":"A.7.6","control_type":"preventive","domains":["Physical & Environmental Security"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-6-3e5f12bc.html","id":"ctrl:iso-27001:A.7.6","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.6","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.6 — Working in secure areas","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-7-6-3e5f12bc.a785d5c03eb9e0a8.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Security of assets off-premises","details":{"automation":"manual","control_category":"physical","control_id":"A.7.9","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-9-43947bba.html","id":"ctrl:iso-27001:A.7.9","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.9","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.9 — Security of assets off-premises","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-7-9-43947bba.c6ef66cfb8830a9c.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"User endpoint devices","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.1","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-1-12f14999.html","id":"ctrl:iso-27001:A.8.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.1","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.1 — User endpoint devices","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-1-12f14999.273137a54d65477a.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Information deletion","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.10","control_type":"preventive","domains":["Data Protection & Privacy"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-10-8e3feb8b.html","id":"ctrl:iso-27001:A.8.10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.10","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.10 — Information deletion","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-10-8e3feb8b.6163cfe8db756b62.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Information backup","details":{"automation":"automated","control_category":"technical","control_id":"A.8.13","control_type":"corrective","domains":["Business Continuity & Disaster Recovery"],"framework":"iso-27001","group":"Technological controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-13-23e70806.html","id":"ctrl:iso-27001:A.8.13","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.13","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.13 — Information backup","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-13-23e70806.88286a292a4227d6.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Redundancy of information processing facilities","details":{"automation":"automated","control_category":"technical","control_id":"A.8.14","control_type":"corrective","domains":["Business Continuity & Disaster Recovery"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-14-3901c4da.html","id":"ctrl:iso-27001:A.8.14","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.14","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.14 — Redundancy of information processing facilities","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-14-3901c4da.8d14b46f10639f5e.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Installation of software on operational systems","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.19","control_type":"preventive","domains":["Secure Configuration & Change Management"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-19-44c22e39.html","id":"ctrl:iso-27001:A.8.19","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.19","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.19 — Installation of software on operational systems","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-19-44c22e39.545f3e62c0b33cfe.json"},{"attributes":{"category":"administrative","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Use of External Systems","details":{"automation":"manual","control_category":"administrative","control_id":"AC-20","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"nist-800-53","group":"Access Control","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-ac-20-6e822026.html","id":"ctrl:nist-800-53:AC-20","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3AAC-20","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"AC-20 — Use of External Systems","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-ac-20-6e822026.123e8f1f431a107e.json"},{"attributes":{"category":"administrative","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Software Usage Restrictions","details":{"automation":"manual","control_category":"administrative","control_id":"CM-10","control_type":"preventive","domains":["Secure Configuration & Change Management","Asset Management & Inventory"],"framework":"nist-800-53","group":"Configuration Management","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-cm-10-5490946c.html","id":"ctrl:nist-800-53:CM-10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ACM-10","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CM-10 — Software Usage Restrictions","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-cm-10-5490946c.19018af579f6fa64.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"User-installed Software","details":{"automation":"hybrid","control_category":"technical","control_id":"CM-11","control_type":"preventive","domains":["Secure Configuration & Change Management"],"framework":"nist-800-53","group":"Configuration Management","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-cm-11-8a205c95.html","id":"ctrl:nist-800-53:CM-11","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ACM-11","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CM-11 — User-installed Software","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-cm-11-8a205c95.689db9255b9aa3b9.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Signed Components","details":{"automation":"automated","control_category":"technical","control_id":"CM-14","control_type":"preventive","domains":["Secure Configuration & Change Management","Asset Management & Inventory"],"framework":"nist-800-53","group":"Configuration Management","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-cm-14-64650a51.html","id":"ctrl:nist-800-53:CM-14","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ACM-14","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CM-14 — Signed Components","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-cm-14-64650a51.45ef150de138baab.json"},{"attributes":{"category":"administrative","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"System Component Inventory","details":{"automation":"hybrid","control_category":"administrative","control_id":"CM-8","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"nist-800-53","group":"Configuration Management","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-cm-8-d6b0ba27.html","id":"ctrl:nist-800-53:CM-8","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ACM-8","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CM-8 — System Component Inventory","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-cm-8-d6b0ba27.d1cb00e0a6d51e30.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"System Recovery and Reconstitution","details":{"automation":"hybrid","control_category":"technical","control_id":"CP-10","control_type":"corrective","domains":["Business Continuity & Disaster Recovery"],"framework":"nist-800-53","group":"Contingency Planning","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-cp-10-8d8dfd5a.html","id":"ctrl:nist-800-53:CP-10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ACP-10","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CP-10 — System Recovery and Reconstitution","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-cp-10-8d8dfd5a.5a0ea1f45ddd29b7.json"},{"attributes":{"category":"physical","framework":"nist-800-53","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Alternate Storage Site","details":{"automation":"manual","control_category":"physical","control_id":"CP-6","control_type":"corrective","domains":["Business Continuity & Disaster Recovery"],"framework":"nist-800-53","group":"Contingency Planning","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-cp-6-8b2868ea.html","id":"ctrl:nist-800-53:CP-6","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ACP-6","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CP-6 — Alternate Storage Site","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-cp-6-8b2868ea.4f24d8da878c25b4.json"},{"attributes":{"category":"physical","framework":"nist-800-53","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Alternate Processing Site","details":{"automation":"manual","control_category":"physical","control_id":"CP-7","control_type":"corrective","domains":["Business Continuity & Disaster Recovery"],"framework":"nist-800-53","group":"Contingency Planning","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-cp-7-b42f3ba9.html","id":"ctrl:nist-800-53:CP-7","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ACP-7","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CP-7 — Alternate Processing Site","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-cp-7-b42f3ba9.c22d026a613082e7.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Telecommunications Services","details":{"automation":"hybrid","control_category":"technical","control_id":"CP-8","control_type":"corrective","domains":["Business Continuity & Disaster Recovery"],"framework":"nist-800-53","group":"Contingency Planning","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-cp-8-cc006118.html","id":"ctrl:nist-800-53:CP-8","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ACP-8","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CP-8 — Telecommunications Services","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-cp-8-cc006118.b9db800a4212e5c8.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"System Backup","details":{"automation":"automated","control_category":"technical","control_id":"CP-9","control_type":"corrective","domains":["Business Continuity & Disaster Recovery"],"framework":"nist-800-53","group":"Contingency Planning","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-cp-9-d9112bea.html","id":"ctrl:nist-800-53:CP-9","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ACP-9","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CP-9 — System Backup","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-cp-9-d9112bea.af46db5cf94945ac.json"},{"attributes":{"category":"administrative","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Maintenance Tools","details":{"automation":"manual","control_category":"administrative","control_id":"MA-3","control_type":"preventive","domains":["Secure Configuration & Change Management"],"framework":"nist-800-53","group":"Maintenance","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-ma-3-1dc1f1d5.html","id":"ctrl:nist-800-53:MA-3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3AMA-3","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"MA-3 — Maintenance Tools","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-ma-3-1dc1f1d5.701c8af5c7e43644.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0193ee372df87471f989640b9a67875fec12d77ca2480b3c725772ea14d52169","properties":{"control_id":"A.8.1","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-1-12f14999.json","targetId":"ctrl:iso-27001:A.8.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:066a3a0e5eb15d5845581b56b0e1609668817c04ae2412887b1e532a9815acfd","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-1-a327b00e.json","sourceId":"ctrl:iso-27001:A.7.1","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:10d0f981e11b450b1cb9af6b4c7f2a68baebfa3b64cfe1f67f257533fd9a70c9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-ma-3-1dc1f1d5.json","sourceId":"ctrl:nist-800-53:MA-3","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:10f2c8f3da582a25784d9db0b56806fe33641235b08257f7ed6a433ed4973603","properties":{"control_id":"A.7.10","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-10-2bfc8971.json","targetId":"ctrl:iso-27001:A.7.10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:147ae985b733872ac1b56a5c69d128a1273023f70c2ca3795bb209a971d54203","properties":{"control_id":"A.8.13","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-03-d30f4ccf.json","sourceId":"uc:UC-BCDR-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-13-23e70806.json","targetId":"ctrl:iso-27001:A.8.13","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:154d032b8c8a51251df0659b39df888301f7cb7aae1f872ad0aa66f4279be75b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-310-9cf84fad.json","sourceId":"ctrl:hipaa:HIPAA-164.310","targetDetailPath":"/data/v1/records/std-hipaa-a825d271.json","targetId":"std:hipaa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:165477b789f44ce9d930421335c11f36733e2cb74deaafce7580ec576dacad75","properties":{"control_id":"MEA03","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-24-fa96fe18.json","sourceId":"uc:UC-AUDIT-24","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-mea03-99c7dcca.json","targetId":"ctrl:cobit-2019:MEA03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:169d6622df6fde59aa992aa7416fb7c99cae450e0c56b5f5b5e87dc64e061da5","properties":{"control_id":"A.7.6","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-6-3e5f12bc.json","targetId":"ctrl:iso-27001:A.7.6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:176b2ff48f0328e6487bbba5bb2db8598d2eed6505c55c794d9b1c1b814e9dcc","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-14-5ada9a8e.json","sourceId":"ctrl:iso-27001:A.7.14","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:180cd078fc831b671b5afb4ab1987c145fe458af88d172f34c611ab5240242d8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art30-e7db10f3.json","sourceId":"ctrl:gdpr:GDPR-Art30","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:18457278e43b410f52161ca8640e0370690eb4a499175ad48b54070e4905c372","properties":{"control_id":"A.7.9","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-9-43947bba.json","targetId":"ctrl:iso-27001:A.7.9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1e436015deeb46e84ecb360078a2ec5da9b1a73ab35cb977613f368ef5081c90","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-10-5490946c.json","sourceId":"ctrl:nist-800-53:CM-10","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1f351b41c6da0c2df1781cfe55b9bd525fa4f987dd6f2432800908487b9d0e8e","properties":{"control_id":"A.7.1","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-1-a327b00e.json","targetId":"ctrl:iso-27001:A.7.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:20e4b2a31e5517b32fa223ea9b1b8fd79f1f9756c4fd2ee3519a688b1e5e002f","properties":{"control_id":"DSS02","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss02-af5bca5d.json","targetId":"ctrl:cobit-2019:DSS02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:238a45d8ea4f46ef5f4ceef5591956db44382d3276460b6165f8af6cac02f025","properties":{"control_id":"A.5.14","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-08-7413af1c.json","sourceId":"uc:UC-ASSET-08","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-14-c427daf1.json","targetId":"ctrl:iso-27001:A.5.14","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2525c39295ea228ebb567a859879ac822a2efc6cfd453409cbb70d179fbbcfac","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-3-1b2f4ae0.json","sourceId":"ctrl:iso-27001:A.7.3","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:27dd5e945af28141d844fab51e3199d7c1f67cead03cf2660e5481fa101c8ec7","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-9-64706ee7.json","sourceId":"ctrl:iso-27001:A.5.9","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2cb89276c4531270f1a98b51d3cff3d981127e180cb4fac86e7f8a121b6ed785","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-9-d9112bea.json","sourceId":"ctrl:nist-800-53:CP-9","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2e2b50c86f8b2218c14fb4e9569a5c8a0507a11726b723c80dff2fd945514676","properties":{"control_id":"A.8.10","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-data-09-f83a01a3.json","sourceId":"uc:UC-DATA-09","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-10-8e3feb8b.json","targetId":"ctrl:iso-27001:A.8.10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2fa9ee745188901dc9cf334d826e8e52a294a06c63ae786f99df85acdb98780d","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-dss02-af5bca5d.json","sourceId":"ctrl:cobit-2019:DSS02","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3165ad3f02bcdb9746b97d6edcc165a99e985acca005200d7abf6cd12495da6a","properties":{"control_id":"A.5.13","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","sourceId":"uc:UC-ASSET-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-13-b1e84751.json","targetId":"ctrl:iso-27001:A.5.13","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:36569c96d581a0f13c86b5cebcc2272b76c64149dd4942b9c22b3145bcbefe45","properties":{"control_id":"A.5.12","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","sourceId":"uc:UC-ASSET-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-12-eb4887b2.json","targetId":"ctrl:iso-27001:A.5.12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:39b30f0980dc2a4c11b9ce2b623bbf9a939d0e5b5aace19f0d2e7cc96a2afa98","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-10-8e3feb8b.json","sourceId":"ctrl:iso-27001:A.8.10","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3cdceed58717a8955895a09f9613a3e23c9f0f9b2ca82d5699366641c3d670d2","properties":{"control_id":"A.5.11","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-07-5039208b.json","sourceId":"uc:UC-ASSET-07","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-11-07680424.json","targetId":"ctrl:iso-27001:A.5.11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3dbf331723a49242ebe31772d373a6634fca02ad4e43de322e54db40626811f5","properties":{"control_id":"A.7.4","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-02-05f35d07.json","sourceId":"uc:UC-PHYS-02","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-4-9f51f324.json","targetId":"ctrl:iso-27001:A.7.4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:42ae85e554b79183ad5bea734690a293ff4d9ee213e7f81c944c2c034d22b91e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-10-8d8dfd5a.json","sourceId":"ctrl:nist-800-53:CP-10","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:44cc4186b5c1bb4eff60a99d8daf742e4590cc9298b27c249ab8845d231946b4","properties":{"control_id":"A.7.3","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-3-1b2f4ae0.json","targetId":"ctrl:iso-27001:A.7.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:487724165a10b9798cbe1ef95c6cb5b09f052f518fe78f70353322a25de9a5db","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-14-3901c4da.json","sourceId":"ctrl:iso-27001:A.8.14","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:512ba21439e87bc291748f791f63165c51c302598232ea229c29542a3578a201","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-dss03-2540740f.json","sourceId":"ctrl:cobit-2019:DSS03","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:51eb1aaf372e56e178e80a1502ebfcf0f2725d63b17c3f28280480fc3cce7f20","properties":{"control_id":"A.7.2","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-2-7f774ee6.json","targetId":"ctrl:iso-27001:A.7.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:521a89a1ca7581bbd368a446574c3a54f920420d19d82a0f4a5512f7200a8cd7","properties":{"control_id":"P13","coverage":"partial","delta":"COSO expects quality information supporting all internal control components","framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-02-6c6ac61b.json","sourceId":"uc:UC-ASSET-02","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p13-0c70843b.json","targetId":"ctrl:coso-ic:P13","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:524a42280be8e0712969b39078dfe8a89b3683d09127c7a7556f44b8bc25f7f9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-6-8b2868ea.json","sourceId":"ctrl:nist-800-53:CP-6","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5a1cadd30ef153d96c37530c120af1562f4fc2e98f1b340e21fb987963c815f7","properties":{"control_id":"A.8.19","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-config-05-84d5ee43.json","sourceId":"uc:UC-CONFIG-05","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-19-44c22e39.json","targetId":"ctrl:iso-27001:A.8.19","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6211dca87613b36dc26a16c224980c7d5e044c31c777bf4c86c9880d1a51ee8e","properties":{"control_id":"A.5.10","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-10-2d5f0877.json","targetId":"ctrl:iso-27001:A.5.10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6245560e88a0b25a51c060ec56866eed4994290ee0d92752753fc75bd841b7e1","properties":{"control_id":"A.5.32","coverage":"partial","delta":"operational IPR safeguards - license/asset registers with usage-vs-entitlement enforcement, proof-of-license retention, and acquisition from authorized sources - beyond registering and periodically evaluating the obligation","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-24-fa96fe18.json","sourceId":"uc:UC-AUDIT-24","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-32-7342e3f4.json","targetId":"ctrl:iso-27001:A.5.32","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6301bb8cf6f4875e4d952e85a9fc2d0b2bed417d787eecd0b09b7a45ed5a94c8","properties":{"control_id":"CM-11","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-config-05-84d5ee43.json","sourceId":"uc:UC-CONFIG-05","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-11-8a205c95.json","targetId":"ctrl:nist-800-53:CM-11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:66b3d3aad91497c34fbf2759a01d50a1872a5c3b0a00bc4fb7a7ea0a60d7ef30","properties":{"control_id":"MA-3","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-config-08-e94308da.json","sourceId":"uc:UC-CONFIG-08","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ma-3-1dc1f1d5.json","targetId":"ctrl:nist-800-53:MA-3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:67a81d9aca89e4727d57d92fc43b1c8cbe3b0c88584059ee23fb1534698bdc32","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-ic-p13-0c70843b.json","sourceId":"ctrl:coso-ic:P13","targetDetailPath":"/data/v1/records/std-coso-ic-3f80f565.json","targetId":"std:coso-ic","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6af614e2df6e6cbc6408a920bff22a8f313e53b22bf9fd40b97a28f4fb1e3822","properties":{"control_id":"AC-20","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-20-6e822026.json","targetId":"ctrl:nist-800-53:AC-20","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6c4f29c5c1ef53eef065930a6efca8c7f780ffff4c3c5becbf5a5c49ab2ec6b3","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-14-64650a51.json","sourceId":"ctrl:nist-800-53:CM-14","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6cd84798e905847e4af7974212aca5ac6b13a2458f611342d5d25dac426d73e0","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-14-c427daf1.json","sourceId":"ctrl:iso-27001:A.5.14","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6cd89c31a0f6722453e9f1cb4ee69e4fdb4992f60f3243d03259b9058b5738c2","properties":{"control_id":"DSS01","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-12-0d9cc358.json","sourceId":"uc:UC-BCDR-12","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss01-d3ff2961.json","targetId":"ctrl:cobit-2019:DSS01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6ea2241cc7573102a2aa155e24e4f6d70ec70c02aab173cecabbec89872ced48","properties":{"control_id":"GDPR-Art6","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-data-01-9fcf72e8.json","sourceId":"uc:UC-DATA-01","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art6-cbe66aa0.json","targetId":"ctrl:gdpr:GDPR-Art6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6fa8c61aa8f5bf102eca5de1145906d3c2b635e765a122d5fea40e943b36360a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-10-2bfc8971.json","sourceId":"ctrl:iso-27001:A.7.10","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7048bc38b1c19805455ed20fca10e5ab08ce34c3afa5cff4429f02cedf05f05e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-19-44c22e39.json","sourceId":"ctrl:iso-27001:A.8.19","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:756e56aa28d97bf259c164c3a495b12aa99c615b674fb0906739098afb29070a","properties":{"control_id":"A.8.14","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-04-5d004f42.json","sourceId":"uc:UC-BCDR-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-14-3901c4da.json","targetId":"ctrl:iso-27001:A.8.14","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7600e8066bd80f681f6cdd1adaff667045e6a5a0ff9a75dcdce290af53c5d65d","properties":{"control_id":"HIPAA-164.310","coverage":"partial","delta":"also covers workstation use/security and device and media controls","framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-310-9cf84fad.json","targetId":"ctrl:hipaa:HIPAA-164.310","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7b190dc2b7f123c2b0335469fe3cbd6b4641a35e43788a8ef24e109959e26c7b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-7-b42f3ba9.json","sourceId":"ctrl:nist-800-53:CP-7","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7be827f3f5f3b5ec04d16ec812c4240d136e0301d0b63eca8450857a1eed7d00","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-13-b1e84751.json","sourceId":"ctrl:iso-27001:A.5.13","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7c4757cbea8a44d57e05fb416fa000732b28c508b262641ae99493be0ed4c882","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-11-07680424.json","sourceId":"ctrl:iso-27001:A.5.11","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7def629af2e63fd82808e5330d7a6291c876c04b5d6a94c9439d1d9e8229b592","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-10-2d5f0877.json","sourceId":"ctrl:iso-27001:A.5.10","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:84965314f57b1f964f26b51977ca58ae0531e7ad88e5a04a6527a95f2ad721f8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-20-6e822026.json","sourceId":"ctrl:nist-800-53:AC-20","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8b9de4df2b9b11f4758d16caba3a14418486d52562080438d56995febeaf4511","properties":{"control_id":"DORA-Art17-23","coverage":"partial","delta":"major-incident report clocks: initial 24h, intermediate 72h, final 1 month","framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art17-23-9aa7977f.json","targetId":"ctrl:dora:DORA-Art17-23","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:960d0f0d80955dfcf6ff9d5494af149cc09ad90267ced52de0c441b7a6fa5258","properties":{"control_id":"GDPR-Art30","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-02-6c6ac61b.json","sourceId":"uc:UC-ASSET-02","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art30-e7db10f3.json","targetId":"ctrl:gdpr:GDPR-Art30","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:96f2fb180f84f99fb86941c3b49202eb0caef57d3105f6680d156665adeddebd","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-dss01-d3ff2961.json","sourceId":"ctrl:cobit-2019:DSS01","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9cf7441a234b2e10473c8821a2cd7077ba4c41b418d5433379f0fdd638b535e2","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-6-3e5f12bc.json","sourceId":"ctrl:iso-27001:A.7.6","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9f229e45003f2c7c825f7932294437466bf8be9e39c6c4ab0bcb25d8dc6b2192","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-dora-dora-art17-23-9aa7977f.json","sourceId":"ctrl:dora:DORA-Art17-23","targetDetailPath":"/data/v1/records/std-dora-95cf939d.json","targetId":"std:dora","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a34d1b95310d02df2f38016789331618ad71256de254d7d5290a8d14dc84ba75","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-2-7f774ee6.json","sourceId":"ctrl:iso-27001:A.7.2","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a3b9aa8dc72577ef82f115806dd492aee5b6087954584bbabb0d498bc835896a","properties":{"control_id":"CP-10","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-07-e5d74596.json","sourceId":"uc:UC-BCDR-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-10-8d8dfd5a.json","targetId":"ctrl:nist-800-53:CP-10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a73ec3cd22801fc393e49ceaaaebeb68441349a625535ea5f13c226d0ef9b5ea","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-32-7342e3f4.json","sourceId":"ctrl:iso-27001:A.5.32","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a945420f1311deb2ede68743201f30e4c3b8977422c38ceae982e25b19d47deb","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-9-43947bba.json","sourceId":"ctrl:iso-27001:A.7.9","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:acbedbf085108cdf393bb33351fbcf48e610d18345317ae33d0037259992e143","properties":{"control_id":"CM-10","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-config-05-84d5ee43.json","sourceId":"uc:UC-CONFIG-05","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-10-5490946c.json","targetId":"ctrl:nist-800-53:CM-10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b06dd8979f216ebfd8a54ea6e4a2f9f3783324b5e41888b2bb10b06f271e56e0","properties":{"control_id":"CP-9","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-03-d30f4ccf.json","sourceId":"uc:UC-BCDR-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-9-d9112bea.json","targetId":"ctrl:nist-800-53:CP-9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b4899f7912335a7240c0671a7d3f47a9fbe675ab613f66e382e3146270615b93","properties":{"control_id":"A.7.14","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-14-5ada9a8e.json","targetId":"ctrl:iso-27001:A.7.14","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b99514009d751c4de5dcc2cc86e5c023aed69f78a104e25390068405c5caf7c9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-8-cc006118.json","sourceId":"ctrl:nist-800-53:CP-8","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bb81974adc1ada5498944c8d63e01254f1dd56c1067d93f111a7108e053a2b5f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-4-9f51f324.json","sourceId":"ctrl:iso-27001:A.7.4","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bf750d3c6442fa00e90c0f7f6c2b6ad46182baf74575d4b56bb9a668ff64f93b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-1-12f14999.json","sourceId":"ctrl:iso-27001:A.8.1","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bfb7de3a8015b3a23a00a22565f5ec4ed0ddcdd12489f4bb54574cd8ddbc7472","properties":{"control_id":"DSS03","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss03-2540740f.json","targetId":"ctrl:cobit-2019:DSS03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cbf5b1fd90a88dc6e4b251867131daf48c0905ada385c3258cfe4fa4ea7b95e1","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art6-cbe66aa0.json","sourceId":"ctrl:gdpr:GDPR-Art6","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cef009418dd209296a5536bef4f3ea2ed698d83ab27d7147585bfe22c8a477fa","properties":{"control_id":"CP-8","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-04-5d004f42.json","sourceId":"uc:UC-BCDR-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-8-cc006118.json","targetId":"ctrl:nist-800-53:CP-8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d0ea89650d6c0179809d1fef5a3584ceaeeee59d78450193d0b2c71a83fc4608","properties":{"control_id":"CM-8","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-8-d6b0ba27.json","targetId":"ctrl:nist-800-53:CM-8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d47a58eb6d3c1d423e8a62159f33a83555f2ec34e8506657e6f990dfac5cacb5","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-11-8a205c95.json","sourceId":"ctrl:nist-800-53:CM-11","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d9e6e946442603aaa9b6e365c4fb9d605c4c50779bdc4c1096c55f30636bd335","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-12-eb4887b2.json","sourceId":"ctrl:iso-27001:A.5.12","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dd37b54a97d7a95a246a6ff755255a6880b917586da6259561c950566b3787b3","properties":{"control_id":"CP-7","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-04-5d004f42.json","sourceId":"uc:UC-BCDR-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-7-b42f3ba9.json","targetId":"ctrl:nist-800-53:CP-7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ddb0646430e762b2edd17c5ab6751bb80c3cb89ba0766edd3f89033aacc36cd0","properties":{"control_id":"CP-6","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-04-5d004f42.json","sourceId":"uc:UC-BCDR-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-6-8b2868ea.json","targetId":"ctrl:nist-800-53:CP-6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dfe559816aa8494a6d1fd4b26b3aea935be01495f24dc5dffe6db21953a20c19","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-13-23e70806.json","sourceId":"ctrl:iso-27001:A.8.13","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e115412b6dbd6e8acfd6e03c6f5a8f3d855469e2439b614314f3c5731fa7e439","properties":{"control_id":"A.5.9","coverage":"partial","delta":"inventorying information (data) assets themselves, addressed by the data-inventory control","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-9-64706ee7.json","targetId":"ctrl:iso-27001:A.5.9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb4f44d97f08b10b4d8988ddd92feffde262f146c9d895c2b11f7766e58f875d","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-mea03-99c7dcca.json","sourceId":"ctrl:cobit-2019:MEA03","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f28187b4b13bb811680bf53dc2228fd88a3f228694d5dab047c9dd7fc4896441","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-8-d6b0ba27.json","sourceId":"ctrl:nist-800-53:CM-8","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f9b6574049a8871d046cf6854d785cb6baf1e72ff41e7206fc5b9b3e17a9a3cd","properties":{"control_id":"CM-14","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-config-06-31f293f7.json","sourceId":"uc:UC-CONFIG-06","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-14-64650a51.json","targetId":"ctrl:nist-800-53:CM-14","type":"maps_to"}],"schemaVersion":1,"scope":"topics","total":193}
