{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["ctrl:aiuc-1:A008","ctrl:aiuc-1:B002","ctrl:aiuc-1:B004","ctrl:aiuc-1:B005","ctrl:aiuc-1:B010","ctrl:aiuc-1:E005","ctrl:hipaa:HIPAA-164.312(e)","ctrl:iso-27001:A.8.24","ctrl:nist-800-53:AC-17","ctrl:nist-800-53:AC-18","ctrl:nist-800-53:AC-19","ctrl:nist-800-53:IA-7","ctrl:nist-800-53:SC-10","ctrl:nist-800-53:SC-11","ctrl:nist-800-53:SC-12","ctrl:nist-800-53:SC-13","ctrl:nist-800-53:SC-17","ctrl:nist-800-53:SC-20","ctrl:nist-800-53:SC-21","ctrl:nist-800-53:SC-22","ctrl:nist-800-53:SC-23","ctrl:nist-800-53:SC-28","ctrl:nist-800-53:SC-37","ctrl:nist-800-53:SC-40","ctrl:nist-800-53:SC-45","ctrl:nist-800-53:SC-8","ctrl:nist-ai-agent-identity:NIST-AGI-06","ctrl:nist-ai-tevv-athlon:NIST-TEVV-05","ctrl:nist-csf-2:PR.DS-01","ctrl:nist-csf-2:PR.DS-02","ctrl:nist-csf-2:PR.DS-10","ctrl:nydfs-500:500.15","ctrl:pci-dss:PCI-Req3","ctrl:pci-dss:PCI-Req4","ctrl:soc2:CC6.7"],"directIds":["risk:ai-secrets-credential-leakage","risk:crypto-cleartext-credential-transfer","risk:crypto-counterfeit-certificates","risk:crypto-weak-or-absent-encryption","risk:net-interception-mitm"],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"Cryptography & Key Management","next":"/assets/agent_topics-cryptography-key-management-2.341ff9ae8dee0b5b.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Prevent leakage of credentials and secrets","details":{"automation":"automated","control_category":"technical","control_id":"A008","control_type":"preventive","domains":["AI Governance","Data Protection & Privacy"],"framework":"aiuc-1","group":"Data & Privacy","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":2,"source_pages":null,"source_url":"https://www.aiuc-1.com/data-and-privacy/prevent-secrets-leakage"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-a008-509139e6.html","id":"ctrl:aiuc-1:A008","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AA008","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/data-and-privacy/prevent-secrets-leakage","title":"A008 — Prevent leakage of credentials and secrets","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-a008-509139e6.3ed78f02e164abfc.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Detect adversarial input","details":{"automation":"automated","control_category":"technical","control_id":"B002","control_type":"detective","domains":["AI Governance","Access Control & Identity Management","Secure Development (SDLC) & Application Security"],"framework":"aiuc-1","group":"Security","key_control":false,"requirement_frequency":"Every 3 months","requirement_status":"optional","risk_count":4,"source_pages":null,"source_url":"https://www.aiuc-1.com/security/detect-adversarial-input"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-b002-07a4b0e1.html","id":"ctrl:aiuc-1:B002","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AB002","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/security/detect-adversarial-input","title":"B002 — Detect adversarial input","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-b002-07a4b0e1.dc1c0aa05175aea1.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Prevent AI endpoint scraping","details":{"automation":"automated","control_category":"technical","control_id":"B004","control_type":"preventive","domains":["AI Governance","Access Control & Identity Management","Secure Development (SDLC) & Application Security"],"framework":"aiuc-1","group":"Security","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":4,"source_pages":null,"source_url":"https://www.aiuc-1.com/security/prevent-ai-endpoint-scraping"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-b004-d4ff3b14.html","id":"ctrl:aiuc-1:B004","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AB004","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/security/prevent-ai-endpoint-scraping","title":"B004 — Prevent AI endpoint scraping","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-b004-d4ff3b14.a9e4d50c6372d755.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Implement real-time input filtering","details":{"automation":"automated","control_category":"technical","control_id":"B005","control_type":"detective","domains":["AI Governance","Access Control & Identity Management","Secure Development (SDLC) & Application Security"],"framework":"aiuc-1","group":"Security","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"optional","risk_count":4,"source_pages":null,"source_url":"https://www.aiuc-1.com/security/implement-real-time-input-filtering"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-b005-fe985c7b.html","id":"ctrl:aiuc-1:B005","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AB005","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/security/implement-real-time-input-filtering","title":"B005 — Implement real-time input filtering","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-b005-fe985c7b.4f92c99c324b08c4.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Promote secure patterns in generated code","details":{"automation":"hybrid","control_category":"technical","control_id":"B010","control_type":"preventive","domains":["AI Governance","Access Control & Identity Management","Secure Development (SDLC) & Application Security"],"framework":"aiuc-1","group":"Security","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":2,"source_pages":null,"source_url":"https://www.aiuc-1.com/security/promote-secure-code-patterns"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-b010-a075f8e3.html","id":"ctrl:aiuc-1:B010","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AB010","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/security/promote-secure-code-patterns","title":"B010 — Promote secure patterns in generated code","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-b010-a075f8e3.25eccdcd936d65d0.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Document data storage security","details":{"automation":"manual","control_category":"administrative","control_id":"E005","control_type":"preventive","domains":["AI Governance","Governance, Policy & Oversight"],"framework":"aiuc-1","group":"Accountability","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":4,"source_pages":null,"source_url":"https://www.aiuc-1.com/accountability/assess-cloud-vs-on-prem-processing"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-e005-8a88c16c.html","id":"ctrl:aiuc-1:E005","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AE005","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/accountability/assess-cloud-vs-on-prem-processing","title":"E005 — Document data storage security","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-e005-8a88c16c.c5c6eceff8634985.json"},{"attributes":{"category":"technical","framework":"hipaa","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/hipaa/","description":"Transmission security for ePHI (integrity controls and encryption in transit)","details":{"automation":"automated","control_category":"technical","control_id":"HIPAA-164.312(e)","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Data Protection & Privacy"],"framework":"hipaa","group":"HIPAA Security Rule","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-hipaa-hipaa-164-312-e-edf6e525.html","id":"ctrl:hipaa:HIPAA-164.312(e)","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Ahipaa%3AHIPAA-164.312%28e%29","sourceIds":["hipaa"],"sourceUrl":null,"title":"HIPAA-164.312(e) — Transmission security for ePHI (integrity controls and encryption in transit)","type":"control","url":"/assets/agent_record-ctrl-hipaa-hipaa-164-312-e-edf6e525.cc09c2cb5592142d.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Use of cryptography","details":{"automation":"automated","control_category":"technical","control_id":"A.8.24","control_type":"preventive","domains":["Cryptography & Key Management"],"framework":"iso-27001","group":"Technological controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-24-f5cc6274.html","id":"ctrl:iso-27001:A.8.24","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.24","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.24 — Use of cryptography","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-24-f5cc6274.553cbbe56ae1369e.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Remote Access","details":{"automation":"hybrid","control_category":"technical","control_id":"AC-17","control_type":"preventive","domains":["Network & Communications Security"],"framework":"nist-800-53","group":"Access Control","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-ac-17-4b0ce4dd.html","id":"ctrl:nist-800-53:AC-17","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3AAC-17","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"AC-17 — Remote Access","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-ac-17-4b0ce4dd.e9743dea29d9fabb.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Wireless Access","details":{"automation":"hybrid","control_category":"technical","control_id":"AC-18","control_type":"preventive","domains":["Network & Communications Security"],"framework":"nist-800-53","group":"Access Control","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-ac-18-e2c1b10c.html","id":"ctrl:nist-800-53:AC-18","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3AAC-18","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"AC-18 — Wireless Access","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-ac-18-e2c1b10c.58183ac6f13a18f2.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Access Control for Mobile Devices","details":{"automation":"hybrid","control_category":"technical","control_id":"AC-19","control_type":"preventive","domains":["Network & Communications Security"],"framework":"nist-800-53","group":"Access Control","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-ac-19-ec21db96.html","id":"ctrl:nist-800-53:AC-19","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3AAC-19","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"AC-19 — Access Control for Mobile Devices","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-ac-19-ec21db96.fc83978bb66ccb3c.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Cryptographic Module Authentication","details":{"automation":"automated","control_category":"technical","control_id":"IA-7","control_type":"preventive","domains":["Cryptography & Key Management"],"framework":"nist-800-53","group":"Identification and Authentication","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-ia-7-7dfc5b71.html","id":"ctrl:nist-800-53:IA-7","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3AIA-7","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"IA-7 — Cryptographic Module Authentication","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-ia-7-7dfc5b71.eb71d0353f10f7ae.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Network Disconnect","details":{"automation":"automated","control_category":"technical","control_id":"SC-10","control_type":"preventive","domains":["Network & Communications Security","Cryptography & Key Management","Business Continuity & Disaster Recovery"],"framework":"nist-800-53","group":"System and Communications Protection","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-sc-10-01b0320e.html","id":"ctrl:nist-800-53:SC-10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ASC-10","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"SC-10 — Network Disconnect","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-sc-10-01b0320e.ca106595110251ea.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Trusted Path","details":{"automation":"automated","control_category":"technical","control_id":"SC-11","control_type":"preventive","domains":["Network & Communications Security","Cryptography & Key Management","Business Continuity & Disaster Recovery"],"framework":"nist-800-53","group":"System and Communications Protection","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-sc-11-971f92bc.html","id":"ctrl:nist-800-53:SC-11","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ASC-11","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"SC-11 — Trusted Path","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-sc-11-971f92bc.50b7b9458ebd470c.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Cryptographic Key Establishment and Management","details":{"automation":"hybrid","control_category":"technical","control_id":"SC-12","control_type":"preventive","domains":["Cryptography & Key Management"],"framework":"nist-800-53","group":"System and Communications Protection","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-sc-12-afabf2ca.html","id":"ctrl:nist-800-53:SC-12","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ASC-12","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"SC-12 — Cryptographic Key Establishment and Management","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-sc-12-afabf2ca.6e0e4ee7e969c6de.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Cryptographic Protection","details":{"automation":"automated","control_category":"technical","control_id":"SC-13","control_type":"preventive","domains":["Cryptography & Key Management"],"framework":"nist-800-53","group":"System and Communications Protection","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-sc-13-d7da2f08.html","id":"ctrl:nist-800-53:SC-13","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ASC-13","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"SC-13 — Cryptographic Protection","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-sc-13-d7da2f08.50bf0e729c67ba65.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Public Key Infrastructure Certificates","details":{"automation":"hybrid","control_category":"technical","control_id":"SC-17","control_type":"preventive","domains":["Cryptography & Key Management"],"framework":"nist-800-53","group":"System and Communications Protection","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-sc-17-b6802187.html","id":"ctrl:nist-800-53:SC-17","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ASC-17","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"SC-17 — Public Key Infrastructure Certificates","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-sc-17-b6802187.01133d712644df3a.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Secure Name/Address Resolution Service (Authoritative Source)","details":{"automation":"automated","control_category":"technical","control_id":"SC-20","control_type":"preventive","domains":["Network & Communications Security"],"framework":"nist-800-53","group":"System and Communications Protection","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-sc-20-534627dd.html","id":"ctrl:nist-800-53:SC-20","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ASC-20","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"SC-20 — Secure Name/Address Resolution Service (Authoritative Source)","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-sc-20-534627dd.73fd29745233ef4a.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Secure Name/Address Resolution Service (Recursive or Caching Resolver)","details":{"automation":"automated","control_category":"technical","control_id":"SC-21","control_type":"preventive","domains":["Network & Communications Security"],"framework":"nist-800-53","group":"System and Communications Protection","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-sc-21-720f7e8e.html","id":"ctrl:nist-800-53:SC-21","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ASC-21","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"SC-21 — Secure Name/Address Resolution Service (Recursive or Caching Resolver)","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-sc-21-720f7e8e.1e3cec417a867ea8.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Architecture and Provisioning for Name/Address Resolution Service","details":{"automation":"automated","control_category":"technical","control_id":"SC-22","control_type":"preventive","domains":["Network & Communications Security"],"framework":"nist-800-53","group":"System and Communications Protection","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-sc-22-b1767165.html","id":"ctrl:nist-800-53:SC-22","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ASC-22","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"SC-22 — Architecture and Provisioning for Name/Address Resolution Service","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-sc-22-b1767165.080c6b7ecb278efa.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Session Authenticity","details":{"automation":"automated","control_category":"technical","control_id":"SC-23","control_type":"preventive","domains":["Network & Communications Security"],"framework":"nist-800-53","group":"System and Communications Protection","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-sc-23-77326ab3.html","id":"ctrl:nist-800-53:SC-23","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ASC-23","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"SC-23 — Session Authenticity","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-sc-23-77326ab3.311d20cb55a7e7cc.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Protection of Information at Rest","details":{"automation":"automated","control_category":"technical","control_id":"SC-28","control_type":"preventive","domains":["Cryptography & Key Management","Data Protection & Privacy"],"framework":"nist-800-53","group":"System and Communications Protection","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-sc-28-740b8f3c.html","id":"ctrl:nist-800-53:SC-28","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ASC-28","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"SC-28 — Protection of Information at Rest","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-sc-28-740b8f3c.85043e67f83a77b2.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Out-of-band Channels","details":{"automation":"manual","control_category":"technical","control_id":"SC-37","control_type":"preventive","domains":["Network & Communications Security","Cryptography & Key Management","Business Continuity & Disaster Recovery"],"framework":"nist-800-53","group":"System and Communications Protection","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-sc-37-370be823.html","id":"ctrl:nist-800-53:SC-37","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ASC-37","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"SC-37 — Out-of-band Channels","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-sc-37-370be823.537163d926bb0017.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Wireless Link Protection","details":{"automation":"automated","control_category":"technical","control_id":"SC-40","control_type":"preventive","domains":["Network & Communications Security","Cryptography & Key Management","Business Continuity & Disaster Recovery"],"framework":"nist-800-53","group":"System and Communications Protection","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-sc-40-3d233d47.html","id":"ctrl:nist-800-53:SC-40","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ASC-40","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"SC-40 — Wireless Link Protection","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-sc-40-3d233d47.4e1c3b1d2578d4c3.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"System Time Synchronization","details":{"automation":"automated","control_category":"technical","control_id":"SC-45","control_type":"preventive","domains":["Network & Communications Security","Cryptography & Key Management","Business Continuity & Disaster Recovery"],"framework":"nist-800-53","group":"System and Communications Protection","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-sc-45-927bedb6.html","id":"ctrl:nist-800-53:SC-45","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ASC-45","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"SC-45 — System Time Synchronization","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-sc-45-927bedb6.90851848cfb7e799.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Transmission Confidentiality and Integrity","details":{"automation":"automated","control_category":"technical","control_id":"SC-8","control_type":"preventive","domains":["Cryptography & Key Management","Data Protection & Privacy","Network & Communications Security"],"framework":"nist-800-53","group":"System and Communications Protection","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-sc-8-56ac3e1a.html","id":"ctrl:nist-800-53:SC-8","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ASC-8","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"SC-8 — Transmission Confidentiality and Integrity","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-sc-8-56ac3e1a.a5d161cf21ea0237.json"},{"attributes":{"category":"technical","framework":"nist-ai-agent-identity","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-ai-agent-identity/","description":"The paper explicitly asks which controls help prevent direct and indirect prompt injection and which controls can limit its impact after an injection succeeds.","details":{"automation":"hybrid","control_category":"technical","control_id":"NIST-AGI-06","control_type":"preventive","domains":[],"framework":"nist-ai-agent-identity","group":"Agent Identity and Authorization Topics","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":0,"source_pages":"Concept paper p. 4: Prompt Injection prevention and mitigation","source_url":"https://www.nccoe.nist.gov/sites/default/files/2026-02/accelerating-the-adoption-of-software-and-ai-agent-identity-and-authorization-concept-paper.pdf#page=5","statement":"The paper explicitly asks which controls help prevent direct and indirect prompt injection and which controls can limit its impact after an injection succeeds."},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-ai-agent-identity-nist-agi-06-e6b81ea1.html","id":"ctrl:nist-ai-agent-identity:NIST-AGI-06","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-ai-agent-identity%3ANIST-AGI-06","sourceIds":["nist-ai-agent-identity"],"sourceUrl":"https://www.nccoe.nist.gov/sites/default/files/2026-02/accelerating-the-adoption-of-software-and-ai-agent-identity-and-authorization-concept-paper.pdf#page=5","title":"NIST-AGI-06 — Prompt-injection prevention and limits on resulting harm","type":"control","url":"/assets/agent_record-ctrl-nist-ai-agent-identity-nist-agi-06-e6b81ea1.062683d38430c824.json"},{"attributes":{"category":"technical","framework":"nist-ai-tevv-athlon","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-ai-tevv-athlon/","description":"Appendix B includes integrity tests for direct and indirect prompt injection, poisoning, obfuscated inputs, and retrieval weaknesses that could alter intended outputs or outcomes.","details":{"automation":"hybrid","control_category":"technical","control_id":"NIST-TEVV-05","control_type":"detective","domains":[],"framework":"nist-ai-tevv-athlon","group":"AI Evaluation and Agent Security Testing","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":0,"source_pages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks","source_url":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf#page=32","statement":"Appendix B includes integrity tests for direct and indirect prompt injection, poisoning, obfuscated inputs, and retrieval weaknesses that could alter intended outputs or outcomes."},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-ai-tevv-athlon-nist-tevv-05-f9e22b30.html","id":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-05","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-ai-tevv-athlon%3ANIST-TEVV-05","sourceIds":["nist-ai-tevv-athlon"],"sourceUrl":"https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.200-2.ipd.pdf#page=32","title":"NIST-TEVV-05 — Test direct and indirect prompt injection","type":"control","url":"/assets/agent_record-ctrl-nist-ai-tevv-athlon-nist-tevv-05-f9e22b30.b0eb7471f9aab513.json"},{"attributes":{"category":"technical","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-csf-2/","description":"Data Security: The confidentiality, integrity, and availability of data-at-rest are protected","details":{"automation":"automated","control_category":"technical","control_id":"PR.DS-01","control_type":"preventive","domains":["Cryptography & Key Management","Data Protection & Privacy"],"framework":"nist-csf-2","group":"Protect","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-csf-2-pr-ds-01-e42f5cc9.html","id":"ctrl:nist-csf-2:PR.DS-01","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-csf-2%3APR.DS-01","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"PR.DS-01 — Data Security: The confidentiality, integrity, and availability of data-at-rest are protected","type":"control","url":"/assets/agent_record-ctrl-nist-csf-2-pr-ds-01-e42f5cc9.6bddfb0fd86c74fc.json"},{"attributes":{"category":"technical","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-csf-2/","description":"Data Security: The confidentiality, integrity, and availability of data-in-transit are protected","details":{"automation":"automated","control_category":"technical","control_id":"PR.DS-02","control_type":"preventive","domains":["Cryptography & Key Management","Data Protection & Privacy","Network & Communications Security"],"framework":"nist-csf-2","group":"Protect","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-csf-2-pr-ds-02-3ef7fff1.html","id":"ctrl:nist-csf-2:PR.DS-02","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-csf-2%3APR.DS-02","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"PR.DS-02 — Data Security: The confidentiality, integrity, and availability of data-in-transit are protected","type":"control","url":"/assets/agent_record-ctrl-nist-csf-2-pr-ds-02-3ef7fff1.78659cc5d4d4f26d.json"},{"attributes":{"category":"technical","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-csf-2/","description":"Data Security: The confidentiality, integrity, and availability of data-in-use are protected","details":{"automation":"automated","control_category":"technical","control_id":"PR.DS-10","control_type":"preventive","domains":["Cryptography & Key Management","Data Protection & Privacy"],"framework":"nist-csf-2","group":"Protect","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-csf-2-pr-ds-10-0ec91e33.html","id":"ctrl:nist-csf-2:PR.DS-10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-csf-2%3APR.DS-10","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"PR.DS-10 — Data Security: The confidentiality, integrity, and availability of data-in-use are protected","type":"control","url":"/assets/agent_record-ctrl-nist-csf-2-pr-ds-10-0ec91e33.0e94206d2424dc72.json"},{"attributes":{"category":"technical","framework":"nydfs-500","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nydfs-500/","description":"Encryption of nonpublic information","details":{"automation":"automated","control_category":"technical","control_id":"500.15","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Access Control & Identity Management","Vulnerability & Patch Management","Logging, Monitoring & Detection","Third-Party / Supply-Chain Risk","Cryptography & Key Management","Incident Management & Response","Business Continuity & Disaster Recovery","Awareness & Training"],"framework":"nydfs-500","group":"NYDFS 500 (NY Cybersecurity Regulation, 23 NYCRR 500)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nydfs-500-500-15-5ef052ba.html","id":"ctrl:nydfs-500:500.15","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anydfs-500%3A500.15","sourceIds":["nydfs-500"],"sourceUrl":null,"title":"500.15 — Encryption of nonpublic information","type":"control","url":"/assets/agent_record-ctrl-nydfs-500-500-15-5ef052ba.9e4792460f3b19a6.json"},{"attributes":{"category":"technical","framework":"pci-dss","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/pci-dss/","description":"Protect stored account data","details":{"automation":"hybrid","control_category":"technical","control_id":"PCI-Req3","control_type":"preventive","domains":["Network & Communications Security","Secure Configuration & Change Management","Data Protection & Privacy","Cryptography & Key Management","Vulnerability & Patch Management","Secure Development (SDLC) & Application Security","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"pci-dss","group":"PCI DSS v4.0.1","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-pci-dss-pci-req3-e250c900.html","id":"ctrl:pci-dss:PCI-Req3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Apci-dss%3APCI-Req3","sourceIds":["pci-dss"],"sourceUrl":null,"title":"PCI-Req3 — Protect stored account data","type":"control","url":"/assets/agent_record-ctrl-pci-dss-pci-req3-e250c900.aacf1026a4750203.json"},{"attributes":{"category":"technical","framework":"pci-dss","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/pci-dss/","description":"Protect cardholder data with strong cryptography during transmission over open, public networks","details":{"automation":"automated","control_category":"technical","control_id":"PCI-Req4","control_type":"preventive","domains":["Network & Communications Security","Secure Configuration & Change Management","Data Protection & Privacy","Cryptography & Key Management","Vulnerability & Patch Management","Secure Development (SDLC) & Application Security","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"pci-dss","group":"PCI DSS v4.0.1","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-pci-dss-pci-req4-e571f282.html","id":"ctrl:pci-dss:PCI-Req4","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Apci-dss%3APCI-Req4","sourceIds":["pci-dss"],"sourceUrl":null,"title":"PCI-Req4 — Protect cardholder data with strong cryptography during transmission over open, public networks","type":"control","url":"/assets/agent_record-ctrl-pci-dss-pci-req4-e571f282.8ab354382b4994a8.json"},{"attributes":{"category":"technical","framework":"soc2","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/soc2/","description":"The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission, movement, or removal to meet the entity's objectives.","details":{"automation":"automated","control_category":"technical","control_id":"CC6.7","control_type":"preventive","domains":["Cryptography & Key Management","Network & Communications Security"],"framework":"soc2","group":"Common Criteria (Security)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-soc2-cc6-7-f815d553.html","id":"ctrl:soc2:CC6.7","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Asoc2%3ACC6.7","sourceIds":["soc2"],"sourceUrl":null,"title":"CC6.7 — The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission, movement, or removal to meet the entity's objectives.","type":"control","url":"/assets/agent_record-ctrl-soc2-cc6-7-f815d553.415b5992d8bfb895.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Data Protection & Privacy","Cryptography & Key Management"],"inherent_rating":"high","taxonomy":["owasp-llm-top10-2025","nist-ai-rmf-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-secrets-credential-leakage","description":"API keys, tokens, private keys, and connection strings pasted into prompts, returned in outputs, hardcoded in generated code, or captured in conversation logs are exposed to unauthorized parties or persisted outside secret management, enabling account takeover and lateral movement.","details":{"category":"ai_governance","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"ai-secrets-credential-leakage","taxonomies":["owasp-llm-top10-2025","nist-ai-rmf-risk"],"treatment":"mitigate"},"direct":true,"htmlUrl":"/agents/records/risk-ai-secrets-credential-leakage-abf1bf77.html","id":"risk:ai-secrets-credential-leakage","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aai-secrets-credential-leakage","sourceIds":["aiuc-1","nist-ai-agent-identity","nist-ai-tevv-athlon"],"sourceUrl":null,"title":"Credential and secret leakage through AI inputs, outputs, logs and generated code","type":"risk","url":"/assets/agent_record-risk-ai-secrets-credential-leakage-abf1bf77.102567b687c1fc7d.json"},{"attributes":{"category":"cyber_security","domain":["Cryptography & Key Management","Network & Communications Security"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acrypto-cleartext-credential-transfer","description":"Authentication credentials or sensitive system communications transmitted unencrypted over networks, and absence of mutual sender/receiver authentication, enable interception, credential theft, and spoofing.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"crypto-cleartext-credential-transfer","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":true,"htmlUrl":"/agents/records/risk-crypto-cleartext-credential-transfer-b88065a1.html","id":"risk:crypto-cleartext-credential-transfer","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acrypto-cleartext-credential-transfer","sourceIds":["aiuc-1","hipaa","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Credentials and sensitive data transmitted in clear text","type":"risk","url":"/assets/agent_record-risk-crypto-cleartext-credential-transfer-b88065a1.a9caa8149d5dd221.json"},{"attributes":{"category":"cyber_security","domain":["Cryptography & Key Management","Network & Communications Security"],"inherent_rating":"high","taxonomy":["nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acrypto-counterfeit-certificates","description":"Adversary counterfeits or compromises a certificate authority so that malware or connections appear legitimate, defeating trust in TLS and code-signing and enabling man-in-the-middle or malicious-code delivery.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"low","risk_id":"crypto-counterfeit-certificates","taxonomies":["nist-800-30-threat-event"],"treatment":"mitigate"},"direct":true,"htmlUrl":"/agents/records/risk-crypto-counterfeit-certificates-d9dcc5c5.html","id":"risk:crypto-counterfeit-certificates","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acrypto-counterfeit-certificates","sourceIds":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Compromised or counterfeit certificates / certificate authority","type":"risk","url":"/assets/agent_record-risk-crypto-counterfeit-certificates-d9dcc5c5.8f0926d32cdc4988.json"},{"attributes":{"category":"cyber_security","domain":["Cryptography & Key Management","Data Protection & Privacy","Network & Communications Security"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event","nist-privacy-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Acrypto-weak-or-absent-encryption","description":"Sensitive data stored or transmitted without adequate encryption, or use of weak/flawed cryptography and poor key generation, storage, rotation, and destruction — enabling interception, disclosure, or tampering of data.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"crypto-weak-or-absent-encryption","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event","nist-privacy-risk"],"treatment":"mitigate"},"direct":true,"htmlUrl":"/agents/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.html","id":"risk:crypto-weak-or-absent-encryption","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Acrypto-weak-or-absent-encryption","sourceIds":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Weak or absent encryption and key management","type":"risk","url":"/assets/agent_record-risk-crypto-weak-or-absent-encryption-2fe7d24e.22e603984ef2659e.json"},{"attributes":{"category":"cyber_security","domain":["Network & Communications Security","Cryptography & Key Management","Data Protection & Privacy"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-event","iso-27005-vulnerability"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Anet-interception-mitm","description":"Passive monitoring/sniffing of communications, interception of unencrypted or weakly encrypted channels, wireless interception, and man-in-the-middle attacks capture or corrupt transmitted data — including TEMPEST-type emanation capture.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"net-interception-mitm","taxonomies":["iso-27005-threat","nist-800-30-threat-event","iso-27005-vulnerability"],"treatment":"mitigate"},"direct":true,"htmlUrl":"/agents/records/risk-net-interception-mitm-2a226fa0.html","id":"risk:net-interception-mitm","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Anet-interception-mitm","sourceIds":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"sourceUrl":null,"title":"Communications interception, eavesdropping and man-in-the-middle","type":"risk","url":"/assets/agent_record-risk-net-interception-mitm-2a226fa0.8d3161e822e49154.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0083b823d1479a811e274089f6658e2a1a882805ebf8b83b5a50a508f6260427","properties":{"control_id":"AC-19","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-19-ec21db96.json","targetId":"ctrl:nist-800-53:AC-19","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:07b91331e6ae0e90f3ef05642ee19afab0c15ab53c1e24c15373f3371bbc98c0","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-19-ec21db96.json","sourceId":"ctrl:nist-800-53:AC-19","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0bc8962adfc45ae2158ce4122f8c5cbcc3049a33b6f0e6c3e15b9327a8d48306","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-11-971f92bc.json","sourceId":"ctrl:nist-800-53:SC-11","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0dce2b553d8180d563cc2e7c6531b355e611e4d980a6a281d29355e9bca8080d","properties":{"control_id":"PCI-Req3","coverage":"partial","delta":"key-management requirements (3.6-3.7) satisfied by the key lifecycle control; SAD-not-stored-after-authorization (3.3) and PAN display masking (3.4) also fall outside this control's scope","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req3-e250c900.json","targetId":"ctrl:pci-dss:PCI-Req3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0e3ac8e4c97f738183cf32c50e9ea33938466091c2daf33d793f114dadd35098","properties":{"control_id":"SC-20","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-07-53c6774f.json","sourceId":"uc:UC-NET-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-20-534627dd.json","targetId":"ctrl:nist-800-53:SC-20","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0e4930031c4e98fa0337179a0ed2f2875f81c6d640db01e0ba749bffe03ae534","properties":{"control_id":"SC-23","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","sourceId":"uc:UC-NET-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-23-77326ab3.json","targetId":"ctrl:nist-800-53:SC-23","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1018ea8b37b2517f5f5921dc98b775633945e5129a5b282b467c9fbcdfdd73d0","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-a008-509139e6.json","sourceId":"ctrl:aiuc-1:A008","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:115222064c136d9bc448cfd5f68724d78ed7d13912b19fb3d73b2e81be7b81f8","properties":{"control_id":"SC-13","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-02-9be37a83.json","sourceId":"uc:UC-CRYPTO-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-13-d7da2f08.json","targetId":"ctrl:nist-800-53:SC-13","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:12a9f0c66a8f67e68815d7b85bd3ea19fe7a31b0c571551b1da17d52629ce157","properties":{"control_id":"B010","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-25-21e48906.json","sourceId":"uc:UC-AI-25","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b010-a075f8e3.json","targetId":"ctrl:aiuc-1:B010","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1321e20fc1c352d3bd2591a1b9383bb475570ebb871869fcdf4648690c60aba2","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-10-01b0320e.json","sourceId":"ctrl:nist-800-53:SC-10","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:13f64e9bd86f0bc703948908c3cf78914b528e48bfb571ac0392522a46ce644f","properties":{"rationale":"Requires trusted certificates and rejects insecure fallback, helping reject rogue certs in MITM; the operative approved-CA/revocation defense sits in UC-CRYPTO-03.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/risk-crypto-counterfeit-certificates-d9dcc5c5.json","targetId":"risk:crypto-counterfeit-certificates","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:223afce98b0c8b317705d72570f1bcd6cfc98864226f4103fa45a9ccb2d25d06","properties":{"control_id":"PR.DS-01","coverage":"partial","delta":"availability of data-at-rest (backup/redundancy), addressed by the backup control","framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-ds-01-e42f5cc9.json","targetId":"ctrl:nist-csf-2:PR.DS-01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2323f0b78144197d66c97c4be4f265fa5e5322714f7cd4012f4c02aeb71f69b6","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-8-56ac3e1a.json","sourceId":"ctrl:nist-800-53:SC-8","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:250ff003f4b715eb5d0786b51acc43c0e458ca085b40ac375477d3b7a93a58b4","properties":{"control_id":"SC-21","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-07-53c6774f.json","sourceId":"uc:UC-NET-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-21-720f7e8e.json","targetId":"ctrl:nist-800-53:SC-21","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:252a262b37fb5058b624267ecd2537c260e7b073842b0d39f443ddf24a68864f","properties":{"control_id":"SC-12","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-03-8821a347.json","sourceId":"uc:UC-CRYPTO-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-12-afabf2ca.json","targetId":"ctrl:nist-800-53:SC-12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:29839c3acb7b642fd5676a76d543bf1cca24b8b4255460b9740880acca326548","properties":{"control_id":"SC-45","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-07-53c6774f.json","sourceId":"uc:UC-NET-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-45-927bedb6.json","targetId":"ctrl:nist-800-53:SC-45","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2b27d6601dcf4e126d3164477830bc8bb8111f97b1645d9a804900c159461f6e","properties":{"rationale":"Authenticated, integrity-verified name resolution prevents DNS spoofing/redirection that enables man-in-the-middle.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-07-53c6774f.json","sourceId":"uc:UC-NET-07","targetDetailPath":"/data/v1/records/risk-net-interception-mitm-2a226fa0.json","targetId":"risk:net-interception-mitm","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:307aaa3ff6067b1987301898f2760743c0a955ddcf88d86094502fc3c7fb86d6","properties":{"rationale":"Trusted, mutually authenticated communication paths plus session-integrity protection prevent man-in-the-middle interception and insertion.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","sourceId":"uc:UC-NET-03","targetDetailPath":"/data/v1/records/risk-net-interception-mitm-2a226fa0.json","targetId":"risk:net-interception-mitm","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3d3f990630e2782c8aa78860c8fe6e41b33953c4c3f847c4749757ca140c724b","properties":{"rationale":"Banning early TLS and weak ciphers prevents protocol-downgrade and decryption of captured traffic, hardening the in-transit encryption that blocks interception.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-02-9be37a83.json","sourceId":"uc:UC-CRYPTO-02","targetDetailPath":"/data/v1/records/risk-net-interception-mitm-2a226fa0.json","targetId":"risk:net-interception-mitm","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:40c043135d2d85bf52a9b3bb4f56b6a928475e3c1e451a876bdac97bb1664c22","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-37-370be823.json","sourceId":"ctrl:nist-800-53:SC-37","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4139a32a44de066985ce2c2e8745e38b9e2ab523d4aa5bc7530c282a16da3030","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-312-e-edf6e525.json","sourceId":"ctrl:hipaa:HIPAA-164.312(e)","targetDetailPath":"/data/v1/records/std-hipaa-a825d271.json","targetId":"std:hipaa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4a26f064f6fdca3ab5a9a4b3649202a67d4c520e37219c67a9d8c557b488e46b","properties":{"rationale":"Out-of-band delivery of credentials/keys plus mutually authenticated trusted paths prevent credential capture and spoofing.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","sourceId":"uc:UC-NET-03","targetDetailPath":"/data/v1/records/risk-crypto-cleartext-credential-transfer-b88065a1.json","targetId":"risk:crypto-cleartext-credential-transfer","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4c169a538c7bde531e841ee0427d65f619c2c9819fa90f045a65b1aa684aefec","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-17-4b0ce4dd.json","sourceId":"ctrl:nist-800-53:AC-17","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4e08d3733dbf0df01fcd67f770bddac361278d78363b96313f19dd977fe43c0d","properties":{"control_id":"SC-40","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-40-3d233d47.json","targetId":"ctrl:nist-800-53:SC-40","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4f6e51d66c8d0b2a96b0b134c44e84ebfbb8c8098c96ef577c6324572401336b","properties":{"control_id":"SC-10","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","sourceId":"uc:UC-NET-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-10-01b0320e.json","targetId":"ctrl:nist-800-53:SC-10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4f9cc2273c050ccc6e31960e18dc9c62d82130369aa71bdb6d12c9f12d6623e5","properties":{"control_id":"SC-8","coverage":"partial","delta":"confidentiality of internal-network transmission - the statement scopes transit encryption to open/public/external networks, while SC-8 applies to internal paths as well","framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-8-56ac3e1a.json","targetId":"ctrl:nist-800-53:SC-8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:508d48e43e853b5f261e6cc67e51ce2a82956879a49ddd2a6cdb9d7248b971fe","properties":{"control_id":"SC-11","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","sourceId":"uc:UC-NET-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-11-971f92bc.json","targetId":"ctrl:nist-800-53:SC-11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5709377eedf2fa2192160cc9c682114a97ca1fe24b5998df74b4e550589f7b81","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-22-b1767165.json","sourceId":"ctrl:nist-800-53:SC-22","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5d1f1a0ebca6eba2d224e2dc8357c03b7ae28e3d8419472daabcf58d915afb05","properties":{"rationale":"Prohibiting SHA-1/weak keys and fixing certificate profiles raises the cryptanalytic cost of forging a certificate signature, an enabler of counterfeit certificates.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-02-9be37a83.json","sourceId":"uc:UC-CRYPTO-02","targetDetailPath":"/data/v1/records/risk-crypto-counterfeit-certificates-d9dcc5c5.json","targetId":"risk:crypto-counterfeit-certificates","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5d7ed4cf34f1e7b868f597d323b1b8bd111160279bd908e186ab865856d550f4","properties":{"rationale":"protecting data in use (memory/session encryption, enclaves) extends cryptographic coverage to active data, closing the residual exposure that at-rest/in-transit encryption leaves open","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-04-097c39b7.json","sourceId":"uc:UC-CRYPTO-04","targetDetailPath":"/data/v1/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.json","targetId":"risk:crypto-weak-or-absent-encryption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5ec19aaec5c09f7d361705a7134b3fe28f2badc7b938140e56da0008dd577a5a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-23-77326ab3.json","sourceId":"ctrl:nist-800-53:SC-23","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:64636910b275e35be75bc6717dd97f4eebe76c4402e63289b791d8ecb53084c8","properties":{"rationale":"session/memory protection reduces exposure of data held in active communication sessions","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-04-097c39b7.json","sourceId":"uc:UC-CRYPTO-04","targetDetailPath":"/data/v1/records/risk-net-interception-mitm-2a226fa0.json","targetId":"risk:net-interception-mitm","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:649e529c9a9818779f804d162b20c955e77fa360adabe1b6097b6c3ca4e46a95","properties":{"rationale":"Mandating encryption for remote/wireless/mobile transmission reduces unencrypted-in-transit exposure; storage and key management addressed elsewhere.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.json","targetId":"risk:crypto-weak-or-absent-encryption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6738aa26675e72d82bdcc8fd058f68ce82b545c2ccaf1969c54266eb6f87284f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-24-f5cc6274.json","sourceId":"ctrl:iso-27001:A.8.24","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6b2e1633576aec74797561acd8e2770e4a4b3bf329e76e821b581925d07ae4ea","properties":{"control_id":"HIPAA-164.312(e)","coverage":"full","delta":null,"framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-312-e-edf6e525.json","targetId":"ctrl:hipaa:HIPAA-164.312(e)","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6c407b10ad5d46151c7ff6fecca5f3a9ca0646ad8c5f14b8b5cb13ef0c20f1ba","properties":{"control_id":"AC-18","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-18-e2c1b10c.json","targetId":"ctrl:nist-800-53:AC-18","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6f3f01502f553d7a1f49c50b5c90c0713d99bf34c2b3d26c3c982dcf51c927d5","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-05-f9e22b30.json","sourceId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-05","targetDetailPath":"/data/v1/records/std-nist-ai-tevv-athlon-c008775c.json","targetId":"std:nist-ai-tevv-athlon","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6fb41f2d6d94cc04509d520fa0c0096637073745c031c4d536c9464491acbf60","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nydfs-500-500-15-5ef052ba.json","sourceId":"ctrl:nydfs-500:500.15","targetDetailPath":"/data/v1/records/std-nydfs-500-97d33d25.json","targetId":"std:nydfs-500","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6ff40271e1b5138c73258f4e6041cc60fe2246c2ef4838fcc08ac541b102862b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-21-720f7e8e.json","sourceId":"ctrl:nist-800-53:SC-21","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:72f2f56ed842044eb3de32bf36817661690a614e723a5968076b33ae0a52bed4","properties":{"control_id":"PCI-Req4","coverage":"full","delta":null,"framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req4-e571f282.json","targetId":"ctrl:pci-dss:PCI-Req4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:741c673d16a15884ad61fe5b0caa052bafebadd5eb06fda10e428c43b3c7042b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req3-e250c900.json","sourceId":"ctrl:pci-dss:PCI-Req3","targetDetailPath":"/data/v1/records/std-pci-dss-5d652b0a.json","targetId":"std:pci-dss","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:752fd17b5836191d0a944ca8edb24c2a98e3f970900367018fabf1c5575db95d","properties":{"control_id":"IA-7","coverage":"partial","delta":"operator/role authentication to the cryptographic module itself, which mandating validated modules and approved algorithms does not by itself ensure (e.g., FIPS 140 Level 1 modules impose no operator authentication)","framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-02-9be37a83.json","sourceId":"uc:UC-CRYPTO-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ia-7-7dfc5b71.json","targetId":"ctrl:nist-800-53:IA-7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:76e45cad5fbd3b2ee3c747b6da11a758d142110cb6f173d003e5bffe95146de0","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-40-3d233d47.json","sourceId":"ctrl:nist-800-53:SC-40","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:79bdeeae194462215e7108e8a2a23905c4f758e1e096c1379e4396865b2e1f2f","properties":{"control_id":"NIST-AGI-06","coverage":"guidance","delta":null,"framework":"nist-ai-agent-identity","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Concept paper p. 4: Prompt Injection prevention and mitigation","source_version":"February 2026 draft concept paper"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/ctrl-nist-ai-agent-identity-nist-agi-06-e6b81ea1.json","targetId":"ctrl:nist-ai-agent-identity:NIST-AGI-06","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7c2336bf6fcb3dc53cb4d7d994f37c005305e23ea0b735ddc93b6eb84b62549d","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-ai-agent-identity-nist-agi-06-e6b81ea1.json","sourceId":"ctrl:nist-ai-agent-identity:NIST-AGI-06","targetDetailPath":"/data/v1/records/std-nist-ai-agent-identity-5c357655.json","targetId":"std:nist-ai-agent-identity","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7f84867ba5c5b81b99aad66d6bce3b76b84b2554cf87e3359f2fedb1d44fac7b","properties":{"rationale":"Input screening is where pasted credentials can be caught before they reach the model or its logs.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/risk-ai-secrets-credential-leakage-abf1bf77.json","targetId":"risk:ai-secrets-credential-leakage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8276e3e5266d232aa63fa0040d134624c83cf0a1352d83ca16b366c66aa81d4c","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc2-cc6-7-f815d553.json","sourceId":"ctrl:soc2:CC6.7","targetDetailPath":"/data/v1/records/std-soc2-26a01d3b.json","targetId":"std:soc2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:84b4939370c1ac6f2cf76d4621fcb46c89173633a7b84639cb633431f6170af0","properties":{"control_id":"A008","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-22-129d1e22.json","sourceId":"uc:UC-AI-22","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-a008-509139e6.json","targetId":"ctrl:aiuc-1:A008","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8970c33bddd154c3cef76c7c7d82e5a8d118c74e982d2ab08a338dc51797f3fa","properties":{"rationale":"Renders data at rest unreadable and encrypts data in transit with strong cryptography, directly closing the absent/inadequate-encryption exposure for stored and transmitted data.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.json","targetId":"risk:crypto-weak-or-absent-encryption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:908c341aa078ce102be83a656c1dbff4928a9841491d3385d0d228153e5925dc","properties":{"control_id":"B005","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b005-fe985c7b.json","targetId":"ctrl:aiuc-1:B005","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9410dcb93a1382eb7e0305ce79840b35ad2b921ea2a9c612e48a2c9c861db977","properties":{"rationale":"Issues certificates only from approved CAs, inventories/monitors them, and revokes promptly on compromise, the direct first-order defense against compromised/counterfeit certificates.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-03-8821a347.json","sourceId":"uc:UC-CRYPTO-03","targetDetailPath":"/data/v1/records/risk-crypto-counterfeit-certificates-d9dcc5c5.json","targetId":"risk:crypto-counterfeit-certificates","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9803599fd81586db2acd99ab7acbb8ffb90129619e56d6bc0d1c5e0bb4bbb469","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-e005-8a88c16c.json","sourceId":"ctrl:aiuc-1:E005","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9995e98d5723f34ecb02cc539ca290049e759a06e7a6d330770506cc96231c67","properties":{"rationale":"Encryption, wireless link-level protection, and mutual authentication defeat eavesdropping, wireless interception, and man-in-the-middle on these links.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/risk-net-interception-mitm-2a226fa0.json","targetId":"risk:net-interception-mitm","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9b6dd382e42ada8046ada508d9bb993395a9c4bf58444f616b98e83e47ab07ee","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-ds-02-3ef7fff1.json","sourceId":"ctrl:nist-csf-2:PR.DS-02","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9ef2495e9d51f5cb612c76956abcf730d28d1dd358d8c4550b86b46566054d78","properties":{"control_id":"A.8.24","coverage":"partial","delta":"key management rules satisfied by the key lifecycle control","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-02-9be37a83.json","sourceId":"uc:UC-CRYPTO-02","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-24-f5cc6274.json","targetId":"ctrl:iso-27001:A.8.24","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a397b05f1ef48f04a32884b2d7ea38857e1cdd261143b3ae301684d637fb170f","properties":{"control_id":"SC-28","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-28-740b8f3c.json","targetId":"ctrl:nist-800-53:SC-28","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a3b0a06f9c8d8eb02d152c15cf1dde5e8425eab7f8340834aaacacb6a83ed489","properties":{"control_id":"SC-37","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","sourceId":"uc:UC-NET-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-37-370be823.json","targetId":"ctrl:nist-800-53:SC-37","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a574f3ca2ab48606509eb278aa208428a02a20304b9c0b0f41b0c17b1a4f5c38","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-ds-10-0ec91e33.json","sourceId":"ctrl:nist-csf-2:PR.DS-10","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a96eab50d01760e6480aff0be977377cb9e8b4cff482f78d1f4ae4b1ad6e7220","properties":{"rationale":"Protecting private keys in HSMs and revoking compromised certs denies attackers the stolen-key/impersonation path used for eavesdropping and man-in-the-middle.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-03-8821a347.json","sourceId":"uc:UC-CRYPTO-03","targetDetailPath":"/data/v1/records/risk-net-interception-mitm-2a226fa0.json","targetId":"risk:net-interception-mitm","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a9e0dcc9ad8606060d3ecee93533a2fd7f927c579eb12fbcf5f9cb3843894a9f","properties":{"rationale":"Mandates approved algorithms/key lengths and independently validated modules while banning deprecated primitives (SSL/early TLS, SHA-1, RSA<2048), directly eliminating weak/flawed cryptography and poor key generation.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-02-9be37a83.json","sourceId":"uc:UC-CRYPTO-02","targetDetailPath":"/data/v1/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.json","targetId":"risk:crypto-weak-or-absent-encryption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:aef05ff264d1c00746124128b03a9dbc953f055f07cb074fb999c0823b83c8a1","properties":{"rationale":"Governs key generation, HSM storage, rotation, and destruction under dual control, directly remediating the poor-key-management facet that weakens encryption.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-03-8821a347.json","sourceId":"uc:UC-CRYPTO-03","targetDetailPath":"/data/v1/records/risk-crypto-weak-or-absent-encryption-2fe7d24e.json","targetId":"risk:crypto-weak-or-absent-encryption","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b312a3465956656f933a2d24079ffb3960496f2c22e14a96ad449d31cfe0d456","properties":{"rationale":"Mandates strong encryption of data in transit over all public/external networks and rejects fallback to insecure protocols, directly preventing credentials and sensitive comms from crossing the wire in clear text.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/risk-crypto-cleartext-credential-transfer-b88065a1.json","targetId":"risk:crypto-cleartext-credential-transfer","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b44a833e4a5dc25f02c444192f88be1428ebeb6cc7c4da641ac4387498459868","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-45-927bedb6.json","sourceId":"ctrl:nist-800-53:SC-45","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b6fb2f7672985d2036e3de2f76507ef1bd9c15152269cdc496e9b5a2146402da","properties":{"control_id":"PR.DS-10","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-04-097c39b7.json","sourceId":"uc:UC-CRYPTO-04","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-ds-10-0ec91e33.json","targetId":"ctrl:nist-csf-2:PR.DS-10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b710763db006c50e74e56979f08771abc6a21fb508e06abd61239f155d4f359f","properties":{"control_id":"500.15","coverage":"full","delta":null,"framework":"nydfs-500","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"23 NYCRR 500, Second Amendment"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-nydfs-500-500-15-5ef052ba.json","targetId":"ctrl:nydfs-500:500.15","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ba9c419540dc2d158cc719bfe9772bd7b8d3d482a1b96273f66313593f53492f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-ia-7-7dfc5b71.json","sourceId":"ctrl:nist-800-53:IA-7","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c024fb8b08eea7b33887ad3e6151172489da29702ef891112707a1f4d7008a52","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-ds-01-e42f5cc9.json","sourceId":"ctrl:nist-csf-2:PR.DS-01","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c6b7a150cb296f8a9ed43aae0b1ffa79c70c4d2bc56ea7ad7afe13fc2d1d0bb7","properties":{"control_id":"CC6.7","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-7-f815d553.json","targetId":"ctrl:soc2:CC6.7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cac87c52f8cad781925ff1df93d3ecdcadc88de1e2481e2c5f6ec35ca0f68006","properties":{"control_id":"B004","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b004-d4ff3b14.json","targetId":"ctrl:aiuc-1:B004","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d12810bb743c19ee31493be295824f2014ba01c0b4c01ccb177620aa79dd0909","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-b005-fe985c7b.json","sourceId":"ctrl:aiuc-1:B005","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d88f15573d6e7e64057fe96be5cebce989059e30170983ede39fb2c3dabe10b6","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req4-e571f282.json","sourceId":"ctrl:pci-dss:PCI-Req4","targetDetailPath":"/data/v1/records/std-pci-dss-5d652b0a.json","targetId":"std:pci-dss","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d8b80f08aebb53818d702d4d99d8c67750cac06da57d362f51268c30edd793ac","properties":{"control_id":"NIST-TEVV-05","coverage":"guidance","delta":null,"framework":"nist-ai-tevv-athlon","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"NIST AI 200-2 ipd Appendix B, Table 4, p. 24: Integrity attacks","source_version":"NIST AI 200-2 ipd (Initial Public Draft), August 2026"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/ctrl-nist-ai-tevv-athlon-nist-tevv-05-f9e22b30.json","targetId":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-05","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dacb14bcd5fcf3e19fd06ff4c931b9abb801f1b0971f99063c8e4076aedab5b8","properties":{"control_id":"AC-17","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-17-4b0ce4dd.json","targetId":"ctrl:nist-800-53:AC-17","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dfe4a2f352199a3a665ddddedaf3a66dee1ff1c8687930b9b84f4439e5433a9a","properties":{"control_id":"B002","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b002-07a4b0e1.json","targetId":"ctrl:aiuc-1:B002","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e0f381630542302cf8acba984eb66a245a46ea45dca2726c9b73a4a6bda93719","properties":{"control_id":"PR.DS-02","coverage":"partial","delta":"availability of data-in-transit (resilient/redundant communication paths) and confidentiality of transmission over internal network paths not addressed","framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-ds-02-3ef7fff1.json","targetId":"ctrl:nist-csf-2:PR.DS-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e1fd971026922ddace3aa51f4006f62f79c11dc6afcf61ad292413fabe1565cb","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-17-b6802187.json","sourceId":"ctrl:nist-800-53:SC-17","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e317a50a1f93d9c972822f8bf753183654e8add73e9e71d070892ad169295c57","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-b002-07a4b0e1.json","sourceId":"ctrl:aiuc-1:B002","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e4632b900396dc6c7410ef9ed56bae45ef8e045dfe089098dd265a1e59338d80","properties":{"rationale":"Strong in-transit encryption defeats passive sniffing/eavesdropping while trusted certificates and no-insecure-fallback block man-in-the-middle on public networks.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/risk-net-interception-mitm-2a226fa0.json","targetId":"risk:net-interception-mitm","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e53f015e4cd23962d910e9aa61ce036baf1816a5d60713f90ba1c0e6f46d0213","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-13-d7da2f08.json","sourceId":"ctrl:nist-800-53:SC-13","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb180c76ac7e710e13f9e48814b17340ae292935a08931f64bee369172698524","properties":{"rationale":"Mandatory mutual authentication and encryption on remote/wireless links prevent credential interception and spoofing on those channels.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/risk-crypto-cleartext-credential-transfer-b88065a1.json","targetId":"risk:crypto-cleartext-credential-transfer","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb8ae9550dcdacfecbd0859c5e133b80925bd0724b8cfc9d5c03f7b8194b1bd5","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-b004-d4ff3b14.json","sourceId":"ctrl:aiuc-1:B004","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eccbdcc81993c8b5ae459ce9f2708dcd87427938e06b7458db9233d5fed885bf","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-12-afabf2ca.json","sourceId":"ctrl:nist-800-53:SC-12","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ee8d104c30d16cb2403585b02eef0c22a20992e02e66261b199d70f0c9ab2e48","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-18-e2c1b10c.json","sourceId":"ctrl:nist-800-53:AC-18","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ee90ea861f614b760a4d3c4f804e0ced72db294e8ac76ed436315e7c2b6fb4e3","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-28-740b8f3c.json","sourceId":"ctrl:nist-800-53:SC-28","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f1e3e08c4446358aafd6478b4dd2c7110539a545420b61b03e047edd796b90da","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-20-534627dd.json","sourceId":"ctrl:nist-800-53:SC-20","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f612cb7fa3626c23b14987a9f2c48cde12aeec66b78ff44a1a237710e62d4a28","properties":{"control_id":"E005","coverage":"partial","delta":"a documented storage-security description for AI data stores (training data, prompts, outputs, embeddings) shared with customers","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-01-55215c11.json","sourceId":"uc:UC-CRYPTO-01","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-e005-8a88c16c.json","targetId":"ctrl:aiuc-1:E005","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f6728b5a66c4a5e07bdbb22f6529aa5a679042c9930a2638026587b52c4b8ae9","properties":{"rationale":"Guidance to reference secret managers rather than hardcode credentials keeps secrets out of generated code.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-25-21e48906.json","sourceId":"uc:UC-AI-25","targetDetailPath":"/data/v1/records/risk-ai-secrets-credential-leakage-abf1bf77.json","targetId":"risk:ai-secrets-credential-leakage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f8a2556afe5a96f4cc08e342a67e68e9c357271d761707ea878ddf981cc88075","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-b010-a075f8e3.json","sourceId":"ctrl:aiuc-1:B010","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fc4803dec8c99f3805b00e1b4babbf2e8a9ceb9b53d7a23ddee9a4765d47ad09","properties":{"rationale":"Detecting, redacting, and safely storing credentials across prompts, outputs, logs, and generated code is the direct control for secret leakage.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-22-129d1e22.json","sourceId":"uc:UC-AI-22","targetDetailPath":"/data/v1/records/risk-ai-secrets-credential-leakage-abf1bf77.json","targetId":"risk:ai-secrets-credential-leakage","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fcea20f9ffd805a6a2990a9bb69dbd963e4609bfa735af8c4578351236b0278b","properties":{"control_id":"SC-17","coverage":"partial","delta":"restricting managed trust stores to organization-approved trust anchors only","framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-crypto-03-8821a347.json","sourceId":"uc:UC-CRYPTO-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-17-b6802187.json","targetId":"ctrl:nist-800-53:SC-17","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fd3514f74edfa41986374541285bf70869f4e608934ec75940a035723268b69e","properties":{"control_id":"SC-22","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-net-07-53c6774f.json","sourceId":"uc:UC-NET-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-sc-22-b1767165.json","targetId":"ctrl:nist-800-53:SC-22","type":"maps_to"}],"schemaVersion":1,"scope":"topics","total":83}
