{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["ctrl:aiuc-1:A003","ctrl:aiuc-1:B007","ctrl:aiuc-1:C001","ctrl:cobit-2019:APO01","ctrl:cobit-2019:APO06","ctrl:cobit-2019:APO14","ctrl:cobit-2019:DSS06","ctrl:cobit-2019:EDM01","ctrl:cobit-2019:EDM04","ctrl:cobit-2019:MEA02","ctrl:coso-erm:E1","ctrl:coso-erm:E14","ctrl:coso-erm:E3","ctrl:coso-erm:E4","ctrl:coso-ic:P1","ctrl:coso-ic:P10","ctrl:coso-ic:P11","ctrl:coso-ic:P16","ctrl:coso-ic:P2","ctrl:coso-ic:P5","ctrl:coso-ic:P8","ctrl:eu-ai-act:AIA-Art27","ctrl:eu-ai-act:AIA-Art6-7","ctrl:gdpr:GDPR-Art32","ctrl:hipaa:HIPAA-164.312(a)","ctrl:iia-2024:Principle 1","ctrl:iia-2024:Principle 10","ctrl:iia-2024:Principle 14","ctrl:iia-2024:Principle 15","ctrl:iia-2024:Principle 3","ctrl:iia-2024:Principle 4","ctrl:iia-2024:Principle 6","ctrl:iia-2024:Principle 9","ctrl:iia-2024:Std 1.1","ctrl:iia-2024:Std 1.2","ctrl:iia-2024:Std 1.3","ctrl:iia-2024:Std 10.1","ctrl:iia-2024:Std 10.2","ctrl:iia-2024:Std 10.3","ctrl:iia-2024:Std 11.3"],"directIds":[],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"Financial Reporting Controls (SOX)","next":"/assets/agent_topics-financial-reporting-controls-sox-2.ddb72efbe54cbe40.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Limit AI agent data access","details":{"automation":"automated","control_category":"technical","control_id":"A003","control_type":"preventive","domains":["AI Governance","Data Protection & Privacy"],"framework":"aiuc-1","group":"Data & Privacy","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":7,"source_pages":null,"source_url":"https://www.aiuc-1.com/data-and-privacy/implement-contextual-data-safeguards"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-a003-bea61fd9.html","id":"ctrl:aiuc-1:A003","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AA003","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/data-and-privacy/implement-contextual-data-safeguards","title":"A003 — Limit AI agent data access","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-a003-bea61fd9.af585433fb30a112.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Enforce user access privileges to AI systems","details":{"automation":"hybrid","control_category":"technical","control_id":"B007","control_type":"preventive","domains":["AI Governance","Access Control & Identity Management","Secure Development (SDLC) & Application Security"],"framework":"aiuc-1","group":"Security","key_control":true,"requirement_frequency":"Every 3 months","requirement_status":"mandatory","risk_count":4,"source_pages":null,"source_url":"https://www.aiuc-1.com/security/enforce-ai-access-privileges"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-b007-151dfcd3.html","id":"ctrl:aiuc-1:B007","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AB007","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/security/enforce-ai-access-privileges","title":"B007 — Enforce user access privileges to AI systems","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-b007-151dfcd3.a8fe995563ac9d9f.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Define AI risk taxonomy","details":{"automation":"manual","control_category":"administrative","control_id":"C001","control_type":"preventive","domains":["AI Governance"],"framework":"aiuc-1","group":"Safety","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":8,"source_pages":null,"source_url":"https://www.aiuc-1.com/safety/define-ai-risk-taxonomy"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-c001-6bc6c173.html","id":"ctrl:aiuc-1:C001","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AC001","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/safety/define-ai-risk-taxonomy","title":"C001 — Define AI risk taxonomy","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-c001-6bc6c173.a628dce352165649.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed I&T Management Framework","details":{"automation":"manual","control_category":"administrative","control_id":"APO01","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Human Resources / Personnel Security","Third-Party / Supply-Chain Risk","Asset Management & Inventory"],"framework":"cobit-2019","group":"Align, Plan and Organize","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-apo01-d6a49088.html","id":"ctrl:cobit-2019:APO01","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3AAPO01","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"APO01 — Managed I&T Management Framework","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-apo01-d6a49088.17277180b62a01b0.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Budget and Costs","details":{"automation":"manual","control_category":"administrative","control_id":"APO06","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Human Resources / Personnel Security","Third-Party / Supply-Chain Risk","Asset Management & Inventory"],"framework":"cobit-2019","group":"Align, Plan and Organize","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-apo06-2191e824.html","id":"ctrl:cobit-2019:APO06","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3AAPO06","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"APO06 — Managed Budget and Costs","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-apo06-2191e824.2240d33dbfc81ca4.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Data","details":{"automation":"manual","control_category":"administrative","control_id":"APO14","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Human Resources / Personnel Security","Third-Party / Supply-Chain Risk","Asset Management & Inventory"],"framework":"cobit-2019","group":"Align, Plan and Organize","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-apo14-ab650d02.html","id":"ctrl:cobit-2019:APO14","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3AAPO14","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"APO14 — Managed Data","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-apo14-ab650d02.5061680c52a84d2d.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Business Process Controls","details":{"automation":"hybrid","control_category":"administrative","control_id":"DSS06","control_type":"preventive","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"cobit-2019","group":"Deliver, Service and Support","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":7,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-dss06-c2b31b0e.html","id":"ctrl:cobit-2019:DSS06","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ADSS06","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"DSS06 — Managed Business Process Controls","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-dss06-c2b31b0e.9c635c0a07e1e016.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Ensured Governance Framework Setting and Maintenance","details":{"automation":"manual","control_category":"administrative","control_id":"EDM01","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Compliance, Audit & Assurance"],"framework":"cobit-2019","group":"Evaluate, Direct and Monitor","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-edm01-95fe0a96.html","id":"ctrl:cobit-2019:EDM01","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3AEDM01","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"EDM01 — Ensured Governance Framework Setting and Maintenance","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-edm01-95fe0a96.1091b5e14cca5487.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Ensured Resource Optimization","details":{"automation":"manual","control_category":"administrative","control_id":"EDM04","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Compliance, Audit & Assurance"],"framework":"cobit-2019","group":"Evaluate, Direct and Monitor","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-edm04-7ad4bdc3.html","id":"ctrl:cobit-2019:EDM04","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3AEDM04","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"EDM04 — Ensured Resource Optimization","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-edm04-7ad4bdc3.6bea80073d5fdf60.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed System of Internal Control","details":{"automation":"manual","control_category":"administrative","control_id":"MEA02","control_type":"detective","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"cobit-2019","group":"Monitor, Evaluate and Assess","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-mea02-4513eb15.html","id":"ctrl:cobit-2019:MEA02","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3AMEA02","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"MEA02 — Managed System of Internal Control","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-mea02-4513eb15.4f6f1aa7f3ac463d.json"},{"attributes":{"category":"administrative","framework":"coso-erm","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-erm/","description":"Exercises Board Risk Oversight","details":{"automation":"manual","control_category":"administrative","control_id":"E1","control_type":"preventive","domains":["Governance, Policy & Oversight","Human Resources / Personnel Security","Risk Assessment & Management"],"framework":"coso-erm","group":"Governance & Culture","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-erm-e1-2389ffca.html","id":"ctrl:coso-erm:E1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-erm%3AE1","sourceIds":["coso-erm"],"sourceUrl":null,"title":"E1 — Exercises Board Risk Oversight","type":"control","url":"/assets/agent_record-ctrl-coso-erm-e1-2389ffca.006883516b25c72c.json"},{"attributes":{"category":"administrative","framework":"coso-erm","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-erm/","description":"Develops Portfolio View","details":{"automation":"manual","control_category":"administrative","control_id":"E14","control_type":"preventive","domains":["Risk Assessment & Management"],"framework":"coso-erm","group":"Performance","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-erm-e14-68b8e783.html","id":"ctrl:coso-erm:E14","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-erm%3AE14","sourceIds":["coso-erm"],"sourceUrl":null,"title":"E14 — Develops Portfolio View","type":"control","url":"/assets/agent_record-ctrl-coso-erm-e14-68b8e783.e84cfe480e180976.json"},{"attributes":{"category":"administrative","framework":"coso-erm","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-erm/","description":"Defines Desired Culture","details":{"automation":"manual","control_category":"administrative","control_id":"E3","control_type":"preventive","domains":["Governance, Policy & Oversight","Human Resources / Personnel Security","Risk Assessment & Management"],"framework":"coso-erm","group":"Governance & Culture","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-erm-e3-2d76e2c2.html","id":"ctrl:coso-erm:E3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-erm%3AE3","sourceIds":["coso-erm"],"sourceUrl":null,"title":"E3 — Defines Desired Culture","type":"control","url":"/assets/agent_record-ctrl-coso-erm-e3-2d76e2c2.40fac780258fe732.json"},{"attributes":{"category":"administrative","framework":"coso-erm","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-erm/","description":"Demonstrates Commitment to Core Values","details":{"automation":"manual","control_category":"administrative","control_id":"E4","control_type":"preventive","domains":["Governance, Policy & Oversight","Human Resources / Personnel Security","Risk Assessment & Management"],"framework":"coso-erm","group":"Governance & Culture","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-erm-e4-97e5f081.html","id":"ctrl:coso-erm:E4","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-erm%3AE4","sourceIds":["coso-erm"],"sourceUrl":null,"title":"E4 — Demonstrates Commitment to Core Values","type":"control","url":"/assets/agent_record-ctrl-coso-erm-e4-97e5f081.d480e74ba4c06612.json"},{"attributes":{"category":"administrative","framework":"coso-ic","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-ic/","description":"The organization demonstrates a commitment to integrity and ethical values.","details":{"automation":"manual","control_category":"administrative","control_id":"P1","control_type":"preventive","domains":["Financial Reporting Controls (SOX)","Governance, Policy & Oversight"],"framework":"coso-ic","group":"Control Environment","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-ic-p1-f41d97ed.html","id":"ctrl:coso-ic:P1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-ic%3AP1","sourceIds":["coso-ic"],"sourceUrl":null,"title":"P1 — The organization demonstrates a commitment to integrity and ethical values.","type":"control","url":"/assets/agent_record-ctrl-coso-ic-p1-f41d97ed.bf7947e24cb1aa8f.json"},{"attributes":{"category":"administrative","framework":"coso-ic","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-ic/","description":"The organization selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.","details":{"automation":"manual","control_category":"administrative","control_id":"P10","control_type":"preventive","domains":["Access Control & Identity Management","Financial Reporting Controls (SOX)"],"framework":"coso-ic","group":"Control Activities","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-ic-p10-c5a97f20.html","id":"ctrl:coso-ic:P10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-ic%3AP10","sourceIds":["coso-ic"],"sourceUrl":null,"title":"P10 — The organization selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.","type":"control","url":"/assets/agent_record-ctrl-coso-ic-p10-c5a97f20.8685a7df744a787f.json"},{"attributes":{"category":"administrative","framework":"coso-ic","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-ic/","description":"The organization selects and develops general control activities over technology to support the achievement of objectives.","details":{"automation":"manual","control_category":"administrative","control_id":"P11","control_type":"preventive","domains":["Access Control & Identity Management","Business Continuity & Disaster Recovery","Cryptography & Key Management","Data Protection & Privacy","Financial Reporting Controls (SOX)","Network & Communications Security","Physical & Environmental Security","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security"],"framework":"coso-ic","group":"Control Activities","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-ic-p11-2a08883b.html","id":"ctrl:coso-ic:P11","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-ic%3AP11","sourceIds":["coso-ic"],"sourceUrl":null,"title":"P11 — The organization selects and develops general control activities over technology to support the achievement of objectives.","type":"control","url":"/assets/agent_record-ctrl-coso-ic-p11-2a08883b.f7b1fd369c20e6b6.json"},{"attributes":{"category":"administrative","framework":"coso-ic","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-ic/","description":"The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.","details":{"automation":"manual","control_category":"administrative","control_id":"P16","control_type":"detective","domains":["Business Continuity & Disaster Recovery","Compliance, Audit & Assurance","Financial Reporting Controls (SOX)","Incident Management & Response","Logging, Monitoring & Detection","Vulnerability & Patch Management"],"framework":"coso-ic","group":"Monitoring Activities","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-ic-p16-4995bb68.html","id":"ctrl:coso-ic:P16","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-ic%3AP16","sourceIds":["coso-ic"],"sourceUrl":null,"title":"P16 — The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.","type":"control","url":"/assets/agent_record-ctrl-coso-ic-p16-4995bb68.bc0f3cf9b5d642eb.json"},{"attributes":{"category":"administrative","framework":"coso-ic","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-ic/","description":"The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.","details":{"automation":"manual","control_category":"administrative","control_id":"P2","control_type":"preventive","domains":["Financial Reporting Controls (SOX)","Governance, Policy & Oversight"],"framework":"coso-ic","group":"Control Environment","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-ic-p2-4f80775c.html","id":"ctrl:coso-ic:P2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-ic%3AP2","sourceIds":["coso-ic"],"sourceUrl":null,"title":"P2 — The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.","type":"control","url":"/assets/agent_record-ctrl-coso-ic-p2-4f80775c.4961dddfac783f79.json"},{"attributes":{"category":"administrative","framework":"coso-ic","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-ic/","description":"The organization holds individuals accountable for their internal control responsibilities in the pursuit of objectives.","details":{"automation":"manual","control_category":"administrative","control_id":"P5","control_type":"preventive","domains":["Governance, Policy & Oversight","Human Resources / Personnel Security"],"framework":"coso-ic","group":"Control Environment","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-ic-p5-7f62f522.html","id":"ctrl:coso-ic:P5","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-ic%3AP5","sourceIds":["coso-ic"],"sourceUrl":null,"title":"P5 — The organization holds individuals accountable for their internal control responsibilities in the pursuit of objectives.","type":"control","url":"/assets/agent_record-ctrl-coso-ic-p5-7f62f522.36791ace8dd5f10f.json"},{"attributes":{"category":"administrative","framework":"coso-ic","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-ic/","description":"The organization considers the potential for fraud in assessing risks to the achievement of objectives.","details":{"automation":"manual","control_category":"administrative","control_id":"P8","control_type":"preventive","domains":["Risk Assessment & Management"],"framework":"coso-ic","group":"Risk Assessment","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-ic-p8-e85b1bf7.html","id":"ctrl:coso-ic:P8","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-ic%3AP8","sourceIds":["coso-ic"],"sourceUrl":null,"title":"P8 — The organization considers the potential for fraud in assessing risks to the achievement of objectives.","type":"control","url":"/assets/agent_record-ctrl-coso-ic-p8-e85b1bf7.e1d64e50d05e463c.json"},{"attributes":{"category":"administrative","framework":"eu-ai-act","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/eu-ai-act/","description":"Fundamental rights impact assessment for high-risk AI systems (deployers)","details":{"automation":"manual","control_category":"administrative","control_id":"AIA-Art27","control_type":"preventive","domains":["AI Governance","Risk Assessment & Management","Governance, Policy & Oversight"],"framework":"eu-ai-act","group":"EU AI Act","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-eu-ai-act-aia-art27-7b550500.html","id":"ctrl:eu-ai-act:AIA-Art27","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aeu-ai-act%3AAIA-Art27","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"AIA-Art27 — Fundamental rights impact assessment for high-risk AI systems (deployers)","type":"control","url":"/assets/agent_record-ctrl-eu-ai-act-aia-art27-7b550500.c84e32a15d604ed9.json"},{"attributes":{"category":"administrative","framework":"eu-ai-act","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/eu-ai-act/","description":"Risk-based classification of high-risk AI systems","details":{"automation":"manual","control_category":"administrative","control_id":"AIA-Art6-7","control_type":"preventive","domains":["AI Governance","Risk Assessment & Management","Governance, Policy & Oversight"],"framework":"eu-ai-act","group":"EU AI Act","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-eu-ai-act-aia-art6-7-cd7435c0.html","id":"ctrl:eu-ai-act:AIA-Art6-7","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aeu-ai-act%3AAIA-Art6-7","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"AIA-Art6-7 — Risk-based classification of high-risk AI systems","type":"control","url":"/assets/agent_record-ctrl-eu-ai-act-aia-art6-7-cd7435c0.b842560dde490b21.json"},{"attributes":{"category":"technical","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Security of processing","details":{"automation":"hybrid","control_category":"technical","control_id":"GDPR-Art32","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art32-63aa3290.html","id":"ctrl:gdpr:GDPR-Art32","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art32","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art32 — Security of processing","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art32-63aa3290.135b09987bf85085.json"},{"attributes":{"category":"technical","framework":"hipaa","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/hipaa/","description":"Technical access control for ePHI (unique user ID, emergency access, automatic logoff, encryption/decryption)","details":{"automation":"hybrid","control_category":"technical","control_id":"HIPAA-164.312(a)","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Data Protection & Privacy"],"framework":"hipaa","group":"HIPAA Security Rule","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-hipaa-hipaa-164-312-a-5c8bb707.html","id":"ctrl:hipaa:HIPAA-164.312(a)","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Ahipaa%3AHIPAA-164.312%28a%29","sourceIds":["hipaa"],"sourceUrl":null,"title":"HIPAA-164.312(a) — Technical access control for ePHI (unique user ID, emergency access, automatic logoff, encryption/decryption)","type":"control","url":"/assets/agent_record-ctrl-hipaa-hipaa-164-312-a-5c8bb707.b17a8cd3c637ac4b.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Demonstrate Integrity","details":{"automation":"manual","control_category":"administrative","control_id":"Principle 1","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"iia-2024","group":"Domain II — Ethics and Professionalism","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-principle-1-97822cbc.html","id":"ctrl:iia-2024:Principle 1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3APrinciple+1","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Principle 1 — Demonstrate Integrity","type":"control","url":"/assets/agent_record-ctrl-iia-2024-principle-1-97822cbc.a39b0275f896524f.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Manage Resources","details":{"automation":"manual","control_category":"administrative","control_id":"Principle 10","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"iia-2024","group":"Domain IV — Managing the Internal Audit Function","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-principle-10-fc5ee25f.html","id":"ctrl:iia-2024:Principle 10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3APrinciple+10","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Principle 10 — Manage Resources","type":"control","url":"/assets/agent_record-ctrl-iia-2024-principle-10-fc5ee25f.0ef5adea37e7b102.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Conduct Engagement Work","details":{"automation":"manual","control_category":"administrative","control_id":"Principle 14","control_type":"detective","domains":["Compliance, Audit & Assurance","Risk Assessment & Management"],"framework":"iia-2024","group":"Domain V — Performing Internal Audit Services","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-principle-14-fd4f55ab.html","id":"ctrl:iia-2024:Principle 14","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3APrinciple+14","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Principle 14 — Conduct Engagement Work","type":"control","url":"/assets/agent_record-ctrl-iia-2024-principle-14-fd4f55ab.9b7bbdde718033b0.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Communicate Engagement Results and Monitor Action Plans","details":{"automation":"manual","control_category":"administrative","control_id":"Principle 15","control_type":"detective","domains":["Compliance, Audit & Assurance","Risk Assessment & Management"],"framework":"iia-2024","group":"Domain V — Performing Internal Audit Services","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-principle-15-b57f77c8.html","id":"ctrl:iia-2024:Principle 15","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3APrinciple+15","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Principle 15 — Communicate Engagement Results and Monitor Action Plans","type":"control","url":"/assets/agent_record-ctrl-iia-2024-principle-15-b57f77c8.28ebb6a9a422a8f7.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Demonstrate Competency","details":{"automation":"manual","control_category":"administrative","control_id":"Principle 3","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"iia-2024","group":"Domain II — Ethics and Professionalism","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-principle-3-a2a0c733.html","id":"ctrl:iia-2024:Principle 3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3APrinciple+3","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Principle 3 — Demonstrate Competency","type":"control","url":"/assets/agent_record-ctrl-iia-2024-principle-3-a2a0c733.6ddd3cd4e847e720.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Exercise Due Professional Care","details":{"automation":"manual","control_category":"administrative","control_id":"Principle 4","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"iia-2024","group":"Domain II — Ethics and Professionalism","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-principle-4-e921b675.html","id":"ctrl:iia-2024:Principle 4","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3APrinciple+4","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Principle 4 — Exercise Due Professional Care","type":"control","url":"/assets/agent_record-ctrl-iia-2024-principle-4-e921b675.25c5831c4856b5e5.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Authorized by the Board","details":{"automation":"manual","control_category":"administrative","control_id":"Principle 6","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"iia-2024","group":"Domain III — Governing the Internal Audit Function","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-principle-6-dc3030fa.html","id":"ctrl:iia-2024:Principle 6","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3APrinciple+6","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Principle 6 — Authorized by the Board","type":"control","url":"/assets/agent_record-ctrl-iia-2024-principle-6-dc3030fa.3264aacb93143184.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Plan Strategically","details":{"automation":"manual","control_category":"administrative","control_id":"Principle 9","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"iia-2024","group":"Domain IV — Managing the Internal Audit Function","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-principle-9-068ca212.html","id":"ctrl:iia-2024:Principle 9","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3APrinciple+9","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Principle 9 — Plan Strategically","type":"control","url":"/assets/agent_record-ctrl-iia-2024-principle-9-068ca212.41a53be4ffde1d33.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Honesty and Professional Courage","details":{"automation":"manual","control_category":"administrative","control_id":"Std 1.1","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"iia-2024","group":"Domain II — Ethics and Professionalism","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-std-1-1-e8b262ce.html","id":"ctrl:iia-2024:Std 1.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3AStd+1.1","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Std 1.1 — Honesty and Professional Courage","type":"control","url":"/assets/agent_record-ctrl-iia-2024-std-1-1-e8b262ce.a1ae1a08c7125ef8.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Organization's Ethical Expectations","details":{"automation":"manual","control_category":"administrative","control_id":"Std 1.2","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"iia-2024","group":"Domain II — Ethics and Professionalism","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-std-1-2-da892b84.html","id":"ctrl:iia-2024:Std 1.2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3AStd+1.2","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Std 1.2 — Organization's Ethical Expectations","type":"control","url":"/assets/agent_record-ctrl-iia-2024-std-1-2-da892b84.37954ef6c48d4516.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Legal and Ethical Behavior","details":{"automation":"manual","control_category":"administrative","control_id":"Std 1.3","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"iia-2024","group":"Domain II — Ethics and Professionalism","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-std-1-3-d38479a0.html","id":"ctrl:iia-2024:Std 1.3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3AStd+1.3","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Std 1.3 — Legal and Ethical Behavior","type":"control","url":"/assets/agent_record-ctrl-iia-2024-std-1-3-d38479a0.643dab09874478e5.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Financial Resource Management","details":{"automation":"manual","control_category":"administrative","control_id":"Std 10.1","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"iia-2024","group":"Domain IV — Managing the Internal Audit Function","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-std-10-1-a5b61f0d.html","id":"ctrl:iia-2024:Std 10.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3AStd+10.1","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Std 10.1 — Financial Resource Management","type":"control","url":"/assets/agent_record-ctrl-iia-2024-std-10-1-a5b61f0d.212f891defd4cdaf.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Human Resources Management","details":{"automation":"manual","control_category":"administrative","control_id":"Std 10.2","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"iia-2024","group":"Domain IV — Managing the Internal Audit Function","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-std-10-2-4da20260.html","id":"ctrl:iia-2024:Std 10.2","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3AStd+10.2","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Std 10.2 — Human Resources Management","type":"control","url":"/assets/agent_record-ctrl-iia-2024-std-10-2-4da20260.787708856ce3d820.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Technological Resources","details":{"automation":"manual","control_category":"administrative","control_id":"Std 10.3","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"iia-2024","group":"Domain IV — Managing the Internal Audit Function","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-std-10-3-0c2d9d4e.html","id":"ctrl:iia-2024:Std 10.3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3AStd+10.3","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Std 10.3 — Technological Resources","type":"control","url":"/assets/agent_record-ctrl-iia-2024-std-10-3-0c2d9d4e.0fd150d613777951.json"},{"attributes":{"category":"administrative","framework":"iia-2024","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iia-2024/","description":"Communicating Results","details":{"automation":"manual","control_category":"administrative","control_id":"Std 11.3","control_type":"preventive","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"iia-2024","group":"Domain IV — Managing the Internal Audit Function","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iia-2024-std-11-3-dbfc7dce.html","id":"ctrl:iia-2024:Std 11.3","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiia-2024%3AStd+11.3","sourceIds":["iia-2024"],"sourceUrl":null,"title":"Std 11.3 — Communicating Results","type":"control","url":"/assets/agent_record-ctrl-iia-2024-std-11-3-dbfc7dce.16b8b3f9c0db8437.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0143972f536ed73420cfad9018dabcad73590f295f5a8a7d609d0277e9c474bf","properties":{"control_id":"B007","coverage":"partial","delta":"quarterly review of user access privileges to AI systems, including administrative, configuration, and training-data access","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-05-9b7f3e34.json","sourceId":"uc:UC-ACCESS-05","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b007-151dfcd3.json","targetId":"ctrl:aiuc-1:B007","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:08901f92f139567733352fa9c46f6b8381406d516a043727a779bb251a871be5","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-ic-p5-7f62f522.json","sourceId":"ctrl:coso-ic:P5","targetDetailPath":"/data/v1/records/std-coso-ic-3f80f565.json","targetId":"std:coso-ic","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:09b009e3bb4f13bcbe1f793932891f64ce77bb75af518f7875349255a838ae41","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-principle-10-fc5ee25f.json","sourceId":"ctrl:iia-2024:Principle 10","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0b5c040cb1331091458dc9021e9eed5222d84d5a30ad45691eb9818e70b5ff55","properties":{"control_id":"Std 10.2","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-10-fc9abe7f.json","sourceId":"uc:UC-AUDIT-10","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-10-2-4da20260.json","targetId":"ctrl:iia-2024:Std 10.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0d46be746c1f09cd9aa592f74a9c5676560a0be62dce9471bf6ca38af741e84e","properties":{"control_id":"Std 1.2","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-04-c880e18f.json","sourceId":"uc:UC-AUDIT-04","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-1-2-da892b84.json","targetId":"ctrl:iia-2024:Std 1.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:136507dff54ef0af3b27852a8536c3f3de34c304c0f271557c3d0a9835e36313","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-principle-1-97822cbc.json","sourceId":"ctrl:iia-2024:Principle 1","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:160197ef08f9452b849b32bbca9891899e287a820c310d1d8fead407896dae68","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-mea02-4513eb15.json","sourceId":"ctrl:cobit-2019:MEA02","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:196ceefc0745c6ddc8a3f0db75c1ea4386ea6dd54352a7744060fe898f7b82cc","properties":{"control_id":"GDPR-Art32","coverage":"partial","delta":"also requires encryption, resilience, and effectiveness testing addressed in other domains","framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-access-05-9b7f3e34.json","sourceId":"uc:UC-ACCESS-05","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art32-63aa3290.json","targetId":"ctrl:gdpr:GDPR-Art32","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:199e523235255b49f7b7f37170eadd985d243e5d71a80080efd22243a1989120","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art32-63aa3290.json","sourceId":"ctrl:gdpr:GDPR-Art32","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1cbe84b3d02248a688536c82e7822f036836bb524da8e6cbd17b9c0c80bf40af","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-c001-6bc6c173.json","sourceId":"ctrl:aiuc-1:C001","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:20a8da436eef1b4a0fbbbe4d5b5bd38b34fd731b712d63eb54a70e05277bf953","properties":{"control_id":"MEA02","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-21-6406caa4.json","sourceId":"uc:UC-AUDIT-21","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-mea02-4513eb15.json","targetId":"ctrl:cobit-2019:MEA02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:22743411c609fa2727ce920b35a7ec482323a75c49df8a4e062e554cc2f1d1c9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-principle-15-b57f77c8.json","sourceId":"ctrl:iia-2024:Principle 15","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:28c41d74ce54894c8ad970e817e0c4086c4a329a9082e423ca06dfbd359c6f8b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-std-10-1-a5b61f0d.json","sourceId":"ctrl:iia-2024:Std 10.1","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2b5d7dd7103d37c5bdcd9de34e005051b766a7dad31760bed8fbcf19854795ae","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-std-10-2-4da20260.json","sourceId":"ctrl:iia-2024:Std 10.2","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2c09c6aa382cf10f688a037000963947c1f9b7d147e88c98e51e6092f8d40391","properties":{"control_id":"APO01","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-01-e1e2136d.json","sourceId":"uc:UC-GOV-01","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-apo01-d6a49088.json","targetId":"ctrl:cobit-2019:APO01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2d8557480c52ad380a7c58fe80f500f44daf5311d37b2a0eab646aa8adfa0974","properties":{"control_id":"P16","coverage":"full","delta":null,"framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-21-6406caa4.json","sourceId":"uc:UC-AUDIT-21","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p16-4995bb68.json","targetId":"ctrl:coso-ic:P16","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2f398e5ab32b0939305cf5ee430512a6c80434c63b71bdde4af99fd0c940b146","properties":{"control_id":"Std 10.3","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-10-fc9abe7f.json","sourceId":"uc:UC-AUDIT-10","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-10-3-0c2d9d4e.json","targetId":"ctrl:iia-2024:Std 10.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:301e35f4f0c71b54ab2bebf37b762c44e4373f1ce97bfd2ec5cbfe0bb8cda212","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-erm-e4-97e5f081.json","sourceId":"ctrl:coso-erm:E4","targetDetailPath":"/data/v1/records/std-coso-erm-7265cc54.json","targetId":"std:coso-erm","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:32bf6421f2b8d665a50dabd9afe913d3db465ae6fd73f6978e767f8a3e387d37","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-312-a-5c8bb707.json","sourceId":"ctrl:hipaa:HIPAA-164.312(a)","targetDetailPath":"/data/v1/records/std-hipaa-a825d271.json","targetId":"std:hipaa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:35469ce4cb671182840373ba75e324ed800a0a4e4d47d09d3d1e037f6d10f617","properties":{"control_id":"E1","coverage":"full","delta":null,"framework":"coso-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","sourceId":"uc:UC-GOV-05","targetDetailPath":"/data/v1/records/ctrl-coso-erm-e1-2389ffca.json","targetId":"ctrl:coso-erm:E1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:36f91bc8683791aea147f40d7dd77c7320b5911488e4c14d195ffbf634d8ec4b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-std-10-3-0c2d9d4e.json","sourceId":"ctrl:iia-2024:Std 10.3","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:39dff700e2a0bbdef624f431f6804954b71d44876cada877e7f382362a2cddea","properties":{"control_id":"APO14","coverage":"partial","delta":"operational data management - data-management strategy, business glossary/metadata, data-quality profiling and cleansing, archiving/backup - beyond governance policy and oversight bodies","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-20-4a468c1a.json","sourceId":"uc:UC-GOV-20","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-apo14-ab650d02.json","targetId":"ctrl:cobit-2019:APO14","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3b9ed6f05fd9d237f6102e13c13ce5fc7df7836d69f775bccdc377d4039dfeed","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art6-7-cd7435c0.json","sourceId":"ctrl:eu-ai-act:AIA-Art6-7","targetDetailPath":"/data/v1/records/std-eu-ai-act-54986689.json","targetId":"std:eu-ai-act","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4122f81ea991bcd47e0c3183b4b835b5072fd53212d5155233684f99f1cba7d3","properties":{"control_id":"Principle 10","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-10-fc9abe7f.json","sourceId":"uc:UC-AUDIT-10","targetDetailPath":"/data/v1/records/ctrl-iia-2024-principle-10-fc5ee25f.json","targetId":"ctrl:iia-2024:Principle 10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:41692619f3ba888f986fdccccd6c9ec1066f62d55e05d9d1299f22409cf139ec","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-principle-14-fd4f55ab.json","sourceId":"ctrl:iia-2024:Principle 14","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:45a1e5145b0928b28d18bf5921388ea0c0962d3cd43c1e225eae980c86022c05","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-a003-bea61fd9.json","sourceId":"ctrl:aiuc-1:A003","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:45ba062bf9ad1f3c5aa1ddb880443104a414c5794361f9832e9585af0b2bbeb2","properties":{"control_id":"Principle 6","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-02-0279f203.json","sourceId":"uc:UC-AUDIT-02","targetDetailPath":"/data/v1/records/ctrl-iia-2024-principle-6-dc3030fa.json","targetId":"ctrl:iia-2024:Principle 6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:47472f6f81d5e60212915d60644980d00c90385e35c468c9335aebda80a424de","properties":{"control_id":"HIPAA-164.312(a)","coverage":"partial","delta":"automatic logoff and encryption/decryption of ePHI are satisfied by the session-lock (UC-ACCESS-12) and cryptographic (UC-CRYPTO-01) companion controls; emergency-access is an availability arm","framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-05-9b7f3e34.json","sourceId":"uc:UC-ACCESS-05","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-312-a-5c8bb707.json","targetId":"ctrl:hipaa:HIPAA-164.312(a)","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4afb84782e3cec6bd552916b34f8b15f3759125ed7ec2be222c7c91b5a6e3a61","properties":{"control_id":"APO06","coverage":"partial","delta":"full IT financial management including cost transparency and allocation models","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-11-a13b60d3.json","sourceId":"uc:UC-GOV-11","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-apo06-2191e824.json","targetId":"ctrl:cobit-2019:APO06","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4c7effc1e728339a4e8a777ea4487a722140f1a715d83dbe1b941a4af5afdd1d","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-apo01-d6a49088.json","sourceId":"ctrl:cobit-2019:APO01","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:522d28aed24ab32fe41449ac950acc152ef604cf0a9e3b0e0aee1ab0b91027e2","properties":{"control_id":"P5","coverage":"full","delta":null,"framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-07-2a8998f7.json","sourceId":"uc:UC-GOV-07","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p5-7f62f522.json","targetId":"ctrl:coso-ic:P5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5868785f2387ea5e5baf5f8d80fdbe1d23749713f245e3a69e8790c3536e9c2e","properties":{"control_id":"P1","coverage":"full","delta":null,"framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p1-f41d97ed.json","targetId":"ctrl:coso-ic:P1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5e326730f8ab2cb1e2ab11f630ba19a793966e4dac100e3e7d4d1a544232f1fc","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-ic-p16-4995bb68.json","sourceId":"ctrl:coso-ic:P16","targetDetailPath":"/data/v1/records/std-coso-ic-3f80f565.json","targetId":"std:coso-ic","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6e062e768ccd5a27ae74097131b061d024e4d8c49db22e35bd13c427c83f108e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-std-1-2-da892b84.json","sourceId":"ctrl:iia-2024:Std 1.2","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6e4a82ac5680b85a4a0a1b293996eefad4f8970f2b0ec15e7c53c155b25a3b7d","properties":{"control_id":"P2","coverage":"full","delta":null,"framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","sourceId":"uc:UC-GOV-05","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p2-4f80775c.json","targetId":"ctrl:coso-ic:P2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6ecddf3dfc0606d5faa60338779f21b6e6ce0b511273bf6699b901a79b8b0f64","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-ic-p1-f41d97ed.json","sourceId":"ctrl:coso-ic:P1","targetDetailPath":"/data/v1/records/std-coso-ic-3f80f565.json","targetId":"std:coso-ic","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:74bc65e8e9aa1bfb54f93555a389e7974ee95deaf69f27e0c445b8aa95797baf","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art27-7b550500.json","sourceId":"ctrl:eu-ai-act:AIA-Art27","targetDetailPath":"/data/v1/records/std-eu-ai-act-54986689.json","targetId":"std:eu-ai-act","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:74e883a4246ff37ceb111e94ede879200b02479a84eda309b5816228465bece2","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-dss06-c2b31b0e.json","sourceId":"ctrl:cobit-2019:DSS06","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:76ea898dec4991a063d580a93d29b534d6d9ed2a3aac2b2e7037d9911d54508a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-principle-4-e921b675.json","sourceId":"ctrl:iia-2024:Principle 4","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:76f616cc9d689545baa7759562f2c82713d99f16be87637a3b8abeb1523b4053","properties":{"control_id":"Std 1.1","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-04-c880e18f.json","sourceId":"uc:UC-AUDIT-04","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-1-1-e8b262ce.json","targetId":"ctrl:iia-2024:Std 1.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7b987e2457e3123d2ab502637159c47dbd0be45ceb05c4e95eff9095762ad1b8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-erm-e14-68b8e783.json","sourceId":"ctrl:coso-erm:E14","targetDetailPath":"/data/v1/records/std-coso-erm-7265cc54.json","targetId":"std:coso-erm","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7d7f47e94e080166ff4b43be28d637d82c7939b51d35c1a61664ce6a8d58db45","properties":{"control_id":"Principle 1","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-04-c880e18f.json","sourceId":"uc:UC-AUDIT-04","targetDetailPath":"/data/v1/records/ctrl-iia-2024-principle-1-97822cbc.json","targetId":"ctrl:iia-2024:Principle 1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:83e136a1f18ac7b92e27bb2448dc3cc6c17ecab0f55475fb78cd384b1480466b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-ic-p2-4f80775c.json","sourceId":"ctrl:coso-ic:P2","targetDetailPath":"/data/v1/records/std-coso-ic-3f80f565.json","targetId":"std:coso-ic","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8617482233ffe8bfa5309d39b6d520746dc930ecdc68348f52565c031c767fce","properties":{"control_id":"EDM04","coverage":"partial","delta":"governance of optimization across all enterprise IT resources (people, technology, infrastructure), beyond security-scoped budget and personnel","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-11-a13b60d3.json","sourceId":"uc:UC-GOV-11","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-edm04-7ad4bdc3.json","targetId":"ctrl:cobit-2019:EDM04","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8a42451d0b65b2f78abe66a322743070f045bb0d4cc748770959deed39bbcaf0","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-ic-p11-2a08883b.json","sourceId":"ctrl:coso-ic:P11","targetDetailPath":"/data/v1/records/std-coso-ic-3f80f565.json","targetId":"std:coso-ic","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8d541a5cf5c4693768950d074cf5285533f6708c692c8404b375d1e8a65d9b21","properties":{"control_id":"Principle 9","coverage":"partial","delta":"Principle 9 also spans methodologies (9.3) and assurance coordination/reliance (9.5)","framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-09-f23ecfe4.json","sourceId":"uc:UC-AUDIT-09","targetDetailPath":"/data/v1/records/ctrl-iia-2024-principle-9-068ca212.json","targetId":"ctrl:iia-2024:Principle 9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8fe0a77df14eb5ed5f66711d269b25dd250f9ed2ad6eb19f812f1fadba1e4dca","properties":{"control_id":"Principle 4","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-07-50f8c2fa.json","sourceId":"uc:UC-AUDIT-07","targetDetailPath":"/data/v1/records/ctrl-iia-2024-principle-4-e921b675.json","targetId":"ctrl:iia-2024:Principle 4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:951f198617fd4e6985371dc92e0a4c9ef65a0e645d8465f2002e7785532ca2a6","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-ic-p8-e85b1bf7.json","sourceId":"ctrl:coso-ic:P8","targetDetailPath":"/data/v1/records/std-coso-ic-3f80f565.json","targetId":"std:coso-ic","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:970b37f571d1289fab1672f15a9bbee65cc4f9e65d4b8ebc43b29dbcfe7256f8","properties":{"control_id":"EDM01","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-01-e1e2136d.json","sourceId":"uc:UC-GOV-01","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-edm01-95fe0a96.json","targetId":"ctrl:cobit-2019:EDM01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9932a4f02e142b017c507e3b409efd0cb48f21bb451588f489f5337f3cfa0c24","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-std-1-3-d38479a0.json","sourceId":"ctrl:iia-2024:Std 1.3","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9f5a2586a94972fdb29f62aa7a871ed85bd12341b34300a37eb3c3a4e9db887e","properties":{"control_id":"Std 11.3","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-16-03aa1161.json","sourceId":"uc:UC-AUDIT-16","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-11-3-dbfc7dce.json","targetId":"ctrl:iia-2024:Std 11.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a0c14c0293d1afba8a4199022904af26b4f4095f4319e0f53f6796d1a5facba9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-b007-151dfcd3.json","sourceId":"ctrl:aiuc-1:B007","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a4da889c3e8d9a23cacd902b671a9a5be1365ce9c64cb898768e45d8f0589034","properties":{"control_id":"P8","coverage":"full","delta":null,"framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-12-210e108b.json","sourceId":"uc:UC-RISK-12","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p8-e85b1bf7.json","targetId":"ctrl:coso-ic:P8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ad0e3cf5d28f24b95a2da30e0f428b9a4d26bd2d74f219c1209d4dbc84be7283","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-ic-p10-c5a97f20.json","sourceId":"ctrl:coso-ic:P10","targetDetailPath":"/data/v1/records/std-coso-ic-3f80f565.json","targetId":"std:coso-ic","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b8a1adc13a002c1b9d51e184ce6fa06c7bb6cde5e84ced80eafef7cd10ecd1e3","properties":{"control_id":"Principle 15","coverage":"partial","delta":"Principle 15 also requires monitoring/confirming implementation of recommendations and action plans (15.2)","framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-16-03aa1161.json","sourceId":"uc:UC-AUDIT-16","targetDetailPath":"/data/v1/records/ctrl-iia-2024-principle-15-b57f77c8.json","targetId":"ctrl:iia-2024:Principle 15","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:baa1cf29b74729ad0cedb9794b800c963f716d47933df0994e7ae2bbdd13db4d","properties":{"control_id":"Std 1.3","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-04-c880e18f.json","sourceId":"uc:UC-AUDIT-04","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-1-3-d38479a0.json","targetId":"ctrl:iia-2024:Std 1.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bdc44b1da37bbb6e2bbc0430ad30f108abcae9f7f623ab8b27037ee18c326bd1","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-principle-9-068ca212.json","sourceId":"ctrl:iia-2024:Principle 9","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c35bda6f401c7e185f678db00808439de2948ae69fc0c5849eef9a052d198c43","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-std-1-1-e8b262ce.json","sourceId":"ctrl:iia-2024:Std 1.1","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c56f2b88ba16f4e02b686a0edb022ea251b93d628af0755d9b7f6b517fc4cafe","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-principle-3-a2a0c733.json","sourceId":"ctrl:iia-2024:Principle 3","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c928b3c5d2c020d22ad226062bb2e1ad663ed8de9a59a550ae28c7cd54a72a21","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-edm04-7ad4bdc3.json","sourceId":"ctrl:cobit-2019:EDM04","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cb4bb91299330aba65c724847882f00b89cc0fa6a325e17292b684496c582f1b","properties":{"control_id":"P11","coverage":"partial","delta":"principle applies across all technology domains, not only access","framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-access-15-84699cae.json","sourceId":"uc:UC-ACCESS-15","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p11-2a08883b.json","targetId":"ctrl:coso-ic:P11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cd2736c7f54ef2e0fa56024aff7c35d1791ffc268f0a89ba93a8d8d3b3d3a0c5","properties":{"control_id":"Std 10.1","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-10-fc9abe7f.json","sourceId":"uc:UC-AUDIT-10","targetDetailPath":"/data/v1/records/ctrl-iia-2024-std-10-1-a5b61f0d.json","targetId":"ctrl:iia-2024:Std 10.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cefd16afb3bee8931d0986f095a7fc954359fc5ac0bb3e0ba28519365d40a052","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-erm-e1-2389ffca.json","sourceId":"ctrl:coso-erm:E1","targetDetailPath":"/data/v1/records/std-coso-erm-7265cc54.json","targetId":"std:coso-erm","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d23c16c0475ddff17cb84767adaa69eb11e7677c2c55a2aa5d8ac340b162dc89","properties":{"control_id":"C001","coverage":"partial","delta":"a system-specific AI risk taxonomy with severity tiers that drives output filtering, monitoring categories, and third-party test scope","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-04-b35afd39.json","sourceId":"uc:UC-AI-04","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-c001-6bc6c173.json","targetId":"ctrl:aiuc-1:C001","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d580895fb25016a0f880c3525c9fd4e54d24821bb7ee37bffaaf22bb474926b9","properties":{"control_id":"Principle 3","coverage":"full","delta":null,"framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-06-3a5916e0.json","sourceId":"uc:UC-AUDIT-06","targetDetailPath":"/data/v1/records/ctrl-iia-2024-principle-3-a2a0c733.json","targetId":"ctrl:iia-2024:Principle 3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dc58a262b9c5130739984b7631650a439ee6b18ce8a57263d9b917ac82a47ad5","properties":{"control_id":"P10","coverage":"partial","delta":"principle applies across all control domains, not only access","framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-access-15-84699cae.json","sourceId":"uc:UC-ACCESS-15","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p10-c5a97f20.json","targetId":"ctrl:coso-ic:P10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:de8d6709ab9dabdb8f48b03bd4d7b13076c63669a00fce9accb486fdca9e9713","properties":{"control_id":"E3","coverage":"full","delta":null,"framework":"coso-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/ctrl-coso-erm-e3-2d76e2c2.json","targetId":"ctrl:coso-erm:E3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:def23d1c288a2739ddb09d7a99d80475f3e63aff401fc28cbc44da318c7d47e9","properties":{"control_id":"E14","coverage":"full","delta":null,"framework":"coso-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-10-6d44f690.json","sourceId":"uc:UC-RISK-10","targetDetailPath":"/data/v1/records/ctrl-coso-erm-e14-68b8e783.json","targetId":"ctrl:coso-erm:E14","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e1d3b60ec55d2ba06662780df041b309092dbbf76738f7d5a030fa2f637b11dc","properties":{"control_id":"DSS06","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-14-997de451.json","sourceId":"uc:UC-BCDR-14","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss06-c2b31b0e.json","targetId":"ctrl:cobit-2019:DSS06","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e863c1c1ab2504a5a9f49f75d138cb6c0f587bea79ee2d5f3497ab636a63df12","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-principle-6-dc3030fa.json","sourceId":"ctrl:iia-2024:Principle 6","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb2763c24ae0bb6b3625b11233e6e45a9a11273627780a51ee50b96a9c66f2a8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-apo14-ab650d02.json","sourceId":"ctrl:cobit-2019:APO14","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ec12eedda1de13de98fa6891f9f791b3b3dae6903f4d6bd9259f131e9b9310df","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-edm01-95fe0a96.json","sourceId":"ctrl:cobit-2019:EDM01","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:edc524182fec3365afded04e66505533a46f61f318adf773398145e3a01d5efc","properties":{"control_id":"AIA-Art27","coverage":"full","delta":null,"framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-04-b35afd39.json","sourceId":"uc:UC-AI-04","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art27-7b550500.json","targetId":"ctrl:eu-ai-act:AIA-Art27","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f08b3091da2f2ebef68bbc42112348fdd319a558f738645d33dbdb66a0e005e4","properties":{"control_id":"AIA-Art6-7","coverage":"full","delta":null,"framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-04-b35afd39.json","sourceId":"uc:UC-AI-04","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art6-7-cd7435c0.json","targetId":"ctrl:eu-ai-act:AIA-Art6-7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f1542a50f9e5cd553a0b2a8d3980b06d3b635104cfff72d656321d8373429ebd","properties":{"control_id":"Principle 14","coverage":"partial","delta":"Principle 14 also spans evaluation of findings, recommendations and action plans, and engagement conclusions (Std 14.3-14.5 home) and engagement documentation (Std 14.6 home)","framework":"iia-2024","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2024 edition"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-13-3dae730e.json","sourceId":"uc:UC-AUDIT-13","targetDetailPath":"/data/v1/records/ctrl-iia-2024-principle-14-fd4f55ab.json","targetId":"ctrl:iia-2024:Principle 14","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f16e284a257e8b96794e10fbe08c1efc2c5e2fe1149b35ef766faf310ffbd634","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-apo06-2191e824.json","sourceId":"ctrl:cobit-2019:APO06","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fa025a0315b5823b158620adb1e426d69f3be952af40edb9d2b815f9a31e2bc6","properties":{"control_id":"A003","coverage":"partial","delta":"agent-specific enforcement: data access scoped per task, user role, agent role, and context at inference time","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-a003-bea61fd9.json","targetId":"ctrl:aiuc-1:A003","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fc1864e38234f319edeb1291aab138591e799e19c843dbcba7d1b80c5e00e01a","properties":{"control_id":"E4","coverage":"full","delta":null,"framework":"coso-erm","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/ctrl-coso-erm-e4-97e5f081.json","targetId":"ctrl:coso-erm:E4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fc56b9ed453de3b0261ce897bc26c0edde1bcc41dc9640cc6c37b84f738ade3f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iia-2024-std-11-3-dbfc7dce.json","sourceId":"ctrl:iia-2024:Std 11.3","targetDetailPath":"/data/v1/records/std-iia-2024-1687734b.json","targetId":"std:iia-2024","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fda71e41615a40a1fba57d5edf79eb5cec9502bc8b254d7a4b3a461c70f91a37","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-erm-e3-2d76e2c2.json","sourceId":"ctrl:coso-erm:E3","targetDetailPath":"/data/v1/records/std-coso-erm-7265cc54.json","targetId":"std:coso-erm","type":"belongs_to"}],"schemaVersion":1,"scope":"topics","total":331}
