{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["ctrl:aiuc-1:A004","ctrl:aiuc-1:A005","ctrl:aiuc-1:A006","ctrl:aiuc-1:B008","ctrl:aiuc-1:E009","ctrl:ccpa:CCPA-1798.150","ctrl:cobit-2019:BAI03","ctrl:cobit-2019:DSS02","ctrl:cobit-2019:DSS03","ctrl:cobit-2019:DSS05","ctrl:coso-ic:P17","ctrl:dora:DORA-Art17-23","ctrl:eu-ai-act:AIA-Art15","ctrl:gdpr:GDPR-Art33","ctrl:gdpr:GDPR-Art34","ctrl:gdpr:GDPR-Art44-49","ctrl:gdpr:GDPR-Art9","ctrl:hipaa:HIPAA-164.312(b)","ctrl:hipaa:HIPAA-164.312(c)","ctrl:hipaa:HIPAA-164.400-414","ctrl:hipaa:HIPAA-164.514","ctrl:iso-27001:A.5.24","ctrl:iso-27001:A.5.25","ctrl:iso-27001:A.5.26","ctrl:iso-27001:A.5.27","ctrl:iso-27001:A.5.28","ctrl:iso-27001:A.5.34","ctrl:iso-27001:A.6.8","ctrl:iso-27001:A.8.10","ctrl:iso-27001:A.8.11","ctrl:iso-27001:A.8.12","ctrl:iso-27001:A.8.13","ctrl:iso-27001:A.8.15","ctrl:iso-27001:A.8.16","ctrl:iso-27001:A.8.17","ctrl:iso-27001:A.8.22","ctrl:iso-27001:A.8.27","ctrl:iso-27001:A.8.28","ctrl:iso-27001:A.8.6","ctrl:nist-800-53:AC-4"],"directIds":[],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"Incident Management & Response","next":"/assets/agent_topics-incident-management-response-2.251b1d3cfb3c24df.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Protect IP & trade secrets","details":{"automation":"hybrid","control_category":"technical","control_id":"A004","control_type":"preventive","domains":["AI Governance","Data Protection & Privacy"],"framework":"aiuc-1","group":"Data & Privacy","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":5,"source_pages":null,"source_url":"https://www.aiuc-1.com/data-and-privacy/protect-ip-trade-secrets"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-a004-0955d43a.html","id":"ctrl:aiuc-1:A004","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AA004","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/data-and-privacy/protect-ip-trade-secrets","title":"A004 — Protect IP & trade secrets","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-a004-0955d43a.1017c974af4b43d0.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Prevent cross-customer data exposure","details":{"automation":"automated","control_category":"technical","control_id":"A005","control_type":"preventive","domains":["AI Governance","Data Protection & Privacy"],"framework":"aiuc-1","group":"Data & Privacy","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":5,"source_pages":null,"source_url":"https://www.aiuc-1.com/data-and-privacy/prevent-cross-customer-data-exposure"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-a005-12903764.html","id":"ctrl:aiuc-1:A005","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AA005","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/data-and-privacy/prevent-cross-customer-data-exposure","title":"A005 — Prevent cross-customer data exposure","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-a005-12903764.f738ac844492303a.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Prevent PII leakage","details":{"automation":"automated","control_category":"technical","control_id":"A006","control_type":"preventive","domains":["AI Governance","Data Protection & Privacy"],"framework":"aiuc-1","group":"Data & Privacy","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":4,"source_pages":null,"source_url":"https://www.aiuc-1.com/data-and-privacy/prevent-pii-leakage"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-a006-846858b8.html","id":"ctrl:aiuc-1:A006","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AA006","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/data-and-privacy/prevent-pii-leakage","title":"A006 — Prevent PII leakage","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-a006-846858b8.dc19d2405450a0b3.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Protect AI system deployment environment","details":{"automation":"hybrid","control_category":"technical","control_id":"B008","control_type":"preventive","domains":["AI Governance","Access Control & Identity Management","Secure Development (SDLC) & Application Security"],"framework":"aiuc-1","group":"Security","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":8,"source_pages":null,"source_url":"https://www.aiuc-1.com/security/protect-model-deployment-environment"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-b008-39c816b1.html","id":"ctrl:aiuc-1:B008","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AB008","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/security/protect-model-deployment-environment","title":"B008 — Protect AI system deployment environment","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-b008-39c816b1.d20c1b777cbdcf3a.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Monitor third-party access","details":{"automation":"automated","control_category":"technical","control_id":"E009","control_type":"preventive","domains":["AI Governance","Governance, Policy & Oversight"],"framework":"aiuc-1","group":"Accountability","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":4,"source_pages":null,"source_url":"https://www.aiuc-1.com/accountability/monitor-3rd-party-access"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-e009-5269a385.html","id":"ctrl:aiuc-1:E009","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AE009","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/accountability/monitor-3rd-party-access","title":"E009 — Monitor third-party access","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-e009-5269a385.5dc6cd79a240576a.json"},{"attributes":{"category":"technical","framework":"ccpa","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/ccpa/","description":"Reasonable security procedures; private right of action for breaches","details":{"automation":"hybrid","control_category":"technical","control_id":"CCPA-1798.150","control_type":"preventive","domains":["Data Protection & Privacy","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"ccpa","group":"CCPA/CPRA (California Consumer Privacy)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-ccpa-ccpa-1798-150-da298199.html","id":"ctrl:ccpa:CCPA-1798.150","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Accpa%3ACCPA-1798.150","sourceIds":["ccpa"],"sourceUrl":null,"title":"CCPA-1798.150 — Reasonable security procedures; private right of action for breaches","type":"control","url":"/assets/agent_record-ctrl-ccpa-ccpa-1798-150-da298199.b7ad647e847408af.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Solutions Identification and Build","details":{"automation":"manual","control_category":"administrative","control_id":"BAI03","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai03-bfe681b0.html","id":"ctrl:cobit-2019:BAI03","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI03","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI03 — Managed Solutions Identification and Build","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai03-bfe681b0.bf603bc83f14527d.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Service Requests and Incidents","details":{"automation":"hybrid","control_category":"administrative","control_id":"DSS02","control_type":"corrective","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"cobit-2019","group":"Deliver, Service and Support","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-dss02-af5bca5d.html","id":"ctrl:cobit-2019:DSS02","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ADSS02","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"DSS02 — Managed Service Requests and Incidents","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-dss02-af5bca5d.d9fabf94aa20dc7d.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Problems","details":{"automation":"manual","control_category":"administrative","control_id":"DSS03","control_type":"corrective","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"cobit-2019","group":"Deliver, Service and Support","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-dss03-2540740f.html","id":"ctrl:cobit-2019:DSS03","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ADSS03","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"DSS03 — Managed Problems","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-dss03-2540740f.0983703d1904b1c5.json"},{"attributes":{"category":"technical","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Security Services","details":{"automation":"hybrid","control_category":"technical","control_id":"DSS05","control_type":"preventive","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"cobit-2019","group":"Deliver, Service and Support","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-dss05-80cfe6d8.html","id":"ctrl:cobit-2019:DSS05","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ADSS05","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"DSS05 — Managed Security Services","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-dss05-80cfe6d8.40f5cc048ce33ab4.json"},{"attributes":{"category":"administrative","framework":"coso-ic","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-ic/","description":"The organization evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate.","details":{"automation":"manual","control_category":"administrative","control_id":"P17","control_type":"corrective","domains":["Compliance, Audit & Assurance","Financial Reporting Controls (SOX)","Incident Management & Response"],"framework":"coso-ic","group":"Monitoring Activities","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-ic-p17-277098f3.html","id":"ctrl:coso-ic:P17","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-ic%3AP17","sourceIds":["coso-ic"],"sourceUrl":null,"title":"P17 — The organization evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate.","type":"control","url":"/assets/agent_record-ctrl-coso-ic-p17-277098f3.286298345bb2e228.json"},{"attributes":{"category":"administrative","framework":"dora","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/dora/","description":"ICT-related incident management, classification and reporting","details":{"automation":"hybrid","control_category":"administrative","control_id":"DORA-Art17-23","control_type":"corrective","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Third-Party / Supply-Chain Risk","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"dora","group":"EU DORA (Digital Operational Resilience Act)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-dora-dora-art17-23-9aa7977f.html","id":"ctrl:dora:DORA-Art17-23","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Adora%3ADORA-Art17-23","sourceIds":["dora"],"sourceUrl":null,"title":"DORA-Art17-23 — ICT-related incident management, classification and reporting","type":"control","url":"/assets/agent_record-ctrl-dora-dora-art17-23-9aa7977f.313cf7638f5cfdb3.json"},{"attributes":{"category":"technical","framework":"eu-ai-act","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/eu-ai-act/","description":"Accuracy, robustness and cybersecurity (high-risk)","details":{"automation":"hybrid","control_category":"technical","control_id":"AIA-Art15","control_type":"preventive","domains":["AI Governance","Risk Assessment & Management","Governance, Policy & Oversight"],"framework":"eu-ai-act","group":"EU AI Act","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-eu-ai-act-aia-art15-c3704411.html","id":"ctrl:eu-ai-act:AIA-Art15","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aeu-ai-act%3AAIA-Art15","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"AIA-Art15 — Accuracy, robustness and cybersecurity (high-risk)","type":"control","url":"/assets/agent_record-ctrl-eu-ai-act-aia-art15-c3704411.8feee43381f296a4.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Notification of a personal data breach to the supervisory authority","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art33","control_type":"corrective","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art33-a2a440c2.html","id":"ctrl:gdpr:GDPR-Art33","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art33","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art33 — Notification of a personal data breach to the supervisory authority","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art33-a2a440c2.047194a4abc43d41.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Communication of a breach to the data subject","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art34","control_type":"corrective","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art34-6e2bfc74.html","id":"ctrl:gdpr:GDPR-Art34","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art34","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art34 — Communication of a breach to the data subject","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art34-6e2bfc74.d7048e8b489ba26d.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"International transfers of personal data","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art44-49","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art44-49-8ad28202.html","id":"ctrl:gdpr:GDPR-Art44-49","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art44-49","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art44-49 — International transfers of personal data","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art44-49-8ad28202.5b6cd8ca6d1807c9.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Processing of special categories of data","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art9","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art9-0813ab56.html","id":"ctrl:gdpr:GDPR-Art9","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art9","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art9 — Processing of special categories of data","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art9-0813ab56.36120ac99d1d4774.json"},{"attributes":{"category":"technical","framework":"hipaa","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/hipaa/","description":"Audit controls recording activity in systems with ePHI","details":{"automation":"automated","control_category":"technical","control_id":"HIPAA-164.312(b)","control_type":"detective","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Data Protection & Privacy"],"framework":"hipaa","group":"HIPAA Security Rule","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-hipaa-hipaa-164-312-b-7272303c.html","id":"ctrl:hipaa:HIPAA-164.312(b)","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Ahipaa%3AHIPAA-164.312%28b%29","sourceIds":["hipaa"],"sourceUrl":null,"title":"HIPAA-164.312(b) — Audit controls recording activity in systems with ePHI","type":"control","url":"/assets/agent_record-ctrl-hipaa-hipaa-164-312-b-7272303c.3f97e7dbfc1288c9.json"},{"attributes":{"category":"technical","framework":"hipaa","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/hipaa/","description":"Integrity controls protecting ePHI from improper alteration or destruction","details":{"automation":"hybrid","control_category":"technical","control_id":"HIPAA-164.312(c)","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Data Protection & Privacy"],"framework":"hipaa","group":"HIPAA Security Rule","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-hipaa-hipaa-164-312-c-7002cebd.html","id":"ctrl:hipaa:HIPAA-164.312(c)","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Ahipaa%3AHIPAA-164.312%28c%29","sourceIds":["hipaa"],"sourceUrl":null,"title":"HIPAA-164.312(c) — Integrity controls protecting ePHI from improper alteration or destruction","type":"control","url":"/assets/agent_record-ctrl-hipaa-hipaa-164-312-c-7002cebd.72dc179a1aee2a40.json"},{"attributes":{"category":"administrative","framework":"hipaa","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/hipaa/","description":"Breach notification to individuals, media, and HHS (incl. business-associate duties)","details":{"automation":"manual","control_category":"administrative","control_id":"HIPAA-164.400-414","control_type":"corrective","domains":["Data Protection & Privacy","Incident Management & Response","Compliance, Audit & Assurance"],"framework":"hipaa","group":"HIPAA Privacy & Breach Notification","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-hipaa-hipaa-164-400-414-aeadadc4.html","id":"ctrl:hipaa:HIPAA-164.400-414","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Ahipaa%3AHIPAA-164.400-414","sourceIds":["hipaa"],"sourceUrl":null,"title":"HIPAA-164.400-414 — Breach notification to individuals, media, and HHS (incl. business-associate duties)","type":"control","url":"/assets/agent_record-ctrl-hipaa-hipaa-164-400-414-aeadadc4.93e85a35434b624f.json"},{"attributes":{"category":"administrative","framework":"hipaa","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/hipaa/","description":"De-identification of PHI and limited data sets","details":{"automation":"manual","control_category":"administrative","control_id":"HIPAA-164.514","control_type":"preventive","domains":["Data Protection & Privacy","Incident Management & Response","Compliance, Audit & Assurance"],"framework":"hipaa","group":"HIPAA Privacy & Breach Notification","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-hipaa-hipaa-164-514-ccac89ca.html","id":"ctrl:hipaa:HIPAA-164.514","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Ahipaa%3AHIPAA-164.514","sourceIds":["hipaa"],"sourceUrl":null,"title":"HIPAA-164.514 — De-identification of PHI and limited data sets","type":"control","url":"/assets/agent_record-ctrl-hipaa-hipaa-164-514-ccac89ca.d15a5ad0b40df9a8.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Information security incident management planning and preparation","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.24","control_type":"corrective","domains":["Incident Management & Response"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-24-904c429f.html","id":"ctrl:iso-27001:A.5.24","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.24","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.24 — Information security incident management planning and preparation","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-24-904c429f.8d39585cd153b458.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Assessment and decision on information security events","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.25","control_type":"detective","domains":["Incident Management & Response"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-25-7dc7a20c.html","id":"ctrl:iso-27001:A.5.25","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.25","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.25 — Assessment and decision on information security events","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-25-7dc7a20c.52bc6e2b0f1530dc.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Response to information security incidents","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.26","control_type":"corrective","domains":["Incident Management & Response"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-26-863e832e.html","id":"ctrl:iso-27001:A.5.26","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.26","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.26 — Response to information security incidents","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-26-863e832e.4d7659d97c4996db.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Learning from information security incidents","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.27","control_type":"corrective","domains":["Incident Management & Response"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-27-df970c02.html","id":"ctrl:iso-27001:A.5.27","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.27","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.27 — Learning from information security incidents","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-27-df970c02.ee57fe9c5e3d8a1c.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Collection of evidence","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.28","control_type":"corrective","domains":["Incident Management & Response"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-28-e9d04483.html","id":"ctrl:iso-27001:A.5.28","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.28","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.28 — Collection of evidence","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-28-e9d04483.1cdfd3369d01b3d2.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Privacy and protection of personal identifiable information (PII)","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.34","control_type":"preventive","domains":["AI Governance","Compliance, Audit & Assurance","Data Protection & Privacy"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-34-58b0337f.html","id":"ctrl:iso-27001:A.5.34","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.34","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.34 — Privacy and protection of personal identifiable information (PII)","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-34-58b0337f.e45a5a6c7dded8d5.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Information security event reporting","details":{"automation":"manual","control_category":"administrative","control_id":"A.6.8","control_type":"detective","domains":["Incident Management & Response"],"framework":"iso-27001","group":"People controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-6-8-87f56c6a.html","id":"ctrl:iso-27001:A.6.8","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.6.8","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.6.8 — Information security event reporting","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-6-8-87f56c6a.9e050c5a3627b344.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Information deletion","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.10","control_type":"preventive","domains":["Data Protection & Privacy"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-10-8e3feb8b.html","id":"ctrl:iso-27001:A.8.10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.10","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.10 — Information deletion","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-10-8e3feb8b.6163cfe8db756b62.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Data masking","details":{"automation":"automated","control_category":"technical","control_id":"A.8.11","control_type":"preventive","domains":["Data Protection & Privacy"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-11-bb2940ca.html","id":"ctrl:iso-27001:A.8.11","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.11","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.11 — Data masking","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-11-bb2940ca.cb024d33b7a96e08.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Data leakage prevention","details":{"automation":"automated","control_category":"technical","control_id":"A.8.12","control_type":"preventive","domains":["Data Protection & Privacy"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-12-8310e795.html","id":"ctrl:iso-27001:A.8.12","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.12","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.12 — Data leakage prevention","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-12-8310e795.cb4eafa1d3e16902.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Information backup","details":{"automation":"automated","control_category":"technical","control_id":"A.8.13","control_type":"corrective","domains":["Business Continuity & Disaster Recovery"],"framework":"iso-27001","group":"Technological controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-13-23e70806.html","id":"ctrl:iso-27001:A.8.13","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.13","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.13 — Information backup","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-13-23e70806.88286a292a4227d6.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Logging","details":{"automation":"automated","control_category":"technical","control_id":"A.8.15","control_type":"detective","domains":["Logging, Monitoring & Detection"],"framework":"iso-27001","group":"Technological controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-15-ab7dd8ce.html","id":"ctrl:iso-27001:A.8.15","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.15","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.15 — Logging","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-15-ab7dd8ce.4b3bc4e10652c17d.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Monitoring activities","details":{"automation":"automated","control_category":"technical","control_id":"A.8.16","control_type":"detective","domains":["Logging, Monitoring & Detection","Network & Communications Security"],"framework":"iso-27001","group":"Technological controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-16-ca49cbfe.html","id":"ctrl:iso-27001:A.8.16","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.16","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.16 — Monitoring activities","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-16-ca49cbfe.c9fcc0892cc15830.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Clock synchronization","details":{"automation":"automated","control_category":"technical","control_id":"A.8.17","control_type":"preventive","domains":["Logging, Monitoring & Detection"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-17-92d6c1be.html","id":"ctrl:iso-27001:A.8.17","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.17","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.17 — Clock synchronization","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-17-92d6c1be.30694657701e16dc.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Segregation of networks","details":{"automation":"automated","control_category":"technical","control_id":"A.8.22","control_type":"preventive","domains":["Network & Communications Security"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-22-be69b805.html","id":"ctrl:iso-27001:A.8.22","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.22","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.22 — Segregation of networks","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-22-be69b805.5234cf42dc9ed9c8.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Secure system architecture and engineering principles","details":{"automation":"manual","control_category":"technical","control_id":"A.8.27","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-27-a4a3784c.html","id":"ctrl:iso-27001:A.8.27","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.27","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.27 — Secure system architecture and engineering principles","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-27-a4a3784c.a161fced505c7ea9.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Secure coding","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.28","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-28-03be11c2.html","id":"ctrl:iso-27001:A.8.28","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.28","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.28 — Secure coding","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-28-03be11c2.51642e5597045e70.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Capacity management","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.6","control_type":"detective","domains":["Access Control & Identity Management","Cryptography & Key Management","Data Protection & Privacy","Secure Configuration & Change Management","Vulnerability & Patch Management","Logging, Monitoring & Detection","Business Continuity & Disaster Recovery","Network & Communications Security","Secure Development (SDLC) & Application Security"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-6-d9abb4dc.html","id":"ctrl:iso-27001:A.8.6","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.6","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.6 — Capacity management","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-6-d9abb4dc.e3b708aae744320b.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Information Flow Enforcement","details":{"automation":"automated","control_category":"technical","control_id":"AC-4","control_type":"preventive","domains":["Data Protection & Privacy","Network & Communications Security"],"framework":"nist-800-53","group":"Access Control","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-ac-4-803f5fce.html","id":"ctrl:nist-800-53:AC-4","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3AAC-4","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"AC-4 — Information Flow Enforcement","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-ac-4-803f5fce.04b346cce4b3a152.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:064c13ba66090a675f3ddc5ec32d06e7ad9429416e49de63db68a7cbc43d4f65","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-dss05-80cfe6d8.json","sourceId":"ctrl:cobit-2019:DSS05","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0d43e32f0d3e2b60efea95e2fed94d37ff2af0acfb522094329709a9dc6a056a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-514-ccac89ca.json","sourceId":"ctrl:hipaa:HIPAA-164.514","targetDetailPath":"/data/v1/records/std-hipaa-a825d271.json","targetId":"std:hipaa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0e08d2bd2b64738fdceb908cac4d8acbb4ffc89f70de4c75dbaa5c151721ed92","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-a006-846858b8.json","sourceId":"ctrl:aiuc-1:A006","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1034a1bf8aadb88c03724051eb8a21ece1a44c8b14c592c16dc9039e08476a12","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art44-49-8ad28202.json","sourceId":"ctrl:gdpr:GDPR-Art44-49","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:147ae985b733872ac1b56a5c69d128a1273023f70c2ca3795bb209a971d54203","properties":{"control_id":"A.8.13","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-03-d30f4ccf.json","sourceId":"uc:UC-BCDR-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-13-23e70806.json","targetId":"ctrl:iso-27001:A.8.13","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:151c6358382dbbca56287fa96b5e2f91eda2817b774910275f3b508306cd9bfe","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-a005-12903764.json","sourceId":"ctrl:aiuc-1:A005","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:16c299d41edf19be14879b87685497d898252c077ecae6454388362bb74bb506","properties":{"control_id":"GDPR-Art34","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-08-01afe3d1.json","sourceId":"uc:UC-IR-08","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art34-6e2bfc74.json","targetId":"ctrl:gdpr:GDPR-Art34","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:16d56791ede1a1f154ed635d0174779a85de2cee698b68558f8eaed8b791513b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-17-92d6c1be.json","sourceId":"ctrl:iso-27001:A.8.17","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1e008c7e98dc9d2c91316291b2e08e53b40f4b0e8a6ff8f3833feb47799c8c7a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-27-a4a3784c.json","sourceId":"ctrl:iso-27001:A.8.27","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1e2bd6679be011acc04c51bd48e6fb98b29fe6f75a52aeecd0e358286263f14d","properties":{"control_id":"CCPA-1798.150","coverage":"full","delta":null,"framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","sourceId":"uc:UC-DATA-13","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-150-da298199.json","targetId":"ctrl:ccpa:CCPA-1798.150","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:208d89715d2babbc7c6b0cd41a2ff7f7d0f9f973ea4a7b367c1ade1ce6b935b9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-27-df970c02.json","sourceId":"ctrl:iso-27001:A.5.27","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:20e4b2a31e5517b32fa223ea9b1b8fd79f1f9756c4fd2ee3519a688b1e5e002f","properties":{"control_id":"DSS02","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss02-af5bca5d.json","targetId":"ctrl:cobit-2019:DSS02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:241e3ed1ff8130607909052d7a1a4961af0c9fa568fdacf408d7b8d9d359cb20","properties":{"control_id":"A.6.8","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-03-477c1ef0.json","sourceId":"uc:UC-IR-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-6-8-87f56c6a.json","targetId":"ctrl:iso-27001:A.6.8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2d3f198c0d10bf6a75acff9516befb1d4aebbaf82091a7889c8a800934f32a42","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-24-904c429f.json","sourceId":"ctrl:iso-27001:A.5.24","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2e2b50c86f8b2218c14fb4e9569a5c8a0507a11726b723c80dff2fd945514676","properties":{"control_id":"A.8.10","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-data-09-f83a01a3.json","sourceId":"uc:UC-DATA-09","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-10-8e3feb8b.json","targetId":"ctrl:iso-27001:A.8.10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2fa9ee745188901dc9cf334d826e8e52a294a06c63ae786f99df85acdb98780d","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-dss02-af5bca5d.json","sourceId":"ctrl:cobit-2019:DSS02","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3169f2abc7f4fe1d152757d80f0cb5ad870bd962db2898bc84fe7d135ea5f6f1","properties":{"control_id":"GDPR-Art33","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","sourceId":"uc:UC-LOG-06","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art33-a2a440c2.json","targetId":"ctrl:gdpr:GDPR-Art33","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:39b30f0980dc2a4c11b9ce2b623bbf9a939d0e5b5aace19f0d2e7cc96a2afa98","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-10-8e3feb8b.json","sourceId":"ctrl:iso-27001:A.8.10","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:39ba831adcb789e31ed1c2a108d886bd4232ca89968b0be5c4a70945c663fa9b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-12-8310e795.json","sourceId":"ctrl:iso-27001:A.8.12","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:41e2f7c3bbdb79c83f3d756c399e0ab252e00ec7add49757cef7164b72148cc1","properties":{"control_id":"AIA-Art15","coverage":"partial","delta":"AI-specific accuracy metrics and lifecycle-consistent performance require dedicated AI controls","framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art15-c3704411.json","targetId":"ctrl:eu-ai-act:AIA-Art15","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:46649b5491420104088389b6488bcc81c25e0f04301e1b993c9c416d4ab952b2","properties":{"control_id":"GDPR-Art44-49","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art44-49-8ad28202.json","targetId":"ctrl:gdpr:GDPR-Art44-49","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:494f71c171b62c71568247a14a50ed91f12978cf48211592b92b04d4f030328e","properties":{"control_id":"BAI03","coverage":"partial","delta":"full solution build, component, and maintenance life cycle satisfied by companion controls","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai03-bfe681b0.json","targetId":"ctrl:cobit-2019:BAI03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4d7f38c258495a76082e22f9523b4b80ddc1f72f3d737dc66980a67bb415cca7","properties":{"control_id":"A.5.34","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","sourceId":"uc:UC-DATA-13","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-34-58b0337f.json","targetId":"ctrl:iso-27001:A.5.34","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4dfb4f9e9ede5a7868a3faef7128824fa4aa94fa1d19b18c33452b64e08fbeaf","properties":{"control_id":"A.8.28","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-05-053afd62.json","sourceId":"uc:UC-SDLC-05","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-28-03be11c2.json","targetId":"ctrl:iso-27001:A.8.28","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4fb51c383bd08d7e4cb798d652a83c0b888d8fd0853a69efefe852a66ecbb53a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-312-b-7272303c.json","sourceId":"ctrl:hipaa:HIPAA-164.312(b)","targetDetailPath":"/data/v1/records/std-hipaa-a825d271.json","targetId":"std:hipaa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:512ba21439e87bc291748f791f63165c51c302598232ea229c29542a3578a201","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-dss03-2540740f.json","sourceId":"ctrl:cobit-2019:DSS03","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:523c13c2ff61fdfd308b100e2a64bf9acb3dda9d0aaefd85f7c02cd51c8b727a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-28-03be11c2.json","sourceId":"ctrl:iso-27001:A.8.28","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5669fd2d5b3ff1530dbbda7eb8167298deb5f15a16531065fa2675fca1094b91","properties":{"control_id":"HIPAA-164.312(c)","coverage":"partial","delta":"the electronic mechanism to authenticate that ePHI has not been altered or destroyed is the specific integrity-verification arm","framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-13-c09befaf.json","sourceId":"uc:UC-DATA-13","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-312-c-7002cebd.json","targetId":"ctrl:hipaa:HIPAA-164.312(c)","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5d3158fc5a1ac7d68c5708e840c3784b02a21c451532d965567e134722484087","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-150-da298199.json","sourceId":"ctrl:ccpa:CCPA-1798.150","targetDetailPath":"/data/v1/records/std-ccpa-55f3fd20.json","targetId":"std:ccpa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5ea9a605ea5162b98dfaf780e8acd3f3d613562504140ed2fa84d3b38f3d46c0","properties":{"control_id":"A.8.6","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-6-d9abb4dc.json","targetId":"ctrl:iso-27001:A.8.6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5f4cfb105780887905e7b4b98a5de22d67cd758cfc4002a0f4e9f0804f8d2951","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-34-58b0337f.json","sourceId":"ctrl:iso-27001:A.5.34","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:60288c7b615dd45071fe47c6f5941bd0186a54666ec26aa84d96505dc1e37e13","properties":{"control_id":"A.5.24","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-01-e7711d29.json","sourceId":"uc:UC-IR-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-24-904c429f.json","targetId":"ctrl:iso-27001:A.5.24","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:60f2083b85eec41e5629c01567e3bc03ebc043b72a575f38df3d7bd42caa9029","properties":{"control_id":"A.5.26","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-06-0b166c2a.json","sourceId":"uc:UC-IR-06","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-26-863e832e.json","targetId":"ctrl:iso-27001:A.5.26","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:62a6fd6b6e2a9e76fd2322f78498159ad83a219fdb36c5d6f7523a98e64315fd","properties":{"control_id":"B008","coverage":"partial","delta":"hardening of the model-serving and agent runtime environment, including model-artifact protection and isolation from other workloads","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b008-39c816b1.json","targetId":"ctrl:aiuc-1:B008","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:639af74f867207985c0d330720da0b18bcbac5a07f9e93504c9405e222505aca","properties":{"control_id":"A005","coverage":"partial","delta":"tenant isolation inside AI systems: retrieval indexes, memory, fine-tuning data, and caches segregated so one customer's data cannot surface in another customer's outputs","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-a005-12903764.json","targetId":"ctrl:aiuc-1:A005","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6c1846fb9812d3a66dd47cb08fabc59bc2947d21d3b9398e0ec8166b1e2f5445","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-a004-0955d43a.json","sourceId":"ctrl:aiuc-1:A004","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:73c1e2950e16821930d708b7ad25bf221676650298d136c8d0c766599b260715","properties":{"control_id":"P17","coverage":"partial","delta":"covers all internal-control deficiencies, beyond incident-derived lessons","framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-10-072c0403.json","sourceId":"uc:UC-IR-10","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p17-277098f3.json","targetId":"ctrl:coso-ic:P17","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:742f12bfa22aa79dad1ad12f11142e86877ae1b270e5eb0fec253ea4a23dacd6","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-312-c-7002cebd.json","sourceId":"ctrl:hipaa:HIPAA-164.312(c)","targetDetailPath":"/data/v1/records/std-hipaa-a825d271.json","targetId":"std:hipaa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7566c86da6687604708ae8825c0fd65a28909fb3e0c43ea698aedff05673ebe4","properties":{"control_id":"A.5.25","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-04-6067c069.json","sourceId":"uc:UC-IR-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-25-7dc7a20c.json","targetId":"ctrl:iso-27001:A.5.25","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7d3d8621f5beef92080b8777a791ec58c1dac1c601e0bfaad1e6b2edef600b06","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-4-803f5fce.json","sourceId":"ctrl:nist-800-53:AC-4","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7f3ec345be8a53799972255fcf0841ea74170cd05f5c38778ad918f03cecce68","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art9-0813ab56.json","sourceId":"ctrl:gdpr:GDPR-Art9","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:81d44294f99278af7978ea2c1252664038b73ac319ebe9256bebcaf995fe82a1","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art15-c3704411.json","sourceId":"ctrl:eu-ai-act:AIA-Art15","targetDetailPath":"/data/v1/records/std-eu-ai-act-54986689.json","targetId":"std:eu-ai-act","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:82eea83fdecd378457273ff3b26152ccbdd0dd982a892cdfbf90bfd7358b7263","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-400-414-aeadadc4.json","sourceId":"ctrl:hipaa:HIPAA-164.400-414","targetDetailPath":"/data/v1/records/std-hipaa-a825d271.json","targetId":"std:hipaa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8b9de4df2b9b11f4758d16caba3a14418486d52562080438d56995febeaf4511","properties":{"control_id":"DORA-Art17-23","coverage":"partial","delta":"major-incident report clocks: initial 24h, intermediate 72h, final 1 month","framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art17-23-9aa7977f.json","targetId":"ctrl:dora:DORA-Art17-23","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8ba1fcd2dce54d62b11512c22b5f9ff1de51a9fb9f041e24912fc85eded145cd","properties":{"control_id":"A.8.12","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-12-8310e795.json","targetId":"ctrl:iso-27001:A.8.12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8bdbde7107215d576d6eb3768027a92d2ebe8927bfd8d582b94f3c82ea69844c","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-ic-p17-277098f3.json","sourceId":"ctrl:coso-ic:P17","targetDetailPath":"/data/v1/records/std-coso-ic-3f80f565.json","targetId":"std:coso-ic","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:914fafede5d8ad85fc3020de74b4dd793a5d95525110d79ce2836af7671fa379","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-16-ca49cbfe.json","sourceId":"ctrl:iso-27001:A.8.16","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:93d3de6f3a8a86c480d9312157b8368a234de262365ef6c0a91ba280d32fa3c2","properties":{"control_id":"AC-4","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-4-803f5fce.json","targetId":"ctrl:nist-800-53:AC-4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:98e288190a80f4b9684f719b462f304e3ad2604643cf30159ec607b9f18aa498","properties":{"control_id":"A004","coverage":"partial","delta":"leakage of intellectual property and confidential information through AI system outputs, requiring model-output safeguards beyond network and channel flow controls","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-11-baf71fe4.json","sourceId":"uc:UC-DATA-11","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-a004-0955d43a.json","targetId":"ctrl:aiuc-1:A004","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9b1ac6bfa799e9a878a2f3298cc3d84973dc3ed7da85beabe618a4380720ef55","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai03-bfe681b0.json","sourceId":"ctrl:cobit-2019:BAI03","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9da2566dd4bcec9ec28079e30f249b4e4191c02c2bba10760bf3e22b7202af97","properties":{"control_id":"A.5.27","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-10-072c0403.json","sourceId":"uc:UC-IR-10","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-27-df970c02.json","targetId":"ctrl:iso-27001:A.5.27","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9f229e45003f2c7c825f7932294437466bf8be9e39c6c4ab0bcb25d8dc6b2192","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-dora-dora-art17-23-9aa7977f.json","sourceId":"ctrl:dora:DORA-Art17-23","targetDetailPath":"/data/v1/records/std-dora-95cf939d.json","targetId":"std:dora","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a2a316f5916d3671f160c275b17626637917d041fef59df212398e607e152aa4","properties":{"control_id":"A.8.15","coverage":"partial","delta":"also requires protecting, storing, and analysing produced logs","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-15-ab7dd8ce.json","targetId":"ctrl:iso-27001:A.8.15","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a61f37f0d822a0d2f0f83a8f144cc7c10b3d99b4fed6473e86dbae2100efe744","properties":{"control_id":"HIPAA-164.514","coverage":"full","delta":null,"framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-12-c5a5999a.json","sourceId":"uc:UC-DATA-12","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-514-ccac89ca.json","targetId":"ctrl:hipaa:HIPAA-164.514","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a8cee9dde29a243b600f5ad0128cf7aa74a7d87d1be4519238792fcbf2469e27","properties":{"control_id":"DSS05","coverage":"partial","delta":"also identity/logical access, physical access, and sensitive-document/output-device controls","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-13-aa7feb8e.json","sourceId":"uc:UC-BCDR-13","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss05-80cfe6d8.json","targetId":"ctrl:cobit-2019:DSS05","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ad79ca3242cac5551158b9c9ff960685018e66075adf393b637d03e7c34308b8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-b008-39c816b1.json","sourceId":"ctrl:aiuc-1:B008","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ae3606ca696844c9184d3116249072898cb52510ebf01f819f56d944939af325","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-15-ab7dd8ce.json","sourceId":"ctrl:iso-27001:A.8.15","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b16d94a2172ca8f0cd1a12637021852d2064f9132dd64f4ad2453c881c7973b1","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-26-863e832e.json","sourceId":"ctrl:iso-27001:A.5.26","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b17715d4b91d277dad33081e34c20643df56988bb40b13f8a9acde6d7b7f2683","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-11-bb2940ca.json","sourceId":"ctrl:iso-27001:A.8.11","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bf5f7706b3e73a46db661616cf5be6eac2a75128746032843f715220ed4b0d51","properties":{"control_id":"HIPAA-164.312(b)","coverage":"full","delta":null,"framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-log-01-022e9745.json","sourceId":"uc:UC-LOG-01","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-312-b-7272303c.json","targetId":"ctrl:hipaa:HIPAA-164.312(b)","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bfb7de3a8015b3a23a00a22565f5ec4ed0ddcdd12489f4bb54574cd8ddbc7472","properties":{"control_id":"DSS03","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss03-2540740f.json","targetId":"ctrl:cobit-2019:DSS03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c437dc8c86ab106f3e2b742cf93b153d2d7f7dee2d450d53c59e6f5455f46456","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-6-d9abb4dc.json","sourceId":"ctrl:iso-27001:A.8.6","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c530cc1fc512c2a65966b3618d10b34c3e8e6c8d48b0b90f66500505f8fac21e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-28-e9d04483.json","sourceId":"ctrl:iso-27001:A.5.28","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c6c74ad43ded50d7606418cb4c66907bc7d96670a310f31fd666ed3e9668f9d8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art34-6e2bfc74.json","sourceId":"ctrl:gdpr:GDPR-Art34","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c783b550d3306227ac7538c829191604618ac82bd4c07c50f23ebdf9d0ceb7bf","properties":{"control_id":"A006","coverage":"partial","delta":"personal-data leakage through AI outputs and logs, requiring output-time redaction and log scrubbing in addition to stored-data pseudonymization","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-12-c5a5999a.json","sourceId":"uc:UC-DATA-12","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-a006-846858b8.json","targetId":"ctrl:aiuc-1:A006","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ca0f131f6e62765d8d0d647f569f09a71c706e4660cac0963b79736bc0db2ad1","properties":{"control_id":"GDPR-Art9","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-data-04-2a08628d.json","sourceId":"uc:UC-DATA-04","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art9-0813ab56.json","targetId":"ctrl:gdpr:GDPR-Art9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cf20f209cd1c7d4ef9387c1eeb0c255613c65e9023166ff5fc7b6a53a6a5f8ef","properties":{"control_id":"HIPAA-164.400-414","coverage":"partial","delta":"individual notice within 60 days; media notice at 500+ residents of a state/jurisdiction; HHS notice at 500+ individuals (contemporaneous); HHS notification required for all breaches (sub-500 via annual log)","framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-08-01afe3d1.json","sourceId":"uc:UC-IR-08","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-400-414-aeadadc4.json","targetId":"ctrl:hipaa:HIPAA-164.400-414","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d5dca93df6c9f5e530850413d15cfae38b5b043a13806a8d64c2bcb79f49bcf8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-25-7dc7a20c.json","sourceId":"ctrl:iso-27001:A.5.25","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d76ebfe31f21c2186bd8d943cc9a6d3c0ec35cc97fd13308cabc92f979186c55","properties":{"control_id":"A.8.22","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","sourceId":"uc:UC-NET-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-22-be69b805.json","targetId":"ctrl:iso-27001:A.8.22","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d907cc5edceec1049818f96e23f9a3ce6f9bc431ed0ad1335422ccd5f229e07e","properties":{"control_id":"A.8.17","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-log-02-0d3519a4.json","sourceId":"uc:UC-LOG-02","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-17-92d6c1be.json","targetId":"ctrl:iso-27001:A.8.17","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dbe656ec41a00e61bfd294b0ea18e81c7a16e4ddca41c534718e390300f999c0","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art33-a2a440c2.json","sourceId":"ctrl:gdpr:GDPR-Art33","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dfe559816aa8494a6d1fd4b26b3aea935be01495f24dc5dffe6db21953a20c19","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-13-23e70806.json","sourceId":"ctrl:iso-27001:A.8.13","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e25af5768f22128e1055e10a2199c3d56161178d27b3c68001e5f625c5a67e54","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-e009-5269a385.json","sourceId":"ctrl:aiuc-1:E009","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e7d290409635aa443f48ca96873b8ede955e7a22cdf34121a8acf404b37c3ceb","properties":{"control_id":"A.8.11","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-data-12-c5a5999a.json","sourceId":"uc:UC-DATA-12","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-11-bb2940ca.json","targetId":"ctrl:iso-27001:A.8.11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb9b2fc276833be22e81f68e87785ccf8cb27bd7adccf57070cac1d600ea9e8d","properties":{"control_id":"A.8.27","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-27-a4a3784c.json","targetId":"ctrl:iso-27001:A.8.27","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f0c83635efeba62d090fe35f8b2986eb6385b02b17fd74179801aaf67ac7f465","properties":{"control_id":"A.5.28","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-07-b4d61eff.json","sourceId":"uc:UC-IR-07","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-28-e9d04483.json","targetId":"ctrl:iso-27001:A.5.28","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f88f1f5f58d8e1ec14714587c7e139ff273175c626d9948d5a60b0dd530f56fe","properties":{"control_id":"E009","coverage":"partial","delta":"monitoring of third-party API connections, integrations, and sessions into AI systems, including revocation of stale access","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-log-09-54136146.json","sourceId":"uc:UC-LOG-09","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-e009-5269a385.json","targetId":"ctrl:aiuc-1:E009","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fb186e243e2e1fe03b9317a3e8c9db240c9f551928cd60e4775e7899ae8cd547","properties":{"control_id":"A.8.16","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","sourceId":"uc:UC-LOG-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-16-ca49cbfe.json","targetId":"ctrl:iso-27001:A.8.16","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fbcc32d3308dfe1e2b2af67ca3fa556f7fabce7f55b7f1833e4b6cc79879460f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-6-8-87f56c6a.json","sourceId":"ctrl:iso-27001:A.6.8","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fc576a933f2542e942f21141470a9d706153d23d73f1834e71c92bc1d99baecc","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-22-be69b805.json","sourceId":"ctrl:iso-27001:A.8.22","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"}],"schemaVersion":1,"scope":"topics","total":239}
