{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["ctrl:aiuc-1:B008","ctrl:aiuc-1:E011","ctrl:cobit-2019:BAI02","ctrl:cobit-2019:BAI03","ctrl:cobit-2019:BAI05","ctrl:cobit-2019:BAI06","ctrl:cobit-2019:BAI07","ctrl:cobit-2019:BAI08","ctrl:cobit-2019:BAI09","ctrl:cobit-2019:BAI10","ctrl:cobit-2019:MEA03","ctrl:coso-ic:P12","ctrl:dora:DORA-Art45","ctrl:eu-ai-act:AIA-Art15","ctrl:gdpr:GDPR-Art25","ctrl:iso-27001:A.5.10","ctrl:iso-27001:A.5.21","ctrl:iso-27001:A.5.32","ctrl:iso-27001:A.5.9","ctrl:iso-27001:A.7.10","ctrl:iso-27001:A.7.14","ctrl:iso-27001:A.7.9","ctrl:iso-27001:A.8.1","ctrl:iso-27001:A.8.19","ctrl:iso-27001:A.8.20","ctrl:iso-27001:A.8.21","ctrl:iso-27001:A.8.22","ctrl:iso-27001:A.8.25","ctrl:iso-27001:A.8.26","ctrl:iso-27001:A.8.27","ctrl:iso-27001:A.8.29","ctrl:iso-27001:A.8.30","ctrl:iso-27001:A.8.31","ctrl:iso-27001:A.8.32","ctrl:iso-27001:A.8.33","ctrl:iso-27001:A.8.7","ctrl:iso-27001:A.8.8","ctrl:iso-27001:A.8.9","ctrl:nist-800-53:AC-20","ctrl:nist-800-53:CA-8"],"directIds":[],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"Secure Configuration & Change Management","next":"/assets/agent_topics-secure-configuration-change-management-2.4f8d88688b4a15aa.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Protect AI system deployment environment","details":{"automation":"hybrid","control_category":"technical","control_id":"B008","control_type":"preventive","domains":["AI Governance","Access Control & Identity Management","Secure Development (SDLC) & Application Security"],"framework":"aiuc-1","group":"Security","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":8,"source_pages":null,"source_url":"https://www.aiuc-1.com/security/protect-model-deployment-environment"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-b008-39c816b1.html","id":"ctrl:aiuc-1:B008","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AB008","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/security/protect-model-deployment-environment","title":"B008 — Protect AI system deployment environment","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-b008-39c816b1.d20c1b777cbdcf3a.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Record processing locations","details":{"automation":"manual","control_category":"administrative","control_id":"E011","control_type":"preventive","domains":["AI Governance","Governance, Policy & Oversight"],"framework":"aiuc-1","group":"Accountability","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":1,"source_pages":null,"source_url":"https://www.aiuc-1.com/accountability/record-processing-locations"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-e011-56758692.html","id":"ctrl:aiuc-1:E011","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AE011","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/accountability/record-processing-locations","title":"E011 — Record processing locations","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-e011-56758692.a6cd870064c023c7.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Requirements Definition","details":{"automation":"manual","control_category":"administrative","control_id":"BAI02","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai02-80041b74.html","id":"ctrl:cobit-2019:BAI02","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI02","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI02 — Managed Requirements Definition","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai02-80041b74.811fa9609d081ff1.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Solutions Identification and Build","details":{"automation":"manual","control_category":"administrative","control_id":"BAI03","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai03-bfe681b0.html","id":"ctrl:cobit-2019:BAI03","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI03","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI03 — Managed Solutions Identification and Build","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai03-bfe681b0.bf603bc83f14527d.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Organizational Change","details":{"automation":"manual","control_category":"administrative","control_id":"BAI05","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai05-782c2ba0.html","id":"ctrl:cobit-2019:BAI05","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI05","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI05 — Managed Organizational Change","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai05-782c2ba0.00e720f1e24fc73a.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed IT Changes","details":{"automation":"hybrid","control_category":"administrative","control_id":"BAI06","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai06-306e8a70.html","id":"ctrl:cobit-2019:BAI06","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI06","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI06 — Managed IT Changes","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai06-306e8a70.e9d535a4b9c13753.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed IT Change Acceptance and Transitioning","details":{"automation":"manual","control_category":"administrative","control_id":"BAI07","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai07-dcabfa26.html","id":"ctrl:cobit-2019:BAI07","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI07","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI07 — Managed IT Change Acceptance and Transitioning","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai07-dcabfa26.a0ff637dbb16bcb5.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Knowledge","details":{"automation":"manual","control_category":"administrative","control_id":"BAI08","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai08-9f5f3d72.html","id":"ctrl:cobit-2019:BAI08","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI08","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI08 — Managed Knowledge","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai08-9f5f3d72.7270def696a140ff.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Assets","details":{"automation":"hybrid","control_category":"administrative","control_id":"BAI09","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai09-09a008c3.html","id":"ctrl:cobit-2019:BAI09","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI09","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI09 — Managed Assets","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai09-09a008c3.269925ad628c54e8.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Configuration","details":{"automation":"hybrid","control_category":"administrative","control_id":"BAI10","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":7,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai10-40479176.html","id":"ctrl:cobit-2019:BAI10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI10","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI10 — Managed Configuration","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai10-40479176.0dd8cba1e3a97830.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Compliance With External Requirements","details":{"automation":"manual","control_category":"administrative","control_id":"MEA03","control_type":"detective","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"cobit-2019","group":"Monitor, Evaluate and Assess","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-mea03-99c7dcca.html","id":"ctrl:cobit-2019:MEA03","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3AMEA03","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"MEA03 — Managed Compliance With External Requirements","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-mea03-99c7dcca.fefbe693d563ef85.json"},{"attributes":{"category":"administrative","framework":"coso-ic","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-ic/","description":"The organization deploys control activities through policies that establish what is expected and procedures that put policies into action.","details":{"automation":"manual","control_category":"administrative","control_id":"P12","control_type":"preventive","domains":["AI Governance","Financial Reporting Controls (SOX)","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security"],"framework":"coso-ic","group":"Control Activities","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-ic-p12-233c8710.html","id":"ctrl:coso-ic:P12","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-ic%3AP12","sourceIds":["coso-ic"],"sourceUrl":null,"title":"P12 — The organization deploys control activities through policies that establish what is expected and procedures that put policies into action.","type":"control","url":"/assets/agent_record-ctrl-coso-ic-p12-233c8710.67371e11c8053dff.json"},{"attributes":{"category":"administrative","framework":"dora","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/dora/","description":"Information and intelligence sharing arrangements","details":{"automation":"manual","control_category":"administrative","control_id":"DORA-Art45","control_type":"preventive","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Third-Party / Supply-Chain Risk","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"dora","group":"EU DORA (Digital Operational Resilience Act)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-dora-dora-art45-bb72d2e3.html","id":"ctrl:dora:DORA-Art45","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Adora%3ADORA-Art45","sourceIds":["dora"],"sourceUrl":null,"title":"DORA-Art45 — Information and intelligence sharing arrangements","type":"control","url":"/assets/agent_record-ctrl-dora-dora-art45-bb72d2e3.3fc6e3ce80d93299.json"},{"attributes":{"category":"technical","framework":"eu-ai-act","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/eu-ai-act/","description":"Accuracy, robustness and cybersecurity (high-risk)","details":{"automation":"hybrid","control_category":"technical","control_id":"AIA-Art15","control_type":"preventive","domains":["AI Governance","Risk Assessment & Management","Governance, Policy & Oversight"],"framework":"eu-ai-act","group":"EU AI Act","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-eu-ai-act-aia-art15-c3704411.html","id":"ctrl:eu-ai-act:AIA-Art15","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aeu-ai-act%3AAIA-Art15","sourceIds":["eu-ai-act"],"sourceUrl":null,"title":"AIA-Art15 — Accuracy, robustness and cybersecurity (high-risk)","type":"control","url":"/assets/agent_record-ctrl-eu-ai-act-aia-art15-c3704411.8feee43381f296a4.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/gdpr/","description":"Data protection by design and by default","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art25","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art25-ccf26a83.html","id":"ctrl:gdpr:GDPR-Art25","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art25","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art25 — Data protection by design and by default","type":"control","url":"/assets/agent_record-ctrl-gdpr-gdpr-art25-ccf26a83.b61830414c6ac681.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Acceptable use of information and other associated assets","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.10","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-10-2d5f0877.html","id":"ctrl:iso-27001:A.5.10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.10","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.10 — Acceptable use of information and other associated assets","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-10-2d5f0877.67fb64be930936a4.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Managing information security in the ICT supply chain","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.21","control_type":"preventive","domains":["Third-Party / Supply-Chain Risk"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-21-40b0d925.html","id":"ctrl:iso-27001:A.5.21","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.21","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.21 — Managing information security in the ICT supply chain","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-21-40b0d925.1a3dada72a599921.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Intellectual property rights","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.32","control_type":"preventive","domains":["Compliance, Audit & Assurance"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-32-7342e3f4.html","id":"ctrl:iso-27001:A.5.32","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.32","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.32 — Intellectual property rights","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-32-7342e3f4.528c5cd3488b2ecc.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Inventory of information and other associated assets","details":{"automation":"hybrid","control_category":"administrative","control_id":"A.5.9","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-9-64706ee7.html","id":"ctrl:iso-27001:A.5.9","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.9","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.9 — Inventory of information and other associated assets","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-5-9-64706ee7.4127a3f45cfb1299.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Storage media","details":{"automation":"manual","control_category":"physical","control_id":"A.7.10","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-10-2bfc8971.html","id":"ctrl:iso-27001:A.7.10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.10","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.10 — Storage media","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-7-10-2bfc8971.36c105414741e977.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Secure disposal or re-use of equipment","details":{"automation":"manual","control_category":"physical","control_id":"A.7.14","control_type":"preventive","domains":["Asset Management & Inventory","Physical & Environmental Security"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-14-5ada9a8e.html","id":"ctrl:iso-27001:A.7.14","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.14","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.14 — Secure disposal or re-use of equipment","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-7-14-5ada9a8e.6ece171fd37d329a.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Security of assets off-premises","details":{"automation":"manual","control_category":"physical","control_id":"A.7.9","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-9-43947bba.html","id":"ctrl:iso-27001:A.7.9","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.9","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.9 — Security of assets off-premises","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-7-9-43947bba.c6ef66cfb8830a9c.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"User endpoint devices","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.1","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-1-12f14999.html","id":"ctrl:iso-27001:A.8.1","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.1","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.1 — User endpoint devices","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-1-12f14999.273137a54d65477a.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Installation of software on operational systems","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.19","control_type":"preventive","domains":["Secure Configuration & Change Management"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-19-44c22e39.html","id":"ctrl:iso-27001:A.8.19","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.19","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.19 — Installation of software on operational systems","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-19-44c22e39.545f3e62c0b33cfe.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Networks security","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.20","control_type":"preventive","domains":["Logging, Monitoring & Detection","Network & Communications Security"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-20-68d4486b.html","id":"ctrl:iso-27001:A.8.20","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.20","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.20 — Networks security","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-20-68d4486b.2954a8cb8dc5a784.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Security of network services","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.21","control_type":"preventive","domains":["Logging, Monitoring & Detection","Network & Communications Security"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-21-5b64f0ec.html","id":"ctrl:iso-27001:A.8.21","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.21","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.21 — Security of network services","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-21-5b64f0ec.c19e4e6d4dbc33e9.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Segregation of networks","details":{"automation":"automated","control_category":"technical","control_id":"A.8.22","control_type":"preventive","domains":["Network & Communications Security"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-22-be69b805.html","id":"ctrl:iso-27001:A.8.22","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.22","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.22 — Segregation of networks","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-22-be69b805.5234cf42dc9ed9c8.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Secure development life cycle","details":{"automation":"manual","control_category":"technical","control_id":"A.8.25","control_type":"preventive","domains":["AI Governance","Secure Development (SDLC) & Application Security"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-25-3cbe2191.html","id":"ctrl:iso-27001:A.8.25","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.25","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.25 — Secure development life cycle","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-25-3cbe2191.5a6727c83cc3eeff.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Application security requirements","details":{"automation":"manual","control_category":"technical","control_id":"A.8.26","control_type":"preventive","domains":["AI Governance","Secure Development (SDLC) & Application Security"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-26-34d8988d.html","id":"ctrl:iso-27001:A.8.26","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.26","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.26 — Application security requirements","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-26-34d8988d.573fe72b8c3ba297.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Secure system architecture and engineering principles","details":{"automation":"manual","control_category":"technical","control_id":"A.8.27","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-27-a4a3784c.html","id":"ctrl:iso-27001:A.8.27","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.27","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.27 — Secure system architecture and engineering principles","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-27-a4a3784c.a161fced505c7ea9.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Security testing in development and acceptance","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.29","control_type":"detective","domains":["Secure Development (SDLC) & Application Security","Vulnerability & Patch Management"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-29-e0df0522.html","id":"ctrl:iso-27001:A.8.29","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.29","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.29 — Security testing in development and acceptance","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-29-e0df0522.6821b8b03d894c6c.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Outsourced development","details":{"automation":"manual","control_category":"technical","control_id":"A.8.30","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-30-6a684665.html","id":"ctrl:iso-27001:A.8.30","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.30","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.30 — Outsourced development","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-30-6a684665.8ec550cfd103fa07.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Separation of development, test and production environments","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.31","control_type":"preventive","domains":["Secure Configuration & Change Management","Secure Development (SDLC) & Application Security"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-31-eabf2a51.html","id":"ctrl:iso-27001:A.8.31","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.31","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.31 — Separation of development, test and production environments","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-31-eabf2a51.5799122e39f1a163.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Change management","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.32","control_type":"preventive","domains":["Secure Configuration & Change Management"],"framework":"iso-27001","group":"Technological controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-32-b855772a.html","id":"ctrl:iso-27001:A.8.32","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.32","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.32 — Change management","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-32-b855772a.f5c8f520189bf421.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Test information","details":{"automation":"manual","control_category":"technical","control_id":"A.8.33","control_type":"preventive","domains":["Secure Configuration & Change Management","Secure Development (SDLC) & Application Security"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-33-cabca252.html","id":"ctrl:iso-27001:A.8.33","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.33","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.33 — Test information","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-33-cabca252.2ffe591ca08b91ec.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Protection against malware","details":{"automation":"automated","control_category":"technical","control_id":"A.8.7","control_type":"preventive","domains":["Vulnerability & Patch Management"],"framework":"iso-27001","group":"Technological controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-7-99887761.html","id":"ctrl:iso-27001:A.8.7","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.7","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.7 — Protection against malware","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-7-99887761.9af76b851f2aff97.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Management of technical vulnerabilities","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.8","control_type":"preventive","domains":["Vulnerability & Patch Management"],"framework":"iso-27001","group":"Technological controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-8-d3706b09.html","id":"ctrl:iso-27001:A.8.8","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.8","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.8 — Management of technical vulnerabilities","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-8-d3706b09.07e0ec1dba80b180.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/iso-27001/","description":"Configuration management","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.9","control_type":"preventive","domains":["Secure Configuration & Change Management"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-9-616c4c1b.html","id":"ctrl:iso-27001:A.8.9","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.9","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.9 — Configuration management","type":"control","url":"/assets/agent_record-ctrl-iso-27001-a-8-9-616c4c1b.99b8d5fa27ee6c7e.json"},{"attributes":{"category":"administrative","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Use of External Systems","details":{"automation":"manual","control_category":"administrative","control_id":"AC-20","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"nist-800-53","group":"Access Control","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-ac-20-6e822026.html","id":"ctrl:nist-800-53:AC-20","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3AAC-20","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"AC-20 — Use of External Systems","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-ac-20-6e822026.123e8f1f431a107e.json"},{"attributes":{"category":"administrative","framework":"nist-800-53","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/nist-800-53/","description":"Penetration Testing","details":{"automation":"manual","control_category":"administrative","control_id":"CA-8","control_type":"detective","domains":["Vulnerability & Patch Management"],"framework":"nist-800-53","group":"Assessment, Authorization, and Monitoring","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-nist-800-53-ca-8-bbc6c82f.html","id":"ctrl:nist-800-53:CA-8","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Anist-800-53%3ACA-8","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CA-8 — Penetration Testing","type":"control","url":"/assets/agent_record-ctrl-nist-800-53-ca-8-bbc6c82f.72dab3d99d9167f4.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0193ee372df87471f989640b9a67875fec12d77ca2480b3c725772ea14d52169","properties":{"control_id":"A.8.1","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-1-12f14999.json","targetId":"ctrl:iso-27001:A.8.1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:02142d848bc8e970a3bed03fdd88575c3085b70e94789cdea473a192b7224dae","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-33-cabca252.json","sourceId":"ctrl:iso-27001:A.8.33","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:022e3abf61eda2578d0ac1bf1bb385c27ffcff99c107ff432c71a0a37c23689c","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-32-b855772a.json","sourceId":"ctrl:iso-27001:A.8.32","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:03c04772af38852c61bc45ced60807778313cd2b86db0fcbea885dea098335f6","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-21-40b0d925.json","sourceId":"ctrl:iso-27001:A.5.21","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0b6a063f429cabad5d3ba85857b4eaa9eec0c6399f8ddbd5aa5c4c32b8e505d1","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art25-ccf26a83.json","sourceId":"ctrl:gdpr:GDPR-Art25","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0c22dd4d48750ebdb122b83f160bc279432bdd300e42e74990a61d32ceb5c445","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-29-e0df0522.json","sourceId":"ctrl:iso-27001:A.8.29","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:10f2c8f3da582a25784d9db0b56806fe33641235b08257f7ed6a433ed4973603","properties":{"control_id":"A.7.10","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-10-2bfc8971.json","targetId":"ctrl:iso-27001:A.7.10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:135a001d73a464c593700d51e085d380a9024497c0fa6fb20e8821952e63674e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-26-34d8988d.json","sourceId":"ctrl:iso-27001:A.8.26","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:165477b789f44ce9d930421335c11f36733e2cb74deaafce7580ec576dacad75","properties":{"control_id":"MEA03","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-24-fa96fe18.json","sourceId":"uc:UC-AUDIT-24","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-mea03-99c7dcca.json","targetId":"ctrl:cobit-2019:MEA03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:176b2ff48f0328e6487bbba5bb2db8598d2eed6505c55c794d9b1c1b814e9dcc","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-14-5ada9a8e.json","sourceId":"ctrl:iso-27001:A.7.14","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:18457278e43b410f52161ca8640e0370690eb4a499175ad48b54070e4905c372","properties":{"control_id":"A.7.9","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-9-43947bba.json","targetId":"ctrl:iso-27001:A.7.9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1e008c7e98dc9d2c91316291b2e08e53b40f4b0e8a6ff8f3833feb47799c8c7a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-27-a4a3784c.json","sourceId":"ctrl:iso-27001:A.8.27","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1ebe8d4b78547cfd82fbcc2891be071626367e03eaf85d40e73f49495cd9dd48","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai02-80041b74.json","sourceId":"ctrl:cobit-2019:BAI02","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1f3f2b0ec80cd6a1b3f3a6ca18716e0c06e88c071d704b745a2e9773978e105d","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-7-99887761.json","sourceId":"ctrl:iso-27001:A.8.7","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:266413b704059cefdeb68ba76808b5444e25095d835aa595a43d1476260b7d3e","properties":{"control_id":"BAI10","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","sourceId":"uc:UC-SDLC-06","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai10-40479176.json","targetId":"ctrl:cobit-2019:BAI10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:27dd5e945af28141d844fab51e3199d7c1f67cead03cf2660e5481fa101c8ec7","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-9-64706ee7.json","sourceId":"ctrl:iso-27001:A.5.9","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:35eebd189f1575ee338fadccdde6be2f9eded242acad4ddcb3aa02c74807db27","properties":{"control_id":"BAI09","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-12-08ce2fc7.json","sourceId":"uc:UC-SDLC-12","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai09-09a008c3.json","targetId":"ctrl:cobit-2019:BAI09","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3792d426d2413f6963cd974cd28773026f37c0f551d8cf6724eda4f0744e5f95","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-20-68d4486b.json","sourceId":"ctrl:iso-27001:A.8.20","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3d2c27295dd4a86ef2ad723c9b1de134864a7d88e58e92085293c542028273a3","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-ca-8-bbc6c82f.json","sourceId":"ctrl:nist-800-53:CA-8","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:41e2f7c3bbdb79c83f3d756c399e0ab252e00ec7add49757cef7164b72148cc1","properties":{"control_id":"AIA-Art15","coverage":"partial","delta":"AI-specific accuracy metrics and lifecycle-consistent performance require dedicated AI controls","framework":"eu-ai-act","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2024/1689"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art15-c3704411.json","targetId":"ctrl:eu-ai-act:AIA-Art15","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:435470550375d418dcc629b659104f189e5fcbbef8cdb77b62204259ad3388e1","properties":{"control_id":"DORA-Art45","coverage":"full","delta":null,"framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-16-462251f1.json","sourceId":"uc:UC-BCDR-16","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art45-bb72d2e3.json","targetId":"ctrl:dora:DORA-Art45","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:494f71c171b62c71568247a14a50ed91f12978cf48211592b92b04d4f030328e","properties":{"control_id":"BAI03","coverage":"partial","delta":"full solution build, component, and maintenance life cycle satisfied by companion controls","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai03-bfe681b0.json","targetId":"ctrl:cobit-2019:BAI03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4a230971ca35f4362a01c4861ad078e87bea0a79bdaac6d7720dda0f8cc8d033","properties":{"control_id":"GDPR-Art25","coverage":"partial","delta":"Art.25(2) data-protection-by-default applies organization-wide beyond software design; this control covers the by-design engineering arm","framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-config-04-ed033b30.json","sourceId":"uc:UC-CONFIG-04","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art25-ccf26a83.json","targetId":"ctrl:gdpr:GDPR-Art25","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4b20e41bec7d4f4d8d7613344316f1c36b11efb9a68ae6b18216a95d1be1811b","properties":{"control_id":"A.5.21","coverage":"partial","delta":"propagation of security requirements through the ICT supply chain via contract control","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-07-c98d7242.json","sourceId":"uc:UC-TPRM-07","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-21-40b0d925.json","targetId":"ctrl:iso-27001:A.5.21","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4f39fe587592e6dffbfbbdaffc99e94518b1d19def1920a7401876018b252fe2","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-8-d3706b09.json","sourceId":"ctrl:iso-27001:A.8.8","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5a1cadd30ef153d96c37530c120af1562f4fc2e98f1b340e21fb987963c815f7","properties":{"control_id":"A.8.19","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-config-05-84d5ee43.json","sourceId":"uc:UC-CONFIG-05","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-19-44c22e39.json","targetId":"ctrl:iso-27001:A.8.19","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6211dca87613b36dc26a16c224980c7d5e044c31c777bf4c86c9880d1a51ee8e","properties":{"control_id":"A.5.10","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-10-2d5f0877.json","targetId":"ctrl:iso-27001:A.5.10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6245560e88a0b25a51c060ec56866eed4994290ee0d92752753fc75bd841b7e1","properties":{"control_id":"A.5.32","coverage":"partial","delta":"operational IPR safeguards - license/asset registers with usage-vs-entitlement enforcement, proof-of-license retention, and acquisition from authorized sources - beyond registering and periodically evaluating the obligation","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-24-fa96fe18.json","sourceId":"uc:UC-AUDIT-24","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-32-7342e3f4.json","targetId":"ctrl:iso-27001:A.5.32","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:62a6fd6b6e2a9e76fd2322f78498159ad83a219fdb36c5d6f7523a98e64315fd","properties":{"control_id":"B008","coverage":"partial","delta":"hardening of the model-serving and agent runtime environment, including model-artifact protection and isolation from other workloads","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b008-39c816b1.json","targetId":"ctrl:aiuc-1:B008","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:65364c502c601d992737a86ccb5ece989090bb03969c8d4658bd9fa45839eade","properties":{"control_id":"A.8.33","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-config-03-3a08a2b1.json","sourceId":"uc:UC-CONFIG-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-33-cabca252.json","targetId":"ctrl:iso-27001:A.8.33","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:66c476cbded0770a1dfb5dac88dbddc813fd47b5a6cffddb59a967f1f0fe2087","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai10-40479176.json","sourceId":"ctrl:cobit-2019:BAI10","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6955bdd8dc48a0d0ede2fae85bb4731d83dc0803edd79e3ba3236e1ecfe7c72f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-30-6a684665.json","sourceId":"ctrl:iso-27001:A.8.30","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6af614e2df6e6cbc6408a920bff22a8f313e53b22bf9fd40b97a28f4fb1e3822","properties":{"control_id":"AC-20","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-20-6e822026.json","targetId":"ctrl:nist-800-53:AC-20","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6fa8c61aa8f5bf102eca5de1145906d3c2b635e765a122d5fea40e943b36360a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-10-2bfc8971.json","sourceId":"ctrl:iso-27001:A.7.10","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7048bc38b1c19805455ed20fca10e5ab08ce34c3afa5cff4429f02cedf05f05e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-19-44c22e39.json","sourceId":"ctrl:iso-27001:A.8.19","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:752575973f408428ecdab2255da7065768c9873e1533285b323787a612c45118","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-ic-p12-233c8710.json","sourceId":"ctrl:coso-ic:P12","targetDetailPath":"/data/v1/records/std-coso-ic-3f80f565.json","targetId":"std:coso-ic","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7647e814defe233d67bf447de566e85cc21393edc103da90c9a15a326da809d8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-e011-56758692.json","sourceId":"ctrl:aiuc-1:E011","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7d0ab7dad539ee79842c33f9966a097879c272387bd0aaee9256013bcc6d95b7","properties":{"control_id":"CA-8","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-02-8366666b.json","sourceId":"uc:UC-VULN-02","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ca-8-bbc6c82f.json","targetId":"ctrl:nist-800-53:CA-8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7def629af2e63fd82808e5330d7a6291c876c04b5d6a94c9439d1d9e8229b592","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-10-2d5f0877.json","sourceId":"ctrl:iso-27001:A.5.10","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:80b5dcf1a0401185d2ebceb311894266c3b925724abab44029a60a3f07ae66d1","properties":{"control_id":"A.8.29","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-04-d07c87cf.json","sourceId":"uc:UC-VULN-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-29-e0df0522.json","targetId":"ctrl:iso-27001:A.8.29","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:81d44294f99278af7978ea2c1252664038b73ac319ebe9256bebcaf995fe82a1","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-eu-ai-act-aia-art15-c3704411.json","sourceId":"ctrl:eu-ai-act:AIA-Art15","targetDetailPath":"/data/v1/records/std-eu-ai-act-54986689.json","targetId":"std:eu-ai-act","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:84965314f57b1f964f26b51977ca58ae0531e7ad88e5a04a6527a95f2ad721f8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-20-6e822026.json","sourceId":"ctrl:nist-800-53:AC-20","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8fdc7830079a5918f12dfa65dd2161ce222fcb194b0dc79ac6ab41841a9a5717","properties":{"control_id":"BAI06","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","sourceId":"uc:UC-SDLC-07","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai06-306e8a70.json","targetId":"ctrl:cobit-2019:BAI06","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:96fe8cd5e6550663eb4ec5bf19b88679bf108221016937cf868e836905365c8f","properties":{"control_id":"BAI07","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","sourceId":"uc:UC-SDLC-07","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai07-dcabfa26.json","targetId":"ctrl:cobit-2019:BAI07","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:982ffd5bf47a09cb0d66592478e9216757aada63479fa0423b2afa1ff2452f3f","properties":{"control_id":"BAI05","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-09-659d0280.json","sourceId":"uc:UC-SDLC-09","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai05-782c2ba0.json","targetId":"ctrl:cobit-2019:BAI05","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:98948334f16c82e75fc7875acb9c6157cf1ad71bc9ad5f00b29cd6d8000c1963","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai06-306e8a70.json","sourceId":"ctrl:cobit-2019:BAI06","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:99c34bfb730ca7a75f3d0e684fa410c1bda9b1f8c62798c42121755d101d114e","properties":{"control_id":"A.8.7","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-05-5870fcee.json","sourceId":"uc:UC-VULN-05","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-7-99887761.json","targetId":"ctrl:iso-27001:A.8.7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9b1ac6bfa799e9a878a2f3298cc3d84973dc3ed7da85beabe618a4380720ef55","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai03-bfe681b0.json","sourceId":"ctrl:cobit-2019:BAI03","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9d5e344a30149135e006ecccf476eb173557ce440799713ad29392ae13c3c7b7","properties":{"control_id":"A.8.25","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-01-b3583fd1.json","sourceId":"uc:UC-SDLC-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-25-3cbe2191.json","targetId":"ctrl:iso-27001:A.8.25","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9fa3d3c91726a4a890c2543bd8ae26001b16207ec017301c6e58893cd622b8a6","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai09-09a008c3.json","sourceId":"ctrl:cobit-2019:BAI09","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a2a3c3598fb3e37e3c2d2c40ee861e78f371b126f8f59b460f207cc49b1ad9fa","properties":{"control_id":"A.8.8","coverage":"partial","delta":"also requires obtaining vulnerability intelligence and evaluating exposure","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-03-cc58f6a7.json","sourceId":"uc:UC-VULN-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-8-d3706b09.json","targetId":"ctrl:iso-27001:A.8.8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a4b2f502292f978777af5dfd48e8999c55e77d6f23ea481d1933266e011e2a12","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai08-9f5f3d72.json","sourceId":"ctrl:cobit-2019:BAI08","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a4b962f8681ae302dd3d263e2057be52d76ae3a42d983d3a9f7daf50642b8a4f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-21-5b64f0ec.json","sourceId":"ctrl:iso-27001:A.8.21","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a73ec3cd22801fc393e49ceaaaebeb68441349a625535ea5f13c226d0ef9b5ea","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-32-7342e3f4.json","sourceId":"ctrl:iso-27001:A.5.32","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a945420f1311deb2ede68743201f30e4c3b8977422c38ceae982e25b19d47deb","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-9-43947bba.json","sourceId":"ctrl:iso-27001:A.7.9","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a9c21cb9b25d0672e34ba3509ac1069d58338117d3fe68376e2e33f9616b19e6","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai07-dcabfa26.json","sourceId":"ctrl:cobit-2019:BAI07","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ad79ca3242cac5551158b9c9ff960685018e66075adf393b637d03e7c34308b8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-b008-39c816b1.json","sourceId":"ctrl:aiuc-1:B008","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:aecd717d6185bfe73df9e6b08b317c80a2a700620a5315a7d9f2548452e607d2","properties":{"control_id":"E011","coverage":"partial","delta":"a customer-facing record of the regions and sub-processors where AI inputs and outputs are processed and stored","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-config-10-921518b8.json","sourceId":"uc:UC-CONFIG-10","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-e011-56758692.json","targetId":"ctrl:aiuc-1:E011","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b2d12d84f6b7b23a587ee3058dd3cb7d236c00fa995c84821b0bdc4d8a445e93","properties":{"control_id":"A.8.26","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-03-5de4daf8.json","sourceId":"uc:UC-SDLC-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-26-34d8988d.json","targetId":"ctrl:iso-27001:A.8.26","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b2f6e5331ffae72e3a39ba2f03219e0b3d04438f8856ee7dc17f36d36f7de2dd","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-9-616c4c1b.json","sourceId":"ctrl:iso-27001:A.8.9","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b4899f7912335a7240c0671a7d3f47a9fbe675ab613f66e382e3146270615b93","properties":{"control_id":"A.7.14","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-14-5ada9a8e.json","targetId":"ctrl:iso-27001:A.7.14","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b746704844a32ce3da334aa3bb3c92c52a59c320118c0ce5d8e906cf943e8916","properties":{"control_id":"A.8.32","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-config-02-175d55b0.json","sourceId":"uc:UC-CONFIG-02","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-32-b855772a.json","targetId":"ctrl:iso-27001:A.8.32","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b78df392b933c68f3c14d3ef4c2af8faf28b2a88601ab2e6d22eda2aa8113e2b","properties":{"control_id":"A.8.30","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-10-3ac58852.json","sourceId":"uc:UC-SDLC-10","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-30-6a684665.json","targetId":"ctrl:iso-27001:A.8.30","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b7b3ceac0daac147fd82e8033c375b3cfbb55fab37fca4f509a85bfb003a4830","properties":{"control_id":"A.8.20","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-log-08-61745e12.json","sourceId":"uc:UC-LOG-08","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-20-68d4486b.json","targetId":"ctrl:iso-27001:A.8.20","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bf750d3c6442fa00e90c0f7f6c2b6ad46182baf74575d4b56bb9a668ff64f93b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-1-12f14999.json","sourceId":"ctrl:iso-27001:A.8.1","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c167e1277136936a9d4545736150b97fc15aa63218aa40c5de8daffcfc664e3b","properties":{"control_id":"A.8.31","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-config-03-3a08a2b1.json","sourceId":"uc:UC-CONFIG-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-31-eabf2a51.json","targetId":"ctrl:iso-27001:A.8.31","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d01f94392dc563be0aa2b00b6b75d9fc39ee97811b15eb3cf2774047f5b49b79","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-dora-dora-art45-bb72d2e3.json","sourceId":"ctrl:dora:DORA-Art45","targetDetailPath":"/data/v1/records/std-dora-95cf939d.json","targetId":"std:dora","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d76ebfe31f21c2186bd8d943cc9a6d3c0ec35cc97fd13308cabc92f979186c55","properties":{"control_id":"A.8.22","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-net-01-30bfdc5f.json","sourceId":"uc:UC-NET-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-22-be69b805.json","targetId":"ctrl:iso-27001:A.8.22","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dfbda93476c25cd552d1253bfc6e614f83807e71b80d04d3c61355f7d3b2f5c3","properties":{"control_id":"BAI02","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-03-5de4daf8.json","sourceId":"uc:UC-SDLC-03","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai02-80041b74.json","targetId":"ctrl:cobit-2019:BAI02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e0de50edad858ee64dbfa7c6b722b4a0ea059889b3d392b46762ddf19273bcf0","properties":{"control_id":"A.8.9","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-config-01-8f911a32.json","sourceId":"uc:UC-CONFIG-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-9-616c4c1b.json","targetId":"ctrl:iso-27001:A.8.9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e115412b6dbd6e8acfd6e03c6f5a8f3d855469e2439b614314f3c5731fa7e439","properties":{"control_id":"A.5.9","coverage":"partial","delta":"inventorying information (data) assets themselves, addressed by the data-inventory control","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-9-64706ee7.json","targetId":"ctrl:iso-27001:A.5.9","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e9fa5370e6d6ce54f4497643a6a0d97dfe8e051a981f49756dab4989842e6fd8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-31-eabf2a51.json","sourceId":"ctrl:iso-27001:A.8.31","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb4f44d97f08b10b4d8988ddd92feffde262f146c9d895c2b11f7766e58f875d","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-mea03-99c7dcca.json","sourceId":"ctrl:cobit-2019:MEA03","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb9b2fc276833be22e81f68e87785ccf8cb27bd7adccf57070cac1d600ea9e8d","properties":{"control_id":"A.8.27","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-27-a4a3784c.json","targetId":"ctrl:iso-27001:A.8.27","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ed31e96542f9f30cc5f593b4148416965c7b4d9c69400254d868b2673d57211b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-25-3cbe2191.json","sourceId":"ctrl:iso-27001:A.8.25","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f4913757b9a3f79e7cec28d3765d3acb63ca365f9150bfe794f91c4ecdd4fe6c","properties":{"control_id":"BAI08","coverage":"partial","delta":"enterprise-wide knowledge management extends beyond system documentation","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-08-29ce69df.json","sourceId":"uc:UC-SDLC-08","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai08-9f5f3d72.json","targetId":"ctrl:cobit-2019:BAI08","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f72c4c986f7ebc639fd56c06a35a787752152ccc5a7ef9964e6135a8250f5093","properties":{"control_id":"A.8.21","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-log-08-61745e12.json","sourceId":"uc:UC-LOG-08","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-21-5b64f0ec.json","targetId":"ctrl:iso-27001:A.8.21","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fc576a933f2542e942f21141470a9d706153d23d73f1834e71c92bc1d99baecc","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-22-be69b805.json","sourceId":"ctrl:iso-27001:A.8.22","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fc798f57020128c2304ced9e83b5e2bc542716be475a026d320e85ef491f566a","properties":{"control_id":"P12","coverage":"partial","delta":"COSO expects policies and procedures deploying all control activities, not only CM","framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-config-09-3da3afe2.json","sourceId":"uc:UC-CONFIG-09","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p12-233c8710.json","targetId":"ctrl:coso-ic:P12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ff6d62d55e995572524415f934cd53112d2645892288fd173516f0692dc389be","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai05-782c2ba0.json","sourceId":"ctrl:cobit-2019:BAI05","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"}],"schemaVersion":1,"scope":"topics","total":271}
