{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","contextIds":["ctrl:aiuc-1:A006","ctrl:aiuc-1:B001","ctrl:aiuc-1:B002","ctrl:aiuc-1:B004","ctrl:aiuc-1:B005","ctrl:aiuc-1:B006","ctrl:aiuc-1:B008","ctrl:aiuc-1:B010","ctrl:aiuc-1:C002","ctrl:aiuc-1:C010","ctrl:aiuc-1:C011","ctrl:aiuc-1:C012","ctrl:aiuc-1:D002","ctrl:aiuc-1:D003","ctrl:aiuc-1:D004","ctrl:aiuc-1:E006","ctrl:aiuc-1:E012","ctrl:aiuc-1:E013","ctrl:aiuc-1:E017","ctrl:ccpa:CCPA-1798.106","ctrl:cobit-2019:APO09","ctrl:cobit-2019:APO10","ctrl:cobit-2019:BAI01","ctrl:cobit-2019:BAI02","ctrl:cobit-2019:BAI03","ctrl:cobit-2019:BAI04","ctrl:cobit-2019:BAI05","ctrl:cobit-2019:BAI06","ctrl:cobit-2019:BAI07","ctrl:cobit-2019:BAI08","ctrl:cobit-2019:BAI09","ctrl:cobit-2019:BAI10","ctrl:cobit-2019:BAI11","ctrl:cobit-2019:DSS01","ctrl:cobit-2019:DSS02","ctrl:cobit-2019:DSS03","ctrl:coso-ic:P12","ctrl:dora:DORA-Art17-23","ctrl:dora:DORA-Art28-44","ctrl:dora:DORA-Art45"],"directIds":[],"kind":"bundle","metadata":"/assets/agent_metadata.5c7612c9c5b0b455.json","name":"Secure Development (SDLC) & Application Security","next":"/assets/agent_topics-secure-development-sdlc-application-security-2.24df4705bfea424b.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Prevent PII leakage","details":{"automation":"automated","control_category":"technical","control_id":"A006","control_type":"preventive","domains":["AI Governance","Data Protection & Privacy"],"framework":"aiuc-1","group":"Data & Privacy","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":4,"source_pages":null,"source_url":"https://www.aiuc-1.com/data-and-privacy/prevent-pii-leakage"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-a006-846858b8.html","id":"ctrl:aiuc-1:A006","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AA006","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/data-and-privacy/prevent-pii-leakage","title":"A006 — Prevent PII leakage","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-a006-846858b8.dc19d2405450a0b3.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Third-party testing of adversarial robustness","details":{"automation":"manual","control_category":"administrative","control_id":"B001","control_type":"preventive","domains":["AI Governance","Access Control & Identity Management","Secure Development (SDLC) & Application Security"],"framework":"aiuc-1","group":"Security","key_control":true,"requirement_frequency":"Every 3 months","requirement_status":"mandatory","risk_count":5,"source_pages":null,"source_url":"https://www.aiuc-1.com/security/test-adversarial-robustness"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-b001-19a54ee3.html","id":"ctrl:aiuc-1:B001","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AB001","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/security/test-adversarial-robustness","title":"B001 — Third-party testing of adversarial robustness","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-b001-19a54ee3.f6951418c6c04285.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Detect adversarial input","details":{"automation":"automated","control_category":"technical","control_id":"B002","control_type":"detective","domains":["AI Governance","Access Control & Identity Management","Secure Development (SDLC) & Application Security"],"framework":"aiuc-1","group":"Security","key_control":false,"requirement_frequency":"Every 3 months","requirement_status":"optional","risk_count":4,"source_pages":null,"source_url":"https://www.aiuc-1.com/security/detect-adversarial-input"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-b002-07a4b0e1.html","id":"ctrl:aiuc-1:B002","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AB002","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/security/detect-adversarial-input","title":"B002 — Detect adversarial input","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-b002-07a4b0e1.dc1c0aa05175aea1.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Prevent AI endpoint scraping","details":{"automation":"automated","control_category":"technical","control_id":"B004","control_type":"preventive","domains":["AI Governance","Access Control & Identity Management","Secure Development (SDLC) & Application Security"],"framework":"aiuc-1","group":"Security","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":4,"source_pages":null,"source_url":"https://www.aiuc-1.com/security/prevent-ai-endpoint-scraping"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-b004-d4ff3b14.html","id":"ctrl:aiuc-1:B004","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AB004","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/security/prevent-ai-endpoint-scraping","title":"B004 — Prevent AI endpoint scraping","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-b004-d4ff3b14.a9e4d50c6372d755.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"detective"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Implement real-time input filtering","details":{"automation":"automated","control_category":"technical","control_id":"B005","control_type":"detective","domains":["AI Governance","Access Control & Identity Management","Secure Development (SDLC) & Application Security"],"framework":"aiuc-1","group":"Security","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"optional","risk_count":4,"source_pages":null,"source_url":"https://www.aiuc-1.com/security/implement-real-time-input-filtering"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-b005-fe985c7b.html","id":"ctrl:aiuc-1:B005","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AB005","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/security/implement-real-time-input-filtering","title":"B005 — Implement real-time input filtering","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-b005-fe985c7b.4f92c99c324b08c4.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Prevent unauthorized AI agent actions","details":{"automation":"automated","control_category":"technical","control_id":"B006","control_type":"preventive","domains":["AI Governance","Access Control & Identity Management","Secure Development (SDLC) & Application Security"],"framework":"aiuc-1","group":"Security","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":4,"source_pages":null,"source_url":"https://www.aiuc-1.com/security/enforce-contextual-access-controls"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-b006-2951b397.html","id":"ctrl:aiuc-1:B006","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AB006","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/security/enforce-contextual-access-controls","title":"B006 — Prevent unauthorized AI agent actions","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-b006-2951b397.7297d90ecea628f6.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Protect AI system deployment environment","details":{"automation":"hybrid","control_category":"technical","control_id":"B008","control_type":"preventive","domains":["AI Governance","Access Control & Identity Management","Secure Development (SDLC) & Application Security"],"framework":"aiuc-1","group":"Security","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":8,"source_pages":null,"source_url":"https://www.aiuc-1.com/security/protect-model-deployment-environment"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-b008-39c816b1.html","id":"ctrl:aiuc-1:B008","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AB008","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/security/protect-model-deployment-environment","title":"B008 — Protect AI system deployment environment","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-b008-39c816b1.d20c1b777cbdcf3a.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Promote secure patterns in generated code","details":{"automation":"hybrid","control_category":"technical","control_id":"B010","control_type":"preventive","domains":["AI Governance","Access Control & Identity Management","Secure Development (SDLC) & Application Security"],"framework":"aiuc-1","group":"Security","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":2,"source_pages":null,"source_url":"https://www.aiuc-1.com/security/promote-secure-code-patterns"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-b010-a075f8e3.html","id":"ctrl:aiuc-1:B010","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AB010","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/security/promote-secure-code-patterns","title":"B010 — Promote secure patterns in generated code","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-b010-a075f8e3.25eccdcd936d65d0.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Conduct pre-deployment testing","details":{"automation":"hybrid","control_category":"administrative","control_id":"C002","control_type":"preventive","domains":["AI Governance"],"framework":"aiuc-1","group":"Safety","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":6,"source_pages":null,"source_url":"https://www.aiuc-1.com/safety/conduct-pre-deployment-testing"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-c002-6c739dcb.html","id":"ctrl:aiuc-1:C002","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AC002","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/safety/conduct-pre-deployment-testing","title":"C002 — Conduct pre-deployment testing","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-c002-6c739dcb.9f8944ee1bc83c9e.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Third-party testing for harmful outputs","details":{"automation":"manual","control_category":"administrative","control_id":"C010","control_type":"preventive","domains":["AI Governance"],"framework":"aiuc-1","group":"Safety","key_control":true,"requirement_frequency":"Every 3 months","requirement_status":"mandatory","risk_count":5,"source_pages":null,"source_url":"https://www.aiuc-1.com/safety/3rd-party-testing-for-harmful-outputs"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-c010-b0a758b4.html","id":"ctrl:aiuc-1:C010","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AC010","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/safety/3rd-party-testing-for-harmful-outputs","title":"C010 — Third-party testing for harmful outputs","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-c010-b0a758b4.1c43b9be128d3524.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Third-party testing for out-of-scope outputs","details":{"automation":"manual","control_category":"administrative","control_id":"C011","control_type":"preventive","domains":["AI Governance"],"framework":"aiuc-1","group":"Safety","key_control":true,"requirement_frequency":"Every 3 months","requirement_status":"mandatory","risk_count":5,"source_pages":null,"source_url":"https://www.aiuc-1.com/safety/3rd-party-testing-for-out-of-scope-outputs"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-c011-7889db41.html","id":"ctrl:aiuc-1:C011","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AC011","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/safety/3rd-party-testing-for-out-of-scope-outputs","title":"C011 — Third-party testing for out-of-scope outputs","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-c011-7889db41.be400fb756f735e6.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Third-party testing for customer-defined risk","details":{"automation":"manual","control_category":"administrative","control_id":"C012","control_type":"preventive","domains":["AI Governance"],"framework":"aiuc-1","group":"Safety","key_control":true,"requirement_frequency":"Every 3 months","requirement_status":"mandatory","risk_count":5,"source_pages":null,"source_url":"https://www.aiuc-1.com/safety/3rd-party-testing-for-other-risk"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-c012-783c55df.html","id":"ctrl:aiuc-1:C012","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AC012","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/safety/3rd-party-testing-for-other-risk","title":"C012 — Third-party testing for customer-defined risk","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-c012-783c55df.90373a20c285e27f.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Third-party testing for hallucinations","details":{"automation":"manual","control_category":"administrative","control_id":"D002","control_type":"preventive","domains":["AI Governance"],"framework":"aiuc-1","group":"Reliability","key_control":true,"requirement_frequency":"Every 3 months","requirement_status":"mandatory","risk_count":5,"source_pages":null,"source_url":"https://www.aiuc-1.com/reliability/3rd-party-testing-for-hallucinations"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-d002-34554b38.html","id":"ctrl:aiuc-1:D002","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AD002","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/reliability/3rd-party-testing-for-hallucinations","title":"D002 — Third-party testing for hallucinations","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-d002-34554b38.cd845fda29af2076.json"},{"attributes":{"category":"technical","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Restrict unsafe tool calls","details":{"automation":"automated","control_category":"technical","control_id":"D003","control_type":"preventive","domains":["AI Governance"],"framework":"aiuc-1","group":"Reliability","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":4,"source_pages":null,"source_url":"https://www.aiuc-1.com/reliability/restrict-unsafe-tool-calls"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-d003-9f8f52f3.html","id":"ctrl:aiuc-1:D003","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AD003","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/reliability/restrict-unsafe-tool-calls","title":"D003 — Restrict unsafe tool calls","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-d003-9f8f52f3.26f93da8aadce30a.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Third-party testing of tool calls","details":{"automation":"manual","control_category":"administrative","control_id":"D004","control_type":"preventive","domains":["AI Governance"],"framework":"aiuc-1","group":"Reliability","key_control":true,"requirement_frequency":"Every 3 months","requirement_status":"mandatory","risk_count":5,"source_pages":null,"source_url":"https://www.aiuc-1.com/reliability/3rd-party-testing-of-tool-calls"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-d004-21d4eeb4.html","id":"ctrl:aiuc-1:D004","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AD004","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/reliability/3rd-party-testing-of-tool-calls","title":"D004 — Third-party testing of tool calls","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-d004-21d4eeb4.7a3954e8387e3f1c.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Conduct vendor due diligence","details":{"automation":"manual","control_category":"administrative","control_id":"E006","control_type":"preventive","domains":["AI Governance","Governance, Policy & Oversight"],"framework":"aiuc-1","group":"Accountability","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"mandatory","risk_count":5,"source_pages":null,"source_url":"https://www.aiuc-1.com/accountability/conduct-vendor-due-diligence"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-e006-362f564d.html","id":"ctrl:aiuc-1:E006","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AE006","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/accountability/conduct-vendor-due-diligence","title":"E006 — Conduct vendor due diligence","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-e006-362f564d.11bc436f4b4c62cc.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Document regulatory compliance","details":{"automation":"manual","control_category":"administrative","control_id":"E012","control_type":"preventive","domains":["AI Governance","Governance, Policy & Oversight"],"framework":"aiuc-1","group":"Accountability","key_control":false,"requirement_frequency":"Every 6 months","requirement_status":"mandatory","risk_count":3,"source_pages":null,"source_url":"https://www.aiuc-1.com/accountability/document-regulatory-compliance"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-e012-78a3be53.html","id":"ctrl:aiuc-1:E012","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AE012","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/accountability/document-regulatory-compliance","title":"E012 — Document regulatory compliance","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-e012-78a3be53.10961e879e61170f.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Implement quality management system","details":{"automation":"manual","control_category":"administrative","control_id":"E013","control_type":"preventive","domains":["AI Governance","Governance, Policy & Oversight"],"framework":"aiuc-1","group":"Accountability","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"optional","risk_count":3,"source_pages":null,"source_url":"https://www.aiuc-1.com/accountability/implement-quality-management-system"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-e013-7efd0f38.html","id":"ctrl:aiuc-1:E013","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AE013","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/accountability/implement-quality-management-system","title":"E013 — Implement quality management system","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-e013-7efd0f38.389d202f1be575e4.json"},{"attributes":{"category":"administrative","framework":"aiuc-1","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/aiuc-1/","description":"Document system transparency policy","details":{"automation":"manual","control_category":"administrative","control_id":"E017","control_type":"preventive","domains":["AI Governance","Governance, Policy & Oversight"],"framework":"aiuc-1","group":"Accountability","key_control":false,"requirement_frequency":"Every 12 months","requirement_status":"optional","risk_count":4,"source_pages":null,"source_url":"https://www.aiuc-1.com/accountability/document-system-transparency-policy"},"direct":false,"htmlUrl":"/agents/records/ctrl-aiuc-1-e017-016942cc.html","id":"ctrl:aiuc-1:E017","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Aaiuc-1%3AE017","sourceIds":["aiuc-1"],"sourceUrl":"https://www.aiuc-1.com/accountability/document-system-transparency-policy","title":"E017 — Document system transparency policy","type":"control","url":"/assets/agent_record-ctrl-aiuc-1-e017-016942cc.9a7a70a575ad8c5f.json"},{"attributes":{"category":"administrative","framework":"ccpa","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/ccpa/","description":"Right to correct inaccurate personal information","details":{"automation":"manual","control_category":"administrative","control_id":"CCPA-1798.106","control_type":"corrective","domains":["Data Protection & Privacy","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"ccpa","group":"CCPA/CPRA (California Consumer Privacy)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-ccpa-ccpa-1798-106-35bf5a6c.html","id":"ctrl:ccpa:CCPA-1798.106","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Accpa%3ACCPA-1798.106","sourceIds":["ccpa"],"sourceUrl":null,"title":"CCPA-1798.106 — Right to correct inaccurate personal information","type":"control","url":"/assets/agent_record-ctrl-ccpa-ccpa-1798-106-35bf5a6c.2f0c18ceefcb681c.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Service Agreements","details":{"automation":"manual","control_category":"administrative","control_id":"APO09","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Human Resources / Personnel Security","Third-Party / Supply-Chain Risk","Asset Management & Inventory"],"framework":"cobit-2019","group":"Align, Plan and Organize","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-apo09-2d1f48e2.html","id":"ctrl:cobit-2019:APO09","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3AAPO09","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"APO09 — Managed Service Agreements","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-apo09-2d1f48e2.633991f774128f82.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Vendors","details":{"automation":"manual","control_category":"administrative","control_id":"APO10","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Human Resources / Personnel Security","Third-Party / Supply-Chain Risk","Asset Management & Inventory"],"framework":"cobit-2019","group":"Align, Plan and Organize","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-apo10-2c3cb0dc.html","id":"ctrl:cobit-2019:APO10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3AAPO10","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"APO10 — Managed Vendors","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-apo10-2c3cb0dc.c8d0cf0279298206.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Programs","details":{"automation":"manual","control_category":"administrative","control_id":"BAI01","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai01-12e2e132.html","id":"ctrl:cobit-2019:BAI01","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI01","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI01 — Managed Programs","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai01-12e2e132.1353387b555e069d.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Requirements Definition","details":{"automation":"manual","control_category":"administrative","control_id":"BAI02","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai02-80041b74.html","id":"ctrl:cobit-2019:BAI02","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI02","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI02 — Managed Requirements Definition","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai02-80041b74.811fa9609d081ff1.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Solutions Identification and Build","details":{"automation":"manual","control_category":"administrative","control_id":"BAI03","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai03-bfe681b0.html","id":"ctrl:cobit-2019:BAI03","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI03","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI03 — Managed Solutions Identification and Build","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai03-bfe681b0.bf603bc83f14527d.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Availability and Capacity","details":{"automation":"hybrid","control_category":"administrative","control_id":"BAI04","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai04-c6901e71.html","id":"ctrl:cobit-2019:BAI04","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI04","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI04 — Managed Availability and Capacity","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai04-c6901e71.0ebecd1d62e8c3f1.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Organizational Change","details":{"automation":"manual","control_category":"administrative","control_id":"BAI05","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai05-782c2ba0.html","id":"ctrl:cobit-2019:BAI05","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI05","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI05 — Managed Organizational Change","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai05-782c2ba0.00e720f1e24fc73a.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed IT Changes","details":{"automation":"hybrid","control_category":"administrative","control_id":"BAI06","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai06-306e8a70.html","id":"ctrl:cobit-2019:BAI06","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI06","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI06 — Managed IT Changes","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai06-306e8a70.e9d535a4b9c13753.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed IT Change Acceptance and Transitioning","details":{"automation":"manual","control_category":"administrative","control_id":"BAI07","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai07-dcabfa26.html","id":"ctrl:cobit-2019:BAI07","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI07","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI07 — Managed IT Change Acceptance and Transitioning","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai07-dcabfa26.a0ff637dbb16bcb5.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Knowledge","details":{"automation":"manual","control_category":"administrative","control_id":"BAI08","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai08-9f5f3d72.html","id":"ctrl:cobit-2019:BAI08","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI08","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI08 — Managed Knowledge","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai08-9f5f3d72.7270def696a140ff.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Assets","details":{"automation":"hybrid","control_category":"administrative","control_id":"BAI09","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai09-09a008c3.html","id":"ctrl:cobit-2019:BAI09","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI09","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI09 — Managed Assets","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai09-09a008c3.269925ad628c54e8.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Configuration","details":{"automation":"hybrid","control_category":"administrative","control_id":"BAI10","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":7,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai10-40479176.html","id":"ctrl:cobit-2019:BAI10","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI10","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI10 — Managed Configuration","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai10-40479176.0dd8cba1e3a97830.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Projects","details":{"automation":"manual","control_category":"administrative","control_id":"BAI11","control_type":"preventive","domains":["Secure Development (SDLC) & Application Security","Secure Configuration & Change Management","Asset Management & Inventory","Business Continuity & Disaster Recovery"],"framework":"cobit-2019","group":"Build, Acquire and Implement","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-bai11-fbe7d977.html","id":"ctrl:cobit-2019:BAI11","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ABAI11","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"BAI11 — Managed Projects","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-bai11-fbe7d977.10b2643ea035a1e1.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Operations","details":{"automation":"hybrid","control_category":"administrative","control_id":"DSS01","control_type":"preventive","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"cobit-2019","group":"Deliver, Service and Support","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-dss01-d3ff2961.html","id":"ctrl:cobit-2019:DSS01","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ADSS01","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"DSS01 — Managed Operations","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-dss01-d3ff2961.90fbf85675339668.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Service Requests and Incidents","details":{"automation":"hybrid","control_category":"administrative","control_id":"DSS02","control_type":"corrective","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"cobit-2019","group":"Deliver, Service and Support","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-dss02-af5bca5d.html","id":"ctrl:cobit-2019:DSS02","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ADSS02","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"DSS02 — Managed Service Requests and Incidents","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-dss02-af5bca5d.d9fabf94aa20dc7d.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/cobit-2019/","description":"Managed Problems","details":{"automation":"manual","control_category":"administrative","control_id":"DSS03","control_type":"corrective","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"cobit-2019","group":"Deliver, Service and Support","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-cobit-2019-dss03-2540740f.html","id":"ctrl:cobit-2019:DSS03","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acobit-2019%3ADSS03","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"DSS03 — Managed Problems","type":"control","url":"/assets/agent_record-ctrl-cobit-2019-dss03-2540740f.0983703d1904b1c5.json"},{"attributes":{"category":"administrative","framework":"coso-ic","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/coso-ic/","description":"The organization deploys control activities through policies that establish what is expected and procedures that put policies into action.","details":{"automation":"manual","control_category":"administrative","control_id":"P12","control_type":"preventive","domains":["AI Governance","Financial Reporting Controls (SOX)","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security"],"framework":"coso-ic","group":"Control Activities","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-coso-ic-p12-233c8710.html","id":"ctrl:coso-ic:P12","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Acoso-ic%3AP12","sourceIds":["coso-ic"],"sourceUrl":null,"title":"P12 — The organization deploys control activities through policies that establish what is expected and procedures that put policies into action.","type":"control","url":"/assets/agent_record-ctrl-coso-ic-p12-233c8710.67371e11c8053dff.json"},{"attributes":{"category":"administrative","framework":"dora","type":"corrective"},"canonicalUrl":"https://controlsmap.com/frameworks/dora/","description":"ICT-related incident management, classification and reporting","details":{"automation":"hybrid","control_category":"administrative","control_id":"DORA-Art17-23","control_type":"corrective","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Third-Party / Supply-Chain Risk","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"dora","group":"EU DORA (Digital Operational Resilience Act)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-dora-dora-art17-23-9aa7977f.html","id":"ctrl:dora:DORA-Art17-23","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Adora%3ADORA-Art17-23","sourceIds":["dora"],"sourceUrl":null,"title":"DORA-Art17-23 — ICT-related incident management, classification and reporting","type":"control","url":"/assets/agent_record-ctrl-dora-dora-art17-23-9aa7977f.313cf7638f5cfdb3.json"},{"attributes":{"category":"administrative","framework":"dora","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/dora/","description":"Managing of ICT third-party risk","details":{"automation":"manual","control_category":"administrative","control_id":"DORA-Art28-44","control_type":"preventive","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Third-Party / Supply-Chain Risk","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"dora","group":"EU DORA (Digital Operational Resilience Act)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-dora-dora-art28-44-d3e89c89.html","id":"ctrl:dora:DORA-Art28-44","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Adora%3ADORA-Art28-44","sourceIds":["dora"],"sourceUrl":null,"title":"DORA-Art28-44 — Managing of ICT third-party risk","type":"control","url":"/assets/agent_record-ctrl-dora-dora-art28-44-d3e89c89.a71563b64de05293.json"},{"attributes":{"category":"administrative","framework":"dora","type":"preventive"},"canonicalUrl":"https://controlsmap.com/frameworks/dora/","description":"Information and intelligence sharing arrangements","details":{"automation":"manual","control_category":"administrative","control_id":"DORA-Art45","control_type":"preventive","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Third-Party / Supply-Chain Risk","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"dora","group":"EU DORA (Digital Operational Resilience Act)","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"htmlUrl":"/agents/records/ctrl-dora-dora-art45-bb72d2e3.html","id":"ctrl:dora:DORA-Art45","mapUrl":"https://controlsmap.com/?v=1&node=ctrl%3Adora%3ADORA-Art45","sourceIds":["dora"],"sourceUrl":null,"title":"DORA-Art45 — Information and intelligence sharing arrangements","type":"control","url":"/assets/agent_record-ctrl-dora-dora-art45-bb72d2e3.3fc6e3ce80d93299.json"}],"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:02b6742c91fa0718e15194147640b7f574337534b53d4840d943c3f17c360c59","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-106-35bf5a6c.json","sourceId":"ctrl:ccpa:CCPA-1798.106","targetDetailPath":"/data/v1/records/std-ccpa-55f3fd20.json","targetId":"std:ccpa","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:030c847a1be8b9e26a68bc890c648c03d31e6d385bf1a1132c0be8f4cb1c9848","properties":{"control_id":"BAI01","coverage":"partial","delta":"BAI01 governs the enterprise programme/portfolio management practice; this development-scoped objective covers project-level planning and resourcing, not enterprise portfolio governance","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-02-c3b003c2.json","sourceId":"uc:UC-SDLC-02","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai01-12e2e132.json","targetId":"ctrl:cobit-2019:BAI01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:05f47708636fcc22888663483542bc3e8693875eea819fc13c46fbd1ba60f18f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-apo09-2d1f48e2.json","sourceId":"ctrl:cobit-2019:APO09","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0e08d2bd2b64738fdceb908cac4d8acbb4ffc89f70de4c75dbaa5c151721ed92","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-a006-846858b8.json","sourceId":"ctrl:aiuc-1:A006","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:12a9f0c66a8f67e68815d7b85bd3ea19fe7a31b0c571551b1da17d52629ce157","properties":{"control_id":"B010","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-25-21e48906.json","sourceId":"uc:UC-AI-25","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b010-a075f8e3.json","targetId":"ctrl:aiuc-1:B010","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:153916c8d4adaef1fddde7e44d7535399a5efac931c724be644ae20200e1f51d","properties":{"control_id":"CCPA-1798.106","coverage":"full","delta":null,"framework":"ccpa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"CCPA (2018) as amended by CPRA (2020)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-07-a6976e38.json","sourceId":"uc:UC-DATA-07","targetDetailPath":"/data/v1/records/ctrl-ccpa-ccpa-1798-106-35bf5a6c.json","targetId":"ctrl:ccpa:CCPA-1798.106","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:15a88c013f269a3472c9e13dcac70293ef79deacab09c42d2a942ceb7e66cf78","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-d003-9f8f52f3.json","sourceId":"ctrl:aiuc-1:D003","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1bb99a7220444665b11dad31e587befeb9ef3f26c3fb61bf4ac73c2b49cf1faa","properties":{"control_id":"C002","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-07-9c5c9573.json","sourceId":"uc:UC-AI-07","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-c002-6c739dcb.json","targetId":"ctrl:aiuc-1:C002","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1df7d03ef432f33e2aa5d7ac1451629578a6aa10389545ab9db5a521f3bbf50a","properties":{"control_id":"C010","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-21-8afd47db.json","sourceId":"uc:UC-AI-21","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-c010-b0a758b4.json","targetId":"ctrl:aiuc-1:C010","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1ebe8d4b78547cfd82fbcc2891be071626367e03eaf85d40e73f49495cd9dd48","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai02-80041b74.json","sourceId":"ctrl:cobit-2019:BAI02","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:20e4b2a31e5517b32fa223ea9b1b8fd79f1f9756c4fd2ee3519a688b1e5e002f","properties":{"control_id":"DSS02","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss02-af5bca5d.json","targetId":"ctrl:cobit-2019:DSS02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:266413b704059cefdeb68ba76808b5444e25095d835aa595a43d1476260b7d3e","properties":{"control_id":"BAI10","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-06-c1afc713.json","sourceId":"uc:UC-SDLC-06","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai10-40479176.json","targetId":"ctrl:cobit-2019:BAI10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2e1dd368ab61117184f962a4423da9347a8dc7bd50f9574314804ebded1af983","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-dora-dora-art28-44-d3e89c89.json","sourceId":"ctrl:dora:DORA-Art28-44","targetDetailPath":"/data/v1/records/std-dora-95cf939d.json","targetId":"std:dora","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2fa9ee745188901dc9cf334d826e8e52a294a06c63ae786f99df85acdb98780d","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-dss02-af5bca5d.json","sourceId":"ctrl:cobit-2019:DSS02","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:35eebd189f1575ee338fadccdde6be2f9eded242acad4ddcb3aa02c74807db27","properties":{"control_id":"BAI09","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-12-08ce2fc7.json","sourceId":"uc:UC-SDLC-12","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai09-09a008c3.json","targetId":"ctrl:cobit-2019:BAI09","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3725ab082d6da8f966bc8172699871ad9290c976ed4a2cb8b98b5400c81d7929","properties":{"control_id":"C012","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-21-8afd47db.json","sourceId":"uc:UC-AI-21","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-c012-783c55df.json","targetId":"ctrl:aiuc-1:C012","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:42509eb5656a89b1a92a9c36f3a2a4cdefa1a038aa8cc37f1f6b3d0b23eeb1fe","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-c012-783c55df.json","sourceId":"ctrl:aiuc-1:C012","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:435470550375d418dcc629b659104f189e5fcbbef8cdb77b62204259ad3388e1","properties":{"control_id":"DORA-Art45","coverage":"full","delta":null,"framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-16-462251f1.json","sourceId":"uc:UC-BCDR-16","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art45-bb72d2e3.json","targetId":"ctrl:dora:DORA-Art45","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:494f71c171b62c71568247a14a50ed91f12978cf48211592b92b04d4f030328e","properties":{"control_id":"BAI03","coverage":"partial","delta":"full solution build, component, and maintenance life cycle satisfied by companion controls","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai03-bfe681b0.json","targetId":"ctrl:cobit-2019:BAI03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4f4bfb919d761c9352da8a35038bb54e93595b16f4e9d3163a8df47218198b62","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-c002-6c739dcb.json","sourceId":"ctrl:aiuc-1:C002","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:512ba21439e87bc291748f791f63165c51c302598232ea229c29542a3578a201","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-dss03-2540740f.json","sourceId":"ctrl:cobit-2019:DSS03","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:54a5127b09fa0df51fdec8c2d52d749eb8f7b18dcdc92569ca6cf4f78c2bd536","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-b001-19a54ee3.json","sourceId":"ctrl:aiuc-1:B001","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:62a6fd6b6e2a9e76fd2322f78498159ad83a219fdb36c5d6f7523a98e64315fd","properties":{"control_id":"B008","coverage":"partial","delta":"hardening of the model-serving and agent runtime environment, including model-artifact protection and isolation from other workloads","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-04-ee9d76b1.json","sourceId":"uc:UC-SDLC-04","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b008-39c816b1.json","targetId":"ctrl:aiuc-1:B008","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:66c476cbded0770a1dfb5dac88dbddc813fd47b5a6cffddb59a967f1f0fe2087","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai10-40479176.json","sourceId":"ctrl:cobit-2019:BAI10","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:687aade0ed345b958e16046bbe0bcd893b874ad9fafd1bb20a1d02d2f1d37595","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai11-fbe7d977.json","sourceId":"ctrl:cobit-2019:BAI11","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6a23db00aa832f70449f5331387a49a9848a48c33ed9aec1c9cbbd1cfd41d482","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai04-c6901e71.json","sourceId":"ctrl:cobit-2019:BAI04","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6cd89c31a0f6722453e9f1cb4ee69e4fdb4992f60f3243d03259b9058b5738c2","properties":{"control_id":"DSS01","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-12-0d9cc358.json","sourceId":"uc:UC-BCDR-12","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss01-d3ff2961.json","targetId":"ctrl:cobit-2019:DSS01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:72b94ed91e964541cc87bf386c4b6994337ba2ac851d16d3f3454cfd9b8d8eb3","properties":{"control_id":"D002","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-21-8afd47db.json","sourceId":"uc:UC-AI-21","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-d002-34554b38.json","targetId":"ctrl:aiuc-1:D002","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7378e9eab62be8ba3d1a1ed5bd35f653d390c7165684821983a39c6e739cf851","properties":{"control_id":"C011","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-21-8afd47db.json","sourceId":"uc:UC-AI-21","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-c011-7889db41.json","targetId":"ctrl:aiuc-1:C011","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:752575973f408428ecdab2255da7065768c9873e1533285b323787a612c45118","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-ic-p12-233c8710.json","sourceId":"ctrl:coso-ic:P12","targetDetailPath":"/data/v1/records/std-coso-ic-3f80f565.json","targetId":"std:coso-ic","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7677aeab7f884ba8b21cc4945d4354d344a58e19089c4d325a668392b0e90983","properties":{"control_id":"B006","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b006-2951b397.json","targetId":"ctrl:aiuc-1:B006","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:771fe71b653da797589e3eeb3d84a995ac2416455b1e8170bcd03ca056f8d16e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-d004-21d4eeb4.json","sourceId":"ctrl:aiuc-1:D004","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7fe14f045eb5b989ed2b172e29123795c887a077790aec281603ac0cb5b7b76a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-c010-b0a758b4.json","sourceId":"ctrl:aiuc-1:C010","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:82c78b51e755401f6ce93aa7d9f4f97112d5a31cc8132b148c05aa94938077ac","properties":{"control_id":"E013","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-24-066ea393.json","sourceId":"uc:UC-AI-24","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-e013-7efd0f38.json","targetId":"ctrl:aiuc-1:E013","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8b9de4df2b9b11f4758d16caba3a14418486d52562080438d56995febeaf4511","properties":{"control_id":"DORA-Art17-23","coverage":"partial","delta":"major-incident report clocks: initial 24h, intermediate 72h, final 1 month","framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art17-23-9aa7977f.json","targetId":"ctrl:dora:DORA-Art17-23","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8fdc7830079a5918f12dfa65dd2161ce222fcb194b0dc79ac6ab41841a9a5717","properties":{"control_id":"BAI06","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","sourceId":"uc:UC-SDLC-07","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai06-306e8a70.json","targetId":"ctrl:cobit-2019:BAI06","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:908c341aa078ce102be83a656c1dbff4928a9841491d3385d0d228153e5925dc","properties":{"control_id":"B005","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b005-fe985c7b.json","targetId":"ctrl:aiuc-1:B005","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:94968332499f1103f173cd77196d50bc0dcff5ac97d9906f1d4138683c245e28","properties":{"control_id":"BAI11","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-02-c3b003c2.json","sourceId":"uc:UC-SDLC-02","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai11-fbe7d977.json","targetId":"ctrl:cobit-2019:BAI11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:96f2fb180f84f99fb86941c3b49202eb0caef57d3105f6680d156665adeddebd","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-dss01-d3ff2961.json","sourceId":"ctrl:cobit-2019:DSS01","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:96fe8cd5e6550663eb4ec5bf19b88679bf108221016937cf868e836905365c8f","properties":{"control_id":"BAI07","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-07-22470d8b.json","sourceId":"uc:UC-SDLC-07","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai07-dcabfa26.json","targetId":"ctrl:cobit-2019:BAI07","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:982ffd5bf47a09cb0d66592478e9216757aada63479fa0423b2afa1ff2452f3f","properties":{"control_id":"BAI05","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-09-659d0280.json","sourceId":"uc:UC-SDLC-09","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai05-782c2ba0.json","targetId":"ctrl:cobit-2019:BAI05","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:98948334f16c82e75fc7875acb9c6157cf1ad71bc9ad5f00b29cd6d8000c1963","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai06-306e8a70.json","sourceId":"ctrl:cobit-2019:BAI06","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9a6fbed9e489613a8371aa786123991431f383218b1fad7b83994f3b1fa9b4fe","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai01-12e2e132.json","sourceId":"ctrl:cobit-2019:BAI01","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9b1a000fb0bc87b17f9c36c3bac7b6635fafd307d5e9101ecb04b57d5c2f6904","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-b006-2951b397.json","sourceId":"ctrl:aiuc-1:B006","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9b1ac6bfa799e9a878a2f3298cc3d84973dc3ed7da85beabe618a4380720ef55","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai03-bfe681b0.json","sourceId":"ctrl:cobit-2019:BAI03","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9f229e45003f2c7c825f7932294437466bf8be9e39c6c4ab0bcb25d8dc6b2192","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-dora-dora-art17-23-9aa7977f.json","sourceId":"ctrl:dora:DORA-Art17-23","targetDetailPath":"/data/v1/records/std-dora-95cf939d.json","targetId":"std:dora","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9fa3d3c91726a4a890c2543bd8ae26001b16207ec017301c6e58893cd622b8a6","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai09-09a008c3.json","sourceId":"ctrl:cobit-2019:BAI09","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a40ea91da42c62c6eacc53e2655a44e95b18b26a6ecc50c2554ac27c8c221976","properties":{"control_id":"E017","coverage":"partial","delta":"external transparency artifacts (model cards, datasheets, AI bill of materials) and a shared-responsibility statement distributed under a documented sharing policy","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-06-f47eedcb.json","sourceId":"uc:UC-AI-06","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-e017-016942cc.json","targetId":"ctrl:aiuc-1:E017","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a4b2f502292f978777af5dfd48e8999c55e77d6f23ea481d1933266e011e2a12","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai08-9f5f3d72.json","sourceId":"ctrl:cobit-2019:BAI08","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a74af9c3e6f125055de8d642a9daf7c64db8af1b078ca424106bf9353a63b6c0","properties":{"control_id":"BAI04","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-13-ae800997.json","sourceId":"uc:UC-SDLC-13","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai04-c6901e71.json","targetId":"ctrl:cobit-2019:BAI04","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a9c21cb9b25d0672e34ba3509ac1069d58338117d3fe68376e2e33f9616b19e6","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai07-dcabfa26.json","sourceId":"ctrl:cobit-2019:BAI07","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ad79ca3242cac5551158b9c9ff960685018e66075adf393b637d03e7c34308b8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-b008-39c816b1.json","sourceId":"ctrl:aiuc-1:B008","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b48d208fc579b8bfaf3f263db5da6c421457ede838fd19c511096175349f2716","properties":{"control_id":"APO10","coverage":"partial","delta":"day-to-day vendor performance monitoring and contract administration","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-apo10-2c3cb0dc.json","targetId":"ctrl:cobit-2019:APO10","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b49441ad04e7bb2572f9ca20f5e87f347a22f75d23a7969d40c00117e61d6d09","properties":{"control_id":"D004","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-21-8afd47db.json","sourceId":"uc:UC-AI-21","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-d004-21d4eeb4.json","targetId":"ctrl:aiuc-1:D004","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bbb58faf8b3bbc3d66ef9d7bdeb1609b34fe95674799e8fafe7397a3eb61191b","properties":{"control_id":"D003","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-19-535f3660.json","sourceId":"uc:UC-AI-19","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-d003-9f8f52f3.json","targetId":"ctrl:aiuc-1:D003","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bc558ad8ff092d5a9e10eae1b515809838d780083b7ba00c51f9a09147dac950","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-e012-78a3be53.json","sourceId":"ctrl:aiuc-1:E012","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bfb7de3a8015b3a23a00a22565f5ec4ed0ddcdd12489f4bb54574cd8ddbc7472","properties":{"control_id":"DSS03","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss03-2540740f.json","targetId":"ctrl:cobit-2019:DSS03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c3af86201b362726dcf731b480743ed527971d2ee9164ddbdda693ec766a6961","properties":{"control_id":"E012","coverage":"partial","delta":"semiannual documentation of the AI system's regulatory compliance posture and obligations register shared with customers","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-13-2ce71d80.json","sourceId":"uc:UC-AI-13","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-e012-78a3be53.json","targetId":"ctrl:aiuc-1:E012","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c783b550d3306227ac7538c829191604618ac82bd4c07c50f23ebdf9d0ceb7bf","properties":{"control_id":"A006","coverage":"partial","delta":"personal-data leakage through AI outputs and logs, requiring output-time redaction and log scrubbing in addition to stored-data pseudonymization","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-data-12-c5a5999a.json","sourceId":"uc:UC-DATA-12","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-a006-846858b8.json","targetId":"ctrl:aiuc-1:A006","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cac87c52f8cad781925ff1df93d3ecdcadc88de1e2481e2c5f6ec35ca0f68006","properties":{"control_id":"B004","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b004-d4ff3b14.json","targetId":"ctrl:aiuc-1:B004","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d01f94392dc563be0aa2b00b6b75d9fc39ee97811b15eb3cf2774047f5b49b79","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-dora-dora-art45-bb72d2e3.json","sourceId":"ctrl:dora:DORA-Art45","targetDetailPath":"/data/v1/records/std-dora-95cf939d.json","targetId":"std:dora","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d12810bb743c19ee31493be295824f2014ba01c0b4c01ccb177620aa79dd0909","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-b005-fe985c7b.json","sourceId":"ctrl:aiuc-1:B005","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d30ef7fd2bbb90d2d22640fe778b901d09a3b65df04eb887c2b165df9dec0ab5","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-e006-362f564d.json","sourceId":"ctrl:aiuc-1:E006","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d48739629f27ebf74e1abf8e7ac546403e3835cefc31839403687da5212a0e56","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-apo10-2c3cb0dc.json","sourceId":"ctrl:cobit-2019:APO10","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dadba8095e99ffd7e92198bac506ab1dd4ad19cf0bb742d44e096f3eba524948","properties":{"control_id":"E006","coverage":"partial","delta":"assess foundation and upstream model providers against explicit data-handling, PII-control, security, and compliance criteria, and retain the due-diligence evidence","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-14-cc67739e.json","sourceId":"uc:UC-AI-14","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-e006-362f564d.json","targetId":"ctrl:aiuc-1:E006","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ddc52a3e4e143989b6eafea19376f24a04235bec1d452011589e6ebfc946cb37","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-d002-34554b38.json","sourceId":"ctrl:aiuc-1:D002","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dfbda93476c25cd552d1253bfc6e614f83807e71b80d04d3c61355f7d3b2f5c3","properties":{"control_id":"BAI02","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-03-5de4daf8.json","sourceId":"uc:UC-SDLC-03","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai02-80041b74.json","targetId":"ctrl:cobit-2019:BAI02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dfe4a2f352199a3a665ddddedaf3a66dee1ff1c8687930b9b84f4439e5433a9a","properties":{"control_id":"B002","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-18-f15ac93a.json","sourceId":"uc:UC-AI-18","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b002-07a4b0e1.json","targetId":"ctrl:aiuc-1:B002","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e317a50a1f93d9c972822f8bf753183654e8add73e9e71d070892ad169295c57","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-b002-07a4b0e1.json","sourceId":"ctrl:aiuc-1:B002","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e606dc337059883eca825fc58e55c1db8da105553e224d4723b18417ca8583ac","properties":{"control_id":"B001","coverage":"full","delta":null,"framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-ai-21-8afd47db.json","sourceId":"uc:UC-AI-21","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b001-19a54ee3.json","targetId":"ctrl:aiuc-1:B001","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb0ed37196560f352a362b415b0bec4f7d604169244d4e8fe9f149661b959caf","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-c011-7889db41.json","sourceId":"ctrl:aiuc-1:C011","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eb8ae9550dcdacfecbd0859c5e133b80925bd0724b8cfc9d5c03f7b8194b1bd5","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-b004-d4ff3b14.json","sourceId":"ctrl:aiuc-1:B004","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ef3f77091676a78388c875f348d356433f3f19fbe373bdfcbfd2bf3d21e9db45","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-e013-7efd0f38.json","sourceId":"ctrl:aiuc-1:E013","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f2e2e7b72bc628ac1dc26cf6544d63f62633d9a1276598c3474fe2e52c916f16","properties":{"control_id":"DORA-Art28-44","coverage":"partial","delta":"DORA-specific regulator obligations (register of information format, competent-authority/Lead Overseer interactions) beyond the general third-party program","framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art28-44-d3e89c89.json","targetId":"ctrl:dora:DORA-Art28-44","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f4913757b9a3f79e7cec28d3765d3acb63ca365f9150bfe794f91c4ecdd4fe6c","properties":{"control_id":"BAI08","coverage":"partial","delta":"enterprise-wide knowledge management extends beyond system documentation","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-sdlc-08-29ce69df.json","sourceId":"uc:UC-SDLC-08","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-bai08-9f5f3d72.json","targetId":"ctrl:cobit-2019:BAI08","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f6213ce4eca6e0a05539835ccc809e3e380f5d6ee08b389bfc2a865522fd173a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-e017-016942cc.json","sourceId":"ctrl:aiuc-1:E017","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f8a2556afe5a96f4cc08e342a67e68e9c357271d761707ea878ddf981cc88075","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-aiuc-1-b010-a075f8e3.json","sourceId":"ctrl:aiuc-1:B010","targetDetailPath":"/data/v1/records/std-aiuc-1-d2a8b650.json","targetId":"std:aiuc-1","type":"belongs_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fa1e03375b19113343f4dead8c7384d2ce6473a62a0177095daa5a8303d69ee2","properties":{"control_id":"APO09","coverage":"partial","delta":"service catalog definition and SLA lifecycle management","framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-apo09-2d1f48e2.json","targetId":"ctrl:cobit-2019:APO09","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fc798f57020128c2304ced9e83b5e2bc542716be475a026d320e85ef491f566a","properties":{"control_id":"P12","coverage":"partial","delta":"COSO expects policies and procedures deploying all control activities, not only CM","framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-config-09-3da3afe2.json","sourceId":"uc:UC-CONFIG-09","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p12-233c8710.json","targetId":"ctrl:coso-ic:P12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ff6d62d55e995572524415f934cd53112d2645892288fd173516f0692dc389be","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-bai05-782c2ba0.json","sourceId":"ctrl:cobit-2019:BAI05","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"}],"schemaVersion":1,"scope":"topics","total":423}
