{"defaults":{"detailNodeId":null,"filters":{"framework":["aiuc-1","ccpa","cobit-2019","coso-erm","coso-ic","dora","eu-ai-act","gdpr","hipaa","iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-27001","iso-31000","iso-42001","nis2","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"risk.category":["ai_governance","business_continuity","compliance_regulatory","cyber_security","esg","financial","financial_reporting","operational","people_hr","privacy","reputational","strategic","third_party"],"risk.domain":["AI Governance","Access Control & Identity Management","Asset Management & Inventory","Awareness & Training","Business Continuity & Disaster Recovery","Compliance, Audit & Assurance","Cryptography & Key Management","Data Protection & Privacy","Financial Reporting Controls (SOX)","Governance, Policy & Oversight","Human Resources / Personnel Security","Incident Management & Response","Logging, Monitoring & Detection","Network & Communications Security","Physical & Environmental Security","Risk Assessment & Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Third-Party / Supply-Chain Risk","Vulnerability & Patch Management"],"risk.rating":["critical","high","low","medium"],"risk.taxonomy":["basel-operational-risk","coso-erm-risk","enterprise-risk","eu-ai-act-risk","iso-23894-ai-risk","iso-27005-threat","iso-27005-vulnerability","nist-800-30-threat-event","nist-800-30-threat-source","nist-ai-rmf-risk","nist-privacy-risk","owasp-llm-top10-2025","sox-rmm-assertion"],"source.authority":["framework","guidance","mandatory"],"uc.category":["administrative","physical","technical"],"uc.domain":["AI Governance","Access Control & Identity Management","Asset Management & Inventory","Awareness & Training","Business Continuity & Disaster Recovery","Compliance, Audit & Assurance","Cryptography & Key Management","Data Protection & Privacy","Financial Reporting Controls (SOX)","Governance, Policy & Oversight","Human Resources / Personnel Security","Incident Management & Response","Logging, Monitoring & Detection","Network & Communications Security","Physical & Environmental Security","Risk Assessment & Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Third-Party / Supply-Chain Risk","Vulnerability & Patch Management"],"uc.type":["corrective","detective","preventive"],"workflow.department":["ai-governance","compliance-legal","executive","facilities","finance","hr","internal-audit","it","operations","privacy","procurement","risk-management"],"workflow.domain":["audit","business","controls","grc","reg","sox"],"workflow.line":["assure","monitor","operate","__null__"]},"q":""},"examples":[{"id":"aiuc","label":"AIUC-1 scope","url":"https://controlsmap.com/?v=1&framework=aiuc-1"},{"id":"aiuc-requirement","label":"AIUC-1 E013","url":"https://controlsmap.com/?v=1&framework=aiuc-1&node=ctrl%3Aaiuc-1%3AE013"},{"id":"high-risk","label":"High and critical risks","url":"https://controlsmap.com/?v=1&risk.rating=high&risk.rating=critical"},{"id":"assurance","label":"Assurance workflows","url":"https://controlsmap.com/?v=1&workflow.line=assure"},{"id":"hr","label":"HR workflows","url":"https://controlsmap.com/?v=1&workflow.department=hr"}],"fields":[{"field":"category","hasNull":false,"key":"framework","label":"Framework","options":[{"label":"aiuc-1","value":"aiuc-1"},{"label":"ccpa","value":"ccpa"},{"label":"cobit-2019","value":"cobit-2019"},{"label":"coso-erm","value":"coso-erm"},{"label":"coso-ic","value":"coso-ic"},{"label":"dora","value":"dora"},{"label":"eu-ai-act","value":"eu-ai-act"},{"label":"gdpr","value":"gdpr"},{"label":"hipaa","value":"hipaa"},{"label":"iia-2024","value":"iia-2024"},{"label":"iia-pos-2026-erm","value":"iia-pos-2026-erm"},{"label":"iia-pos-2026-three-lines","value":"iia-pos-2026-three-lines"},{"label":"iso-27001","value":"iso-27001"},{"label":"iso-31000","value":"iso-31000"},{"label":"iso-42001","value":"iso-42001"},{"label":"nis2","value":"nis2"},{"label":"nist-800-53","value":"nist-800-53"},{"label":"nist-ai-agent-identity","value":"nist-ai-agent-identity"},{"label":"nist-ai-tevv-athlon","value":"nist-ai-tevv-athlon"},{"label":"nist-csf-2","value":"nist-csf-2"},{"label":"nydfs-500","value":"nydfs-500"},{"label":"pci-dss","value":"pci-dss"},{"label":"soc1","value":"soc1"},{"label":"soc2","value":"soc2"},{"label":"sox","value":"sox"}],"type":"standard"},{"field":"authority","hasNull":false,"key":"source.authority","label":"Authority","options":[{"label":"framework","value":"framework"},{"label":"guidance","value":"guidance"},{"label":"mandatory","value":"mandatory"}],"type":"standard"},{"field":"domain","hasNull":false,"key":"uc.domain","label":"Domain","options":[{"label":"AI Governance","value":"AI Governance"},{"label":"Access Control & Identity Management","value":"Access Control & Identity Management"},{"label":"Asset Management & Inventory","value":"Asset Management & Inventory"},{"label":"Awareness & Training","value":"Awareness & Training"},{"label":"Business Continuity & Disaster Recovery","value":"Business Continuity & Disaster Recovery"},{"label":"Compliance, Audit & Assurance","value":"Compliance, Audit & Assurance"},{"label":"Cryptography & Key Management","value":"Cryptography & Key Management"},{"label":"Data Protection & Privacy","value":"Data Protection & Privacy"},{"label":"Financial Reporting Controls (SOX)","value":"Financial Reporting Controls (SOX)"},{"label":"Governance, Policy & Oversight","value":"Governance, Policy & Oversight"},{"label":"Human Resources / Personnel Security","value":"Human Resources / Personnel Security"},{"label":"Incident Management & Response","value":"Incident Management & Response"},{"label":"Logging, Monitoring & Detection","value":"Logging, Monitoring & Detection"},{"label":"Network & Communications Security","value":"Network & Communications Security"},{"label":"Physical & Environmental Security","value":"Physical & Environmental Security"},{"label":"Risk Assessment & Management","value":"Risk Assessment & Management"},{"label":"Secure Configuration & Change Management","value":"Secure Configuration & Change Management"},{"label":"Secure Development (SDLC) & Application Security","value":"Secure Development (SDLC) & Application Security"},{"label":"Third-Party / Supply-Chain Risk","value":"Third-Party / Supply-Chain Risk"},{"label":"Vulnerability & Patch Management","value":"Vulnerability & Patch Management"}],"type":"unified"},{"field":"type","hasNull":false,"key":"uc.type","label":"Control type","options":[{"label":"corrective","value":"corrective"},{"label":"detective","value":"detective"},{"label":"preventive","value":"preventive"}],"type":"unified"},{"field":"category","hasNull":false,"key":"uc.category","label":"Control category","options":[{"label":"administrative","value":"administrative"},{"label":"physical","value":"physical"},{"label":"technical","value":"technical"}],"type":"unified"},{"field":"domain","hasNull":false,"key":"workflow.domain","label":"Area","options":[{"label":"audit","value":"audit"},{"label":"business","value":"business"},{"label":"controls","value":"controls"},{"label":"grc","value":"grc"},{"label":"reg","value":"reg"},{"label":"sox","value":"sox"}],"type":"workflow"},{"field":"department","hasNull":false,"key":"workflow.department","label":"Owning department","options":[{"label":"AI Governance","value":"ai-governance"},{"label":"Compliance & Legal","value":"compliance-legal"},{"label":"Executive","value":"executive"},{"label":"Facilities","value":"facilities"},{"label":"Finance","value":"finance"},{"label":"HR","value":"hr"},{"label":"Internal Audit","value":"internal-audit"},{"label":"IT","value":"it"},{"label":"Business Operations","value":"operations"},{"label":"Privacy","value":"privacy"},{"label":"Procurement","value":"procurement"},{"label":"Risk Management","value":"risk-management"}],"type":"workflow"},{"field":"lineOfDefense","hasNull":true,"key":"workflow.line","label":"Line of defense","options":[{"label":"assure","value":"assure"},{"label":"monitor","value":"monitor"},{"label":"operate","value":"operate"},{"label":"(unmapped)","value":"__null__"}],"type":"workflow"},{"field":"category","hasNull":false,"key":"risk.category","label":"Category","options":[{"label":"ai_governance","value":"ai_governance"},{"label":"business_continuity","value":"business_continuity"},{"label":"compliance_regulatory","value":"compliance_regulatory"},{"label":"cyber_security","value":"cyber_security"},{"label":"esg","value":"esg"},{"label":"financial","value":"financial"},{"label":"financial_reporting","value":"financial_reporting"},{"label":"operational","value":"operational"},{"label":"people_hr","value":"people_hr"},{"label":"privacy","value":"privacy"},{"label":"reputational","value":"reputational"},{"label":"strategic","value":"strategic"},{"label":"third_party","value":"third_party"}],"type":"risk"},{"field":"domain","hasNull":false,"key":"risk.domain","label":"Control domain","options":[{"label":"AI Governance","value":"AI Governance"},{"label":"Access Control & Identity Management","value":"Access Control & Identity Management"},{"label":"Asset Management & Inventory","value":"Asset Management & Inventory"},{"label":"Awareness & Training","value":"Awareness & Training"},{"label":"Business Continuity & Disaster Recovery","value":"Business Continuity & Disaster Recovery"},{"label":"Compliance, Audit & Assurance","value":"Compliance, Audit & Assurance"},{"label":"Cryptography & Key Management","value":"Cryptography & Key Management"},{"label":"Data Protection & Privacy","value":"Data Protection & Privacy"},{"label":"Financial Reporting Controls (SOX)","value":"Financial Reporting Controls (SOX)"},{"label":"Governance, Policy & Oversight","value":"Governance, Policy & Oversight"},{"label":"Human Resources / Personnel Security","value":"Human Resources / Personnel Security"},{"label":"Incident Management & Response","value":"Incident Management & Response"},{"label":"Logging, Monitoring & Detection","value":"Logging, Monitoring & Detection"},{"label":"Network & Communications Security","value":"Network & Communications Security"},{"label":"Physical & Environmental Security","value":"Physical & Environmental Security"},{"label":"Risk Assessment & Management","value":"Risk Assessment & Management"},{"label":"Secure Configuration & Change Management","value":"Secure Configuration & Change Management"},{"label":"Secure Development (SDLC) & Application Security","value":"Secure Development (SDLC) & Application Security"},{"label":"Third-Party / Supply-Chain Risk","value":"Third-Party / Supply-Chain Risk"},{"label":"Vulnerability & Patch Management","value":"Vulnerability & Patch Management"}],"type":"risk"},{"field":"taxonomy","hasNull":false,"key":"risk.taxonomy","label":"Taxonomy","options":[{"label":"basel-operational-risk","value":"basel-operational-risk"},{"label":"coso-erm-risk","value":"coso-erm-risk"},{"label":"enterprise-risk","value":"enterprise-risk"},{"label":"eu-ai-act-risk","value":"eu-ai-act-risk"},{"label":"iso-23894-ai-risk","value":"iso-23894-ai-risk"},{"label":"iso-27005-threat","value":"iso-27005-threat"},{"label":"iso-27005-vulnerability","value":"iso-27005-vulnerability"},{"label":"nist-800-30-threat-event","value":"nist-800-30-threat-event"},{"label":"nist-800-30-threat-source","value":"nist-800-30-threat-source"},{"label":"nist-ai-rmf-risk","value":"nist-ai-rmf-risk"},{"label":"nist-privacy-risk","value":"nist-privacy-risk"},{"label":"owasp-llm-top10-2025","value":"owasp-llm-top10-2025"},{"label":"sox-rmm-assertion","value":"sox-rmm-assertion"}],"type":"risk"},{"field":"inherent_rating","hasNull":false,"key":"risk.rating","label":"Inherent rating","options":[{"label":"critical","value":"critical"},{"label":"high","value":"high"},{"label":"low","value":"low"},{"label":"medium","value":"medium"}],"type":"risk"}],"guideUrl":"https://controlsmap.com/agents/","limits":{"nodeCharacters":160,"parameters":128,"queryBytes":8192,"queryCharacters":160,"valuesPerField":64},"nodeAliases":{"wf:D07":"wf:D06","wf:D08":"wf:D06","wf:D09":"wf:D06","wf:D12":"wf:A15","wf:D13":"wf:A15","wf:D14":"wf:A15","wf:D15":"wf:A15","wf:D16":"wf:A15","wf:D17":"wf:A15","wf:D18":"wf:A15","wf:D19":"wf:A15","wf:D20":"wf:A15"},"nodesUrl":"https://controlsmap.com/nodes.json","revision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","semantics":{"absentField":"all","aliasedNode":"canonical-node-preserve-filters","betweenFields":"and","emptyField":"none","invalidFilterValues":"drop-with-notice-retain-empty-if-none-valid","nullToken":"__null__","overLimit":"atomic-reset-with-notice","search":"eligible-matches-with-uc-and-source-context","sourceScope":"strict-membership","unknownNode":"no-panel-with-notice","withinField":"or"},"version":1}