{"nodeAliases":{"wf:D07":"wf:D06","wf:D08":"wf:D06","wf:D09":"wf:D06","wf:D12":"wf:A15","wf:D13":"wf:A15","wf:D14":"wf:A15","wf:D15":"wf:A15","wf:D16":"wf:A15","wf:D17":"wf:A15","wf:D18":"wf:A15","wf:D19":"wf:A15","wf:D20":"wf:A15"},"nodes":[{"id":"ctrl:aiuc-1:A001","rendered":false,"sources":["aiuc-1"],"title":"A001 — Establish input data policy","type":"control"},{"id":"ctrl:aiuc-1:A002","rendered":false,"sources":["aiuc-1"],"title":"A002 — Establish output data policy","type":"control"},{"id":"ctrl:aiuc-1:A003","rendered":false,"sources":["aiuc-1"],"title":"A003 — Limit AI agent data access","type":"control"},{"id":"ctrl:aiuc-1:A004","rendered":false,"sources":["aiuc-1"],"title":"A004 — Protect IP & trade secrets","type":"control"},{"id":"ctrl:aiuc-1:A005","rendered":false,"sources":["aiuc-1"],"title":"A005 — Prevent cross-customer data exposure","type":"control"},{"id":"ctrl:aiuc-1:A006","rendered":false,"sources":["aiuc-1"],"title":"A006 — Prevent PII leakage","type":"control"},{"id":"ctrl:aiuc-1:A007","rendered":false,"sources":["aiuc-1"],"title":"A007 — Prevent IP violations","type":"control"},{"id":"ctrl:aiuc-1:A008","rendered":false,"sources":["aiuc-1"],"title":"A008 — Prevent leakage of credentials and secrets","type":"control"},{"id":"ctrl:aiuc-1:B001","rendered":false,"sources":["aiuc-1"],"title":"B001 — Third-party testing of adversarial robustness","type":"control"},{"id":"ctrl:aiuc-1:B002","rendered":false,"sources":["aiuc-1"],"title":"B002 — Detect adversarial input","type":"control"},{"id":"ctrl:aiuc-1:B003","rendered":false,"sources":["aiuc-1"],"title":"B003 — Manage public release of technical details","type":"control"},{"id":"ctrl:aiuc-1:B004","rendered":false,"sources":["aiuc-1"],"title":"B004 — Prevent AI endpoint scraping","type":"control"},{"id":"ctrl:aiuc-1:B005","rendered":false,"sources":["aiuc-1"],"title":"B005 — Implement real-time input filtering","type":"control"},{"id":"ctrl:aiuc-1:B006","rendered":false,"sources":["aiuc-1"],"title":"B006 — Prevent unauthorized AI agent actions","type":"control"},{"id":"ctrl:aiuc-1:B007","rendered":false,"sources":["aiuc-1"],"title":"B007 — Enforce user access privileges to AI systems","type":"control"},{"id":"ctrl:aiuc-1:B008","rendered":false,"sources":["aiuc-1"],"title":"B008 — Protect AI system deployment environment","type":"control"},{"id":"ctrl:aiuc-1:B009","rendered":false,"sources":["aiuc-1"],"title":"B009 — Limit output over-exposure","type":"control"},{"id":"ctrl:aiuc-1:B010","rendered":false,"sources":["aiuc-1"],"title":"B010 — Promote secure patterns in generated code","type":"control"},{"id":"ctrl:aiuc-1:C001","rendered":false,"sources":["aiuc-1"],"title":"C001 — Define AI risk taxonomy","type":"control"},{"id":"ctrl:aiuc-1:C002","rendered":false,"sources":["aiuc-1"],"title":"C002 — Conduct pre-deployment testing","type":"control"},{"id":"ctrl:aiuc-1:C003","rendered":false,"sources":["aiuc-1"],"title":"C003 — Prevent harmful outputs","type":"control"},{"id":"ctrl:aiuc-1:C004","rendered":false,"sources":["aiuc-1"],"title":"C004 — Prevent out-of-scope outputs","type":"control"},{"id":"ctrl:aiuc-1:C005","rendered":false,"sources":["aiuc-1"],"title":"C005 — Prevent agent-specific high risk outputs","type":"control"},{"id":"ctrl:aiuc-1:C006","rendered":false,"sources":["aiuc-1"],"title":"C006 — Prevent output vulnerabilities","type":"control"},{"id":"ctrl:aiuc-1:C007","rendered":false,"sources":["aiuc-1"],"title":"C007 — Flag high risk outputs for human review","type":"control"},{"id":"ctrl:aiuc-1:C008","rendered":false,"sources":["aiuc-1"],"title":"C008 — Monitor AI risk categories","type":"control"},{"id":"ctrl:aiuc-1:C009","rendered":false,"sources":["aiuc-1"],"title":"C009 — Enable real-time feedback and intervention","type":"control"},{"id":"ctrl:aiuc-1:C010","rendered":false,"sources":["aiuc-1"],"title":"C010 — Third-party testing for harmful outputs","type":"control"},{"id":"ctrl:aiuc-1:C011","rendered":false,"sources":["aiuc-1"],"title":"C011 — Third-party testing for out-of-scope outputs","type":"control"},{"id":"ctrl:aiuc-1:C012","rendered":false,"sources":["aiuc-1"],"title":"C012 — Third-party testing for customer-defined risk","type":"control"},{"id":"ctrl:aiuc-1:D001","rendered":false,"sources":["aiuc-1"],"title":"D001 — Prevent hallucinated outputs","type":"control"},{"id":"ctrl:aiuc-1:D002","rendered":false,"sources":["aiuc-1"],"title":"D002 — Third-party testing for hallucinations","type":"control"},{"id":"ctrl:aiuc-1:D003","rendered":false,"sources":["aiuc-1"],"title":"D003 — Restrict unsafe tool calls","type":"control"},{"id":"ctrl:aiuc-1:D004","rendered":false,"sources":["aiuc-1"],"title":"D004 — Third-party testing of tool calls","type":"control"},{"id":"ctrl:aiuc-1:E001","rendered":false,"sources":["aiuc-1"],"title":"E001 — AI failure plan for security breaches","type":"control"},{"id":"ctrl:aiuc-1:E002","rendered":false,"sources":["aiuc-1"],"title":"E002 — AI failure plan for harmful outputs","type":"control"},{"id":"ctrl:aiuc-1:E003","rendered":false,"sources":["aiuc-1"],"title":"E003 — AI failure plan for hallucinations","type":"control"},{"id":"ctrl:aiuc-1:E004","rendered":false,"sources":["aiuc-1"],"title":"E004 — Assign accountability","type":"control"},{"id":"ctrl:aiuc-1:E005","rendered":false,"sources":["aiuc-1"],"title":"E005 — Document data storage security","type":"control"},{"id":"ctrl:aiuc-1:E006","rendered":false,"sources":["aiuc-1"],"title":"E006 — Conduct vendor due diligence","type":"control"},{"id":"ctrl:aiuc-1:E008","rendered":false,"sources":["aiuc-1"],"title":"E008 — Review internal processes","type":"control"},{"id":"ctrl:aiuc-1:E009","rendered":false,"sources":["aiuc-1"],"title":"E009 — Monitor third-party access","type":"control"},{"id":"ctrl:aiuc-1:E010","rendered":false,"sources":["aiuc-1"],"title":"E010 — Establish AI acceptable use policy","type":"control"},{"id":"ctrl:aiuc-1:E011","rendered":false,"sources":["aiuc-1"],"title":"E011 — Record processing locations","type":"control"},{"id":"ctrl:aiuc-1:E012","rendered":false,"sources":["aiuc-1"],"title":"E012 — Document regulatory compliance","type":"control"},{"id":"ctrl:aiuc-1:E013","rendered":false,"sources":["aiuc-1"],"title":"E013 — Implement quality management system","type":"control"},{"id":"ctrl:aiuc-1:E015","rendered":false,"sources":["aiuc-1"],"title":"E015 — Log AI system activity","type":"control"},{"id":"ctrl:aiuc-1:E016","rendered":false,"sources":["aiuc-1"],"title":"E016 — Implement AI disclosure mechanisms","type":"control"},{"id":"ctrl:aiuc-1:E017","rendered":false,"sources":["aiuc-1"],"title":"E017 — Document system transparency policy","type":"control"},{"id":"ctrl:aiuc-1:F001","rendered":false,"sources":["aiuc-1"],"title":"F001 — Prevent AI cyber misuse","type":"control"},{"id":"ctrl:aiuc-1:F002","rendered":false,"sources":["aiuc-1"],"title":"F002 — Prevent catastrophic misuse","type":"control"},{"id":"ctrl:ccpa:CCPA-1798.100","rendered":false,"sources":["ccpa"],"title":"CCPA-1798.100 — Notice at collection and consumer right to know","type":"control"},{"id":"ctrl:ccpa:CCPA-1798.105","rendered":false,"sources":["ccpa"],"title":"CCPA-1798.105 — Right to delete personal information","type":"control"},{"id":"ctrl:ccpa:CCPA-1798.106","rendered":false,"sources":["ccpa"],"title":"CCPA-1798.106 — Right to correct inaccurate personal information","type":"control"},{"id":"ctrl:ccpa:CCPA-1798.110-115","rendered":false,"sources":["ccpa"],"title":"CCPA-1798.110-115 — Rights to access and disclosure of personal information collected, sold, or shared","type":"control"},{"id":"ctrl:ccpa:CCPA-1798.120-121","rendered":false,"sources":["ccpa"],"title":"CCPA-1798.120-121 — Right to opt out of sale/sharing and to limit use of sensitive personal information","type":"control"},{"id":"ctrl:ccpa:CCPA-1798.125","rendered":false,"sources":["ccpa"],"title":"CCPA-1798.125 — Non-discrimination and financial-incentive requirements","type":"control"},{"id":"ctrl:ccpa:CCPA-1798.130-135","rendered":false,"sources":["ccpa"],"title":"CCPA-1798.130-135 — Request-handling mechanics, verification, and opt-out link requirements","type":"control"},{"id":"ctrl:ccpa:CCPA-1798.140","rendered":false,"sources":["ccpa"],"title":"CCPA-1798.140 — Service-provider and contractor contract requirements","type":"control"},{"id":"ctrl:ccpa:CCPA-1798.150","rendered":false,"sources":["ccpa"],"title":"CCPA-1798.150 — Reasonable security procedures; private right of action for breaches","type":"control"},{"id":"ctrl:ccpa:CCPA-1798.185","rendered":false,"sources":["ccpa"],"title":"CCPA-1798.185 — CPPA regulations: cybersecurity audits and risk assessments","type":"control"},{"id":"ctrl:cobit-2019:APO01","rendered":false,"sources":["cobit-2019"],"title":"APO01 — Managed I&T Management Framework","type":"control"},{"id":"ctrl:cobit-2019:APO02","rendered":false,"sources":["cobit-2019"],"title":"APO02 — Managed Strategy","type":"control"},{"id":"ctrl:cobit-2019:APO03","rendered":false,"sources":["cobit-2019"],"title":"APO03 — Managed Enterprise Architecture","type":"control"},{"id":"ctrl:cobit-2019:APO04","rendered":false,"sources":["cobit-2019"],"title":"APO04 — Managed Innovation","type":"control"},{"id":"ctrl:cobit-2019:APO05","rendered":false,"sources":["cobit-2019"],"title":"APO05 — Managed Portfolio","type":"control"},{"id":"ctrl:cobit-2019:APO06","rendered":false,"sources":["cobit-2019"],"title":"APO06 — Managed Budget and Costs","type":"control"},{"id":"ctrl:cobit-2019:APO07","rendered":false,"sources":["cobit-2019"],"title":"APO07 — Managed Human Resources","type":"control"},{"id":"ctrl:cobit-2019:APO08","rendered":false,"sources":["cobit-2019"],"title":"APO08 — Managed Relationships","type":"control"},{"id":"ctrl:cobit-2019:APO09","rendered":false,"sources":["cobit-2019"],"title":"APO09 — Managed Service Agreements","type":"control"},{"id":"ctrl:cobit-2019:APO10","rendered":false,"sources":["cobit-2019"],"title":"APO10 — Managed Vendors","type":"control"},{"id":"ctrl:cobit-2019:APO11","rendered":false,"sources":["cobit-2019"],"title":"APO11 — Managed Quality","type":"control"},{"id":"ctrl:cobit-2019:APO12","rendered":false,"sources":["cobit-2019"],"title":"APO12 — Managed Risk","type":"control"},{"id":"ctrl:cobit-2019:APO13","rendered":false,"sources":["cobit-2019"],"title":"APO13 — Managed Security","type":"control"},{"id":"ctrl:cobit-2019:APO14","rendered":false,"sources":["cobit-2019"],"title":"APO14 — Managed Data","type":"control"},{"id":"ctrl:cobit-2019:BAI01","rendered":false,"sources":["cobit-2019"],"title":"BAI01 — Managed Programs","type":"control"},{"id":"ctrl:cobit-2019:BAI02","rendered":false,"sources":["cobit-2019"],"title":"BAI02 — Managed Requirements Definition","type":"control"},{"id":"ctrl:cobit-2019:BAI03","rendered":false,"sources":["cobit-2019"],"title":"BAI03 — Managed Solutions Identification and Build","type":"control"},{"id":"ctrl:cobit-2019:BAI04","rendered":false,"sources":["cobit-2019"],"title":"BAI04 — Managed Availability and Capacity","type":"control"},{"id":"ctrl:cobit-2019:BAI05","rendered":false,"sources":["cobit-2019"],"title":"BAI05 — Managed Organizational Change","type":"control"},{"id":"ctrl:cobit-2019:BAI06","rendered":false,"sources":["cobit-2019"],"title":"BAI06 — Managed IT Changes","type":"control"},{"id":"ctrl:cobit-2019:BAI07","rendered":false,"sources":["cobit-2019"],"title":"BAI07 — Managed IT Change Acceptance and Transitioning","type":"control"},{"id":"ctrl:cobit-2019:BAI08","rendered":false,"sources":["cobit-2019"],"title":"BAI08 — Managed Knowledge","type":"control"},{"id":"ctrl:cobit-2019:BAI09","rendered":false,"sources":["cobit-2019"],"title":"BAI09 — Managed Assets","type":"control"},{"id":"ctrl:cobit-2019:BAI10","rendered":false,"sources":["cobit-2019"],"title":"BAI10 — Managed Configuration","type":"control"},{"id":"ctrl:cobit-2019:BAI11","rendered":false,"sources":["cobit-2019"],"title":"BAI11 — Managed Projects","type":"control"},{"id":"ctrl:cobit-2019:DSS01","rendered":false,"sources":["cobit-2019"],"title":"DSS01 — Managed Operations","type":"control"},{"id":"ctrl:cobit-2019:DSS02","rendered":false,"sources":["cobit-2019"],"title":"DSS02 — Managed Service Requests and Incidents","type":"control"},{"id":"ctrl:cobit-2019:DSS03","rendered":false,"sources":["cobit-2019"],"title":"DSS03 — Managed Problems","type":"control"},{"id":"ctrl:cobit-2019:DSS04","rendered":false,"sources":["cobit-2019"],"title":"DSS04 — Managed Continuity","type":"control"},{"id":"ctrl:cobit-2019:DSS05","rendered":false,"sources":["cobit-2019"],"title":"DSS05 — Managed Security Services","type":"control"},{"id":"ctrl:cobit-2019:DSS06","rendered":false,"sources":["cobit-2019"],"title":"DSS06 — Managed Business Process Controls","type":"control"},{"id":"ctrl:cobit-2019:EDM01","rendered":false,"sources":["cobit-2019"],"title":"EDM01 — Ensured Governance Framework Setting and Maintenance","type":"control"},{"id":"ctrl:cobit-2019:EDM02","rendered":false,"sources":["cobit-2019"],"title":"EDM02 — Ensured Benefits Delivery","type":"control"},{"id":"ctrl:cobit-2019:EDM03","rendered":false,"sources":["cobit-2019"],"title":"EDM03 — Ensured Risk Optimization","type":"control"},{"id":"ctrl:cobit-2019:EDM04","rendered":false,"sources":["cobit-2019"],"title":"EDM04 — Ensured Resource Optimization","type":"control"},{"id":"ctrl:cobit-2019:EDM05","rendered":false,"sources":["cobit-2019"],"title":"EDM05 — Ensured Stakeholder Engagement","type":"control"},{"id":"ctrl:cobit-2019:MEA01","rendered":false,"sources":["cobit-2019"],"title":"MEA01 — Managed Performance and Conformance Monitoring","type":"control"},{"id":"ctrl:cobit-2019:MEA02","rendered":false,"sources":["cobit-2019"],"title":"MEA02 — Managed System of Internal Control","type":"control"},{"id":"ctrl:cobit-2019:MEA03","rendered":false,"sources":["cobit-2019"],"title":"MEA03 — Managed Compliance With External Requirements","type":"control"},{"id":"ctrl:cobit-2019:MEA04","rendered":false,"sources":["cobit-2019"],"title":"MEA04 — Managed Assurance","type":"control"},{"id":"ctrl:coso-erm:E1","rendered":false,"sources":["coso-erm"],"title":"E1 — Exercises Board Risk Oversight","type":"control"},{"id":"ctrl:coso-erm:E10","rendered":false,"sources":["coso-erm"],"title":"E10 — Identifies Risk","type":"control"},{"id":"ctrl:coso-erm:E11","rendered":false,"sources":["coso-erm"],"title":"E11 — Assesses Severity of Risk","type":"control"},{"id":"ctrl:coso-erm:E12","rendered":false,"sources":["coso-erm"],"title":"E12 — Prioritizes Risks","type":"control"},{"id":"ctrl:coso-erm:E13","rendered":false,"sources":["coso-erm"],"title":"E13 — Implements Risk Responses","type":"control"},{"id":"ctrl:coso-erm:E14","rendered":false,"sources":["coso-erm"],"title":"E14 — Develops Portfolio View","type":"control"},{"id":"ctrl:coso-erm:E15","rendered":false,"sources":["coso-erm"],"title":"E15 — Assesses Substantial Change","type":"control"},{"id":"ctrl:coso-erm:E16","rendered":false,"sources":["coso-erm"],"title":"E16 — Reviews Risk and Performance","type":"control"},{"id":"ctrl:coso-erm:E17","rendered":false,"sources":["coso-erm"],"title":"E17 — Pursues Improvement in Enterprise Risk Management","type":"control"},{"id":"ctrl:coso-erm:E18","rendered":false,"sources":["coso-erm"],"title":"E18 — Leverages Information and Technology","type":"control"},{"id":"ctrl:coso-erm:E19","rendered":false,"sources":["coso-erm"],"title":"E19 — Communicates Risk Information","type":"control"},{"id":"ctrl:coso-erm:E2","rendered":false,"sources":["coso-erm"],"title":"E2 — Establishes Operating Structures","type":"control"},{"id":"ctrl:coso-erm:E20","rendered":false,"sources":["coso-erm"],"title":"E20 — Reports on Risk, Culture, and Performance","type":"control"},{"id":"ctrl:coso-erm:E3","rendered":false,"sources":["coso-erm"],"title":"E3 — Defines Desired Culture","type":"control"},{"id":"ctrl:coso-erm:E4","rendered":false,"sources":["coso-erm"],"title":"E4 — Demonstrates Commitment to Core Values","type":"control"},{"id":"ctrl:coso-erm:E5","rendered":false,"sources":["coso-erm"],"title":"E5 — Attracts, Develops, and Retains Capable Individuals","type":"control"},{"id":"ctrl:coso-erm:E6","rendered":false,"sources":["coso-erm"],"title":"E6 — Analyzes Business Context","type":"control"},{"id":"ctrl:coso-erm:E7","rendered":false,"sources":["coso-erm"],"title":"E7 — Defines Risk Appetite","type":"control"},{"id":"ctrl:coso-erm:E8","rendered":false,"sources":["coso-erm"],"title":"E8 — Evaluates Alternative Strategies","type":"control"},{"id":"ctrl:coso-erm:E9","rendered":false,"sources":["coso-erm"],"title":"E9 — Formulates Business Objectives","type":"control"},{"id":"ctrl:coso-ic:P1","rendered":false,"sources":["coso-ic"],"title":"P1 — The organization demonstrates a commitment to integrity and ethical values.","type":"control"},{"id":"ctrl:coso-ic:P10","rendered":false,"sources":["coso-ic"],"title":"P10 — The organization selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.","type":"control"},{"id":"ctrl:coso-ic:P11","rendered":false,"sources":["coso-ic"],"title":"P11 — The organization selects and develops general control activities over technology to support the achievement of objectives.","type":"control"},{"id":"ctrl:coso-ic:P12","rendered":false,"sources":["coso-ic"],"title":"P12 — The organization deploys control activities through policies that establish what is expected and procedures that put policies into action.","type":"control"},{"id":"ctrl:coso-ic:P13","rendered":false,"sources":["coso-ic"],"title":"P13 — The organization obtains or generates and uses relevant, quality information to support the functioning of internal control.","type":"control"},{"id":"ctrl:coso-ic:P14","rendered":false,"sources":["coso-ic"],"title":"P14 — The organization internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.","type":"control"},{"id":"ctrl:coso-ic:P15","rendered":false,"sources":["coso-ic"],"title":"P15 — The organization communicates with external parties regarding matters affecting the functioning of internal control.","type":"control"},{"id":"ctrl:coso-ic:P16","rendered":false,"sources":["coso-ic"],"title":"P16 — The organization selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.","type":"control"},{"id":"ctrl:coso-ic:P17","rendered":false,"sources":["coso-ic"],"title":"P17 — The organization evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate.","type":"control"},{"id":"ctrl:coso-ic:P2","rendered":false,"sources":["coso-ic"],"title":"P2 — The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.","type":"control"},{"id":"ctrl:coso-ic:P3","rendered":false,"sources":["coso-ic"],"title":"P3 — Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.","type":"control"},{"id":"ctrl:coso-ic:P4","rendered":false,"sources":["coso-ic"],"title":"P4 — The organization demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.","type":"control"},{"id":"ctrl:coso-ic:P5","rendered":false,"sources":["coso-ic"],"title":"P5 — The organization holds individuals accountable for their internal control responsibilities in the pursuit of objectives.","type":"control"},{"id":"ctrl:coso-ic:P6","rendered":false,"sources":["coso-ic"],"title":"P6 — The organization specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.","type":"control"},{"id":"ctrl:coso-ic:P7","rendered":false,"sources":["coso-ic"],"title":"P7 — The organization identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed.","type":"control"},{"id":"ctrl:coso-ic:P8","rendered":false,"sources":["coso-ic"],"title":"P8 — The organization considers the potential for fraud in assessing risks to the achievement of objectives.","type":"control"},{"id":"ctrl:coso-ic:P9","rendered":false,"sources":["coso-ic"],"title":"P9 — The organization identifies and assesses changes that could significantly impact the system of internal control.","type":"control"},{"id":"ctrl:dora:DORA-Art17-23","rendered":false,"sources":["dora"],"title":"DORA-Art17-23 — ICT-related incident management, classification and reporting","type":"control"},{"id":"ctrl:dora:DORA-Art24-27","rendered":false,"sources":["dora"],"title":"DORA-Art24-27 — Digital operational resilience testing (incl. threat-led penetration testing)","type":"control"},{"id":"ctrl:dora:DORA-Art28-44","rendered":false,"sources":["dora"],"title":"DORA-Art28-44 — Managing of ICT third-party risk","type":"control"},{"id":"ctrl:dora:DORA-Art45","rendered":false,"sources":["dora"],"title":"DORA-Art45 — Information and intelligence sharing arrangements","type":"control"},{"id":"ctrl:dora:DORA-Art5","rendered":false,"sources":["dora"],"title":"DORA-Art5 — Governance and organisation (management body responsibility)","type":"control"},{"id":"ctrl:dora:DORA-Ch2","rendered":false,"sources":["dora"],"title":"DORA-Ch2 — ICT risk management framework (Art 5-16)","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art10","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art10 — Data and data governance (high-risk)","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art11","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art11 — Technical documentation (high-risk)","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art12","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art12 — Record-keeping / logging (high-risk)","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art13","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art13 — Transparency and provision of information to deployers (high-risk)","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art14","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art14 — Human oversight (high-risk)","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art15","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art15 — Accuracy, robustness and cybersecurity (high-risk)","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art16","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art16 — Obligations of providers of high-risk AI systems","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art17","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art17 — Quality management system (providers of high-risk AI systems)","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art18","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art18 — Documentation keeping — 10-year retention of technical documentation, QMS records and conformity documents (providers)","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art19","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art19 — Automatically generated logs — provider retention of high-risk system logs (minimum six months)","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art20","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art20 — Corrective actions and duty of information for non-conforming high-risk AI systems","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art21-22","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art21-22 — Cooperation with competent authorities; authorised representatives of non-EU providers","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art23-25","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art23-25 — Obligations of importers and distributors; responsibilities along the AI value chain","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art26","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art26 — Obligations of deployers of high-risk AI systems","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art27","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art27 — Fundamental rights impact assessment for high-risk AI systems (deployers)","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art43","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art43 — Conformity assessment of high-risk AI systems","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art47-49","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art47-49 — EU declaration of conformity, CE marking and registration in the EU database","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art5","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art5 — Prohibited AI practices","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art50","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art50 — Transparency obligations for certain AI systems (deepfakes, chatbots, emotion recognition)","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art53","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art53 — Obligations for providers of general-purpose AI (GPAI) models","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art55","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art55 — Obligations for GPAI models with systemic risk","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art6-7","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art6-7 — Risk-based classification of high-risk AI systems","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art72","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art72 — Post-market monitoring by providers of high-risk AI systems","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art73","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art73 — Reporting of serious incidents (providers; deployers inform providers)","type":"control"},{"id":"ctrl:eu-ai-act:AIA-Art9","rendered":false,"sources":["eu-ai-act"],"title":"AIA-Art9 — Risk management system (high-risk)","type":"control"},{"id":"ctrl:gdpr:GDPR-Art12-14","rendered":false,"sources":["gdpr"],"title":"GDPR-Art12-14 — Transparency and information to data subjects","type":"control"},{"id":"ctrl:gdpr:GDPR-Art15-22","rendered":false,"sources":["gdpr"],"title":"GDPR-Art15-22 — Data subject rights (access, rectification, erasure, portability, objection, automated decisions)","type":"control"},{"id":"ctrl:gdpr:GDPR-Art24","rendered":false,"sources":["gdpr"],"title":"GDPR-Art24 — Responsibility of the controller","type":"control"},{"id":"ctrl:gdpr:GDPR-Art25","rendered":false,"sources":["gdpr"],"title":"GDPR-Art25 — Data protection by design and by default","type":"control"},{"id":"ctrl:gdpr:GDPR-Art28","rendered":false,"sources":["gdpr"],"title":"GDPR-Art28 — Processor obligations and data processing agreements","type":"control"},{"id":"ctrl:gdpr:GDPR-Art30","rendered":false,"sources":["gdpr"],"title":"GDPR-Art30 — Records of processing activities (RoPA)","type":"control"},{"id":"ctrl:gdpr:GDPR-Art32","rendered":false,"sources":["gdpr"],"title":"GDPR-Art32 — Security of processing","type":"control"},{"id":"ctrl:gdpr:GDPR-Art33","rendered":false,"sources":["gdpr"],"title":"GDPR-Art33 — Notification of a personal data breach to the supervisory authority","type":"control"},{"id":"ctrl:gdpr:GDPR-Art34","rendered":false,"sources":["gdpr"],"title":"GDPR-Art34 — Communication of a breach to the data subject","type":"control"},{"id":"ctrl:gdpr:GDPR-Art35","rendered":false,"sources":["gdpr"],"title":"GDPR-Art35 — Data protection impact assessment (DPIA)","type":"control"},{"id":"ctrl:gdpr:GDPR-Art37-39","rendered":false,"sources":["gdpr"],"title":"GDPR-Art37-39 — Designation and tasks of the Data Protection Officer","type":"control"},{"id":"ctrl:gdpr:GDPR-Art44-49","rendered":false,"sources":["gdpr"],"title":"GDPR-Art44-49 — International transfers of personal data","type":"control"},{"id":"ctrl:gdpr:GDPR-Art5","rendered":false,"sources":["gdpr"],"title":"GDPR-Art5 — Principles relating to processing of personal data","type":"control"},{"id":"ctrl:gdpr:GDPR-Art6","rendered":false,"sources":["gdpr"],"title":"GDPR-Art6 — Lawfulness of processing","type":"control"},{"id":"ctrl:gdpr:GDPR-Art7","rendered":false,"sources":["gdpr"],"title":"GDPR-Art7 — Conditions for consent","type":"control"},{"id":"ctrl:gdpr:GDPR-Art9","rendered":false,"sources":["gdpr"],"title":"GDPR-Art9 — Processing of special categories of data","type":"control"},{"id":"ctrl:hipaa:HIPAA-164.308","rendered":false,"sources":["hipaa"],"title":"HIPAA-164.308 — Administrative safeguards (security management, risk analysis, workforce security, training, contingency plan, evaluation, BAAs)","type":"control"},{"id":"ctrl:hipaa:HIPAA-164.310","rendered":false,"sources":["hipaa"],"title":"HIPAA-164.310 — Physical safeguards (facility access controls, workstation use/security, device and media controls)","type":"control"},{"id":"ctrl:hipaa:HIPAA-164.312(a)","rendered":false,"sources":["hipaa"],"title":"HIPAA-164.312(a) — Technical access control for ePHI (unique user ID, emergency access, automatic logoff, encryption/decryption)","type":"control"},{"id":"ctrl:hipaa:HIPAA-164.312(b)","rendered":false,"sources":["hipaa"],"title":"HIPAA-164.312(b) — Audit controls recording activity in systems with ePHI","type":"control"},{"id":"ctrl:hipaa:HIPAA-164.312(c)","rendered":false,"sources":["hipaa"],"title":"HIPAA-164.312(c) — Integrity controls protecting ePHI from improper alteration or destruction","type":"control"},{"id":"ctrl:hipaa:HIPAA-164.312(d)","rendered":false,"sources":["hipaa"],"title":"HIPAA-164.312(d) — Person or entity authentication before ePHI access","type":"control"},{"id":"ctrl:hipaa:HIPAA-164.312(e)","rendered":false,"sources":["hipaa"],"title":"HIPAA-164.312(e) — Transmission security for ePHI (integrity controls and encryption in transit)","type":"control"},{"id":"ctrl:hipaa:HIPAA-164.314","rendered":false,"sources":["hipaa"],"title":"HIPAA-164.314 — Organizational requirements (business associate contracts, group health plan requirements)","type":"control"},{"id":"ctrl:hipaa:HIPAA-164.316","rendered":false,"sources":["hipaa"],"title":"HIPAA-164.316 — Policies and procedures and documentation requirements","type":"control"},{"id":"ctrl:hipaa:HIPAA-164.400-414","rendered":false,"sources":["hipaa"],"title":"HIPAA-164.400-414 — Breach notification to individuals, media, and HHS (incl. business-associate duties)","type":"control"},{"id":"ctrl:hipaa:HIPAA-164.502","rendered":false,"sources":["hipaa"],"title":"HIPAA-164.502 — Uses and disclosures of PHI (permitted/required uses, minimum necessary)","type":"control"},{"id":"ctrl:hipaa:HIPAA-164.508","rendered":false,"sources":["hipaa"],"title":"HIPAA-164.508 — Authorizations required for other uses and disclosures of PHI","type":"control"},{"id":"ctrl:hipaa:HIPAA-164.514","rendered":false,"sources":["hipaa"],"title":"HIPAA-164.514 — De-identification of PHI and limited data sets","type":"control"},{"id":"ctrl:hipaa:HIPAA-164.520","rendered":false,"sources":["hipaa"],"title":"HIPAA-164.520 — Notice of privacy practices for PHI","type":"control"},{"id":"ctrl:hipaa:HIPAA-164.524","rendered":false,"sources":["hipaa"],"title":"HIPAA-164.524 — Individual right of access to PHI","type":"control"},{"id":"ctrl:hipaa:HIPAA-164.526","rendered":false,"sources":["hipaa"],"title":"HIPAA-164.526 — Individual right to amend PHI","type":"control"},{"id":"ctrl:iia-2024:Principle 1","rendered":false,"sources":["iia-2024"],"title":"Principle 1 — Demonstrate Integrity","type":"control"},{"id":"ctrl:iia-2024:Principle 10","rendered":false,"sources":["iia-2024"],"title":"Principle 10 — Manage Resources","type":"control"},{"id":"ctrl:iia-2024:Principle 11","rendered":false,"sources":["iia-2024"],"title":"Principle 11 — Communicate Effectively","type":"control"},{"id":"ctrl:iia-2024:Principle 12","rendered":false,"sources":["iia-2024"],"title":"Principle 12 — Enhance Quality","type":"control"},{"id":"ctrl:iia-2024:Principle 13","rendered":false,"sources":["iia-2024"],"title":"Principle 13 — Plan Engagements Effectively","type":"control"},{"id":"ctrl:iia-2024:Principle 14","rendered":false,"sources":["iia-2024"],"title":"Principle 14 — Conduct Engagement Work","type":"control"},{"id":"ctrl:iia-2024:Principle 15","rendered":false,"sources":["iia-2024"],"title":"Principle 15 — Communicate Engagement Results and Monitor Action Plans","type":"control"},{"id":"ctrl:iia-2024:Principle 2","rendered":false,"sources":["iia-2024"],"title":"Principle 2 — Maintain Objectivity","type":"control"},{"id":"ctrl:iia-2024:Principle 3","rendered":false,"sources":["iia-2024"],"title":"Principle 3 — Demonstrate Competency","type":"control"},{"id":"ctrl:iia-2024:Principle 4","rendered":false,"sources":["iia-2024"],"title":"Principle 4 — Exercise Due Professional Care","type":"control"},{"id":"ctrl:iia-2024:Principle 5","rendered":false,"sources":["iia-2024"],"title":"Principle 5 — Maintain Confidentiality","type":"control"},{"id":"ctrl:iia-2024:Principle 6","rendered":false,"sources":["iia-2024"],"title":"Principle 6 — Authorized by the Board","type":"control"},{"id":"ctrl:iia-2024:Principle 7","rendered":false,"sources":["iia-2024"],"title":"Principle 7 — Positioned Independently","type":"control"},{"id":"ctrl:iia-2024:Principle 8","rendered":false,"sources":["iia-2024"],"title":"Principle 8 — Overseen by the Board","type":"control"},{"id":"ctrl:iia-2024:Principle 9","rendered":false,"sources":["iia-2024"],"title":"Principle 9 — Plan Strategically","type":"control"},{"id":"ctrl:iia-2024:Purpose","rendered":false,"sources":["iia-2024"],"title":"Purpose — Purpose of Internal Auditing — Internal auditing strengthens the organization's ability to create, protect, and sustain value by providing the board and management with independent, risk-based, and objective assurance, advice, insight, and foresight.","type":"control"},{"id":"ctrl:iia-2024:Std 1.1","rendered":false,"sources":["iia-2024"],"title":"Std 1.1 — Honesty and Professional Courage","type":"control"},{"id":"ctrl:iia-2024:Std 1.2","rendered":false,"sources":["iia-2024"],"title":"Std 1.2 — Organization's Ethical Expectations","type":"control"},{"id":"ctrl:iia-2024:Std 1.3","rendered":false,"sources":["iia-2024"],"title":"Std 1.3 — Legal and Ethical Behavior","type":"control"},{"id":"ctrl:iia-2024:Std 10.1","rendered":false,"sources":["iia-2024"],"title":"Std 10.1 — Financial Resource Management","type":"control"},{"id":"ctrl:iia-2024:Std 10.2","rendered":false,"sources":["iia-2024"],"title":"Std 10.2 — Human Resources Management","type":"control"},{"id":"ctrl:iia-2024:Std 10.3","rendered":false,"sources":["iia-2024"],"title":"Std 10.3 — Technological Resources","type":"control"},{"id":"ctrl:iia-2024:Std 11.1","rendered":false,"sources":["iia-2024"],"title":"Std 11.1 — Building Relationships and Communicating with Stakeholders","type":"control"},{"id":"ctrl:iia-2024:Std 11.2","rendered":false,"sources":["iia-2024"],"title":"Std 11.2 — Effective Communication","type":"control"},{"id":"ctrl:iia-2024:Std 11.3","rendered":false,"sources":["iia-2024"],"title":"Std 11.3 — Communicating Results","type":"control"},{"id":"ctrl:iia-2024:Std 11.4","rendered":false,"sources":["iia-2024"],"title":"Std 11.4 — Errors and Omissions","type":"control"},{"id":"ctrl:iia-2024:Std 11.5","rendered":false,"sources":["iia-2024"],"title":"Std 11.5 — Communicating the Acceptance of Risks","type":"control"},{"id":"ctrl:iia-2024:Std 12.1","rendered":false,"sources":["iia-2024"],"title":"Std 12.1 — Internal Quality Assessment","type":"control"},{"id":"ctrl:iia-2024:Std 12.2","rendered":false,"sources":["iia-2024"],"title":"Std 12.2 — Performance Measurement","type":"control"},{"id":"ctrl:iia-2024:Std 12.3","rendered":false,"sources":["iia-2024"],"title":"Std 12.3 — Oversee and Improve Engagement Performance","type":"control"},{"id":"ctrl:iia-2024:Std 13.1","rendered":false,"sources":["iia-2024"],"title":"Std 13.1 — Engagement Communication","type":"control"},{"id":"ctrl:iia-2024:Std 13.2","rendered":false,"sources":["iia-2024"],"title":"Std 13.2 — Engagement Risk Assessment","type":"control"},{"id":"ctrl:iia-2024:Std 13.3","rendered":false,"sources":["iia-2024"],"title":"Std 13.3 — Engagement Objectives and Scope","type":"control"},{"id":"ctrl:iia-2024:Std 13.4","rendered":false,"sources":["iia-2024"],"title":"Std 13.4 — Evaluation Criteria","type":"control"},{"id":"ctrl:iia-2024:Std 13.5","rendered":false,"sources":["iia-2024"],"title":"Std 13.5 — Engagement Resources","type":"control"},{"id":"ctrl:iia-2024:Std 13.6","rendered":false,"sources":["iia-2024"],"title":"Std 13.6 — Work Program","type":"control"},{"id":"ctrl:iia-2024:Std 14.1","rendered":false,"sources":["iia-2024"],"title":"Std 14.1 — Gathering Information for Analyses and Evaluation","type":"control"},{"id":"ctrl:iia-2024:Std 14.2","rendered":false,"sources":["iia-2024"],"title":"Std 14.2 — Analyses and Potential Engagement Findings","type":"control"},{"id":"ctrl:iia-2024:Std 14.3","rendered":false,"sources":["iia-2024"],"title":"Std 14.3 — Evaluation of Findings","type":"control"},{"id":"ctrl:iia-2024:Std 14.4","rendered":false,"sources":["iia-2024"],"title":"Std 14.4 — Recommendations and Action Plans","type":"control"},{"id":"ctrl:iia-2024:Std 14.5","rendered":false,"sources":["iia-2024"],"title":"Std 14.5 — Engagement Conclusions","type":"control"},{"id":"ctrl:iia-2024:Std 14.6","rendered":false,"sources":["iia-2024"],"title":"Std 14.6 — Engagement Documentation","type":"control"},{"id":"ctrl:iia-2024:Std 15.1","rendered":false,"sources":["iia-2024"],"title":"Std 15.1 — Final Engagement Communication","type":"control"},{"id":"ctrl:iia-2024:Std 15.2","rendered":false,"sources":["iia-2024"],"title":"Std 15.2 — Confirming the Implementation of Recommendations or Action Plans","type":"control"},{"id":"ctrl:iia-2024:Std 2.1","rendered":false,"sources":["iia-2024"],"title":"Std 2.1 — Individual Objectivity","type":"control"},{"id":"ctrl:iia-2024:Std 2.2","rendered":false,"sources":["iia-2024"],"title":"Std 2.2 — Safeguarding Objectivity","type":"control"},{"id":"ctrl:iia-2024:Std 2.3","rendered":false,"sources":["iia-2024"],"title":"Std 2.3 — Disclosing Impairments to Objectivity","type":"control"},{"id":"ctrl:iia-2024:Std 3.1","rendered":false,"sources":["iia-2024"],"title":"Std 3.1 — Competency","type":"control"},{"id":"ctrl:iia-2024:Std 3.2","rendered":false,"sources":["iia-2024"],"title":"Std 3.2 — Continuing Professional Development","type":"control"},{"id":"ctrl:iia-2024:Std 4.1","rendered":false,"sources":["iia-2024"],"title":"Std 4.1 — Conformance with the Global Internal Audit Standards","type":"control"},{"id":"ctrl:iia-2024:Std 4.2","rendered":false,"sources":["iia-2024"],"title":"Std 4.2 — Due Professional Care","type":"control"},{"id":"ctrl:iia-2024:Std 4.3","rendered":false,"sources":["iia-2024"],"title":"Std 4.3 — Professional Skepticism","type":"control"},{"id":"ctrl:iia-2024:Std 5.1","rendered":false,"sources":["iia-2024"],"title":"Std 5.1 — Use of Information","type":"control"},{"id":"ctrl:iia-2024:Std 5.2","rendered":false,"sources":["iia-2024"],"title":"Std 5.2 — Protection of Information","type":"control"},{"id":"ctrl:iia-2024:Std 6.1","rendered":false,"sources":["iia-2024"],"title":"Std 6.1 — Internal Audit Mandate","type":"control"},{"id":"ctrl:iia-2024:Std 6.2","rendered":false,"sources":["iia-2024"],"title":"Std 6.2 — Internal Audit Charter","type":"control"},{"id":"ctrl:iia-2024:Std 6.3","rendered":false,"sources":["iia-2024"],"title":"Std 6.3 — Board and Senior Management Support","type":"control"},{"id":"ctrl:iia-2024:Std 7.1","rendered":false,"sources":["iia-2024"],"title":"Std 7.1 — Organizational Independence","type":"control"},{"id":"ctrl:iia-2024:Std 7.2","rendered":false,"sources":["iia-2024"],"title":"Std 7.2 — Chief Audit Executive Qualifications","type":"control"},{"id":"ctrl:iia-2024:Std 8.1","rendered":false,"sources":["iia-2024"],"title":"Std 8.1 — Board Interaction","type":"control"},{"id":"ctrl:iia-2024:Std 8.2","rendered":false,"sources":["iia-2024"],"title":"Std 8.2 — Resources","type":"control"},{"id":"ctrl:iia-2024:Std 8.3","rendered":false,"sources":["iia-2024"],"title":"Std 8.3 — Quality","type":"control"},{"id":"ctrl:iia-2024:Std 8.4","rendered":false,"sources":["iia-2024"],"title":"Std 8.4 — External Quality Assessment","type":"control"},{"id":"ctrl:iia-2024:Std 9.1","rendered":false,"sources":["iia-2024"],"title":"Std 9.1 — Understanding Governance, Risk Management, and Control Processes","type":"control"},{"id":"ctrl:iia-2024:Std 9.2","rendered":false,"sources":["iia-2024"],"title":"Std 9.2 — Internal Audit Strategy","type":"control"},{"id":"ctrl:iia-2024:Std 9.3","rendered":false,"sources":["iia-2024"],"title":"Std 9.3 — Methodologies","type":"control"},{"id":"ctrl:iia-2024:Std 9.4","rendered":false,"sources":["iia-2024"],"title":"Std 9.4 — Internal Audit Plan","type":"control"},{"id":"ctrl:iia-2024:Std 9.5","rendered":false,"sources":["iia-2024"],"title":"Std 9.5 — Coordination and Reliance","type":"control"},{"id":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-01","rendered":false,"sources":["iia-pos-2026-erm"],"title":"IIA-POS-ERM-01 — Board, Management, and Internal Audit Accountabilities","type":"control"},{"id":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-02","rendered":false,"sources":["iia-pos-2026-erm"],"title":"IIA-POS-ERM-02 — ERM Activity and Service Boundaries","type":"control"},{"id":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-03","rendered":false,"sources":["iia-pos-2026-erm"],"title":"IIA-POS-ERM-03 — Safeguards for Expanded ERM Responsibility","type":"control"},{"id":"ctrl:iia-pos-2026-erm:IIA-POS-ERM-04","rendered":false,"sources":["iia-pos-2026-erm"],"title":"IIA-POS-ERM-04 — Assurance and Advisory Portfolio Calibration","type":"control"},{"id":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-01","rendered":false,"sources":["iia-pos-2026-three-lines"],"title":"IIA-POS-TLM-01 — Activity-Level Three Lines Responsibilities","type":"control"},{"id":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-02","rendered":false,"sources":["iia-pos-2026-three-lines"],"title":"IIA-POS-TLM-02 — Independence and Self-Review Safeguards","type":"control"},{"id":"ctrl:iia-pos-2026-three-lines:IIA-POS-TLM-03","rendered":false,"sources":["iia-pos-2026-three-lines"],"title":"IIA-POS-TLM-03 — Assurance Coordination and Reliance","type":"control"},{"id":"ctrl:iso-27001:A.5.1","rendered":false,"sources":["iso-27001"],"title":"A.5.1 — Policies for information security","type":"control"},{"id":"ctrl:iso-27001:A.5.10","rendered":false,"sources":["iso-27001"],"title":"A.5.10 — Acceptable use of information and other associated assets","type":"control"},{"id":"ctrl:iso-27001:A.5.11","rendered":false,"sources":["iso-27001"],"title":"A.5.11 — Return of assets","type":"control"},{"id":"ctrl:iso-27001:A.5.12","rendered":false,"sources":["iso-27001"],"title":"A.5.12 — Classification of information","type":"control"},{"id":"ctrl:iso-27001:A.5.13","rendered":false,"sources":["iso-27001"],"title":"A.5.13 — Labelling of information","type":"control"},{"id":"ctrl:iso-27001:A.5.14","rendered":false,"sources":["iso-27001"],"title":"A.5.14 — Information transfer","type":"control"},{"id":"ctrl:iso-27001:A.5.15","rendered":false,"sources":["iso-27001"],"title":"A.5.15 — Access control","type":"control"},{"id":"ctrl:iso-27001:A.5.16","rendered":false,"sources":["iso-27001"],"title":"A.5.16 — Identity management","type":"control"},{"id":"ctrl:iso-27001:A.5.17","rendered":false,"sources":["iso-27001"],"title":"A.5.17 — Authentication information","type":"control"},{"id":"ctrl:iso-27001:A.5.18","rendered":false,"sources":["iso-27001"],"title":"A.5.18 — Access rights","type":"control"},{"id":"ctrl:iso-27001:A.5.19","rendered":false,"sources":["iso-27001"],"title":"A.5.19 — Information security in supplier relationships","type":"control"},{"id":"ctrl:iso-27001:A.5.2","rendered":false,"sources":["iso-27001"],"title":"A.5.2 — Information security roles and responsibilities","type":"control"},{"id":"ctrl:iso-27001:A.5.20","rendered":false,"sources":["iso-27001"],"title":"A.5.20 — Addressing information security within supplier agreements","type":"control"},{"id":"ctrl:iso-27001:A.5.21","rendered":false,"sources":["iso-27001"],"title":"A.5.21 — Managing information security in the ICT supply chain","type":"control"},{"id":"ctrl:iso-27001:A.5.22","rendered":false,"sources":["iso-27001"],"title":"A.5.22 — Monitoring, review and change management of supplier services","type":"control"},{"id":"ctrl:iso-27001:A.5.23","rendered":false,"sources":["iso-27001"],"title":"A.5.23 — Information security for use of cloud services","type":"control"},{"id":"ctrl:iso-27001:A.5.24","rendered":false,"sources":["iso-27001"],"title":"A.5.24 — Information security incident management planning and preparation","type":"control"},{"id":"ctrl:iso-27001:A.5.25","rendered":false,"sources":["iso-27001"],"title":"A.5.25 — Assessment and decision on information security events","type":"control"},{"id":"ctrl:iso-27001:A.5.26","rendered":false,"sources":["iso-27001"],"title":"A.5.26 — Response to information security incidents","type":"control"},{"id":"ctrl:iso-27001:A.5.27","rendered":false,"sources":["iso-27001"],"title":"A.5.27 — Learning from information security incidents","type":"control"},{"id":"ctrl:iso-27001:A.5.28","rendered":false,"sources":["iso-27001"],"title":"A.5.28 — Collection of evidence","type":"control"},{"id":"ctrl:iso-27001:A.5.29","rendered":false,"sources":["iso-27001"],"title":"A.5.29 — Information security during disruption","type":"control"},{"id":"ctrl:iso-27001:A.5.3","rendered":false,"sources":["iso-27001"],"title":"A.5.3 — Segregation of duties","type":"control"},{"id":"ctrl:iso-27001:A.5.30","rendered":false,"sources":["iso-27001"],"title":"A.5.30 — ICT readiness for business continuity","type":"control"},{"id":"ctrl:iso-27001:A.5.31","rendered":false,"sources":["iso-27001"],"title":"A.5.31 — Legal, statutory, regulatory and contractual requirements","type":"control"},{"id":"ctrl:iso-27001:A.5.32","rendered":false,"sources":["iso-27001"],"title":"A.5.32 — Intellectual property rights","type":"control"},{"id":"ctrl:iso-27001:A.5.33","rendered":false,"sources":["iso-27001"],"title":"A.5.33 — Protection of records","type":"control"},{"id":"ctrl:iso-27001:A.5.34","rendered":false,"sources":["iso-27001"],"title":"A.5.34 — Privacy and protection of personal identifiable information (PII)","type":"control"},{"id":"ctrl:iso-27001:A.5.35","rendered":false,"sources":["iso-27001"],"title":"A.5.35 — Independent review of information security","type":"control"},{"id":"ctrl:iso-27001:A.5.36","rendered":false,"sources":["iso-27001"],"title":"A.5.36 — Compliance with policies, rules and standards for information security","type":"control"},{"id":"ctrl:iso-27001:A.5.37","rendered":false,"sources":["iso-27001"],"title":"A.5.37 — Documented operating procedures","type":"control"},{"id":"ctrl:iso-27001:A.5.4","rendered":false,"sources":["iso-27001"],"title":"A.5.4 — Management responsibilities","type":"control"},{"id":"ctrl:iso-27001:A.5.5","rendered":false,"sources":["iso-27001"],"title":"A.5.5 — Contact with authorities","type":"control"},{"id":"ctrl:iso-27001:A.5.6","rendered":false,"sources":["iso-27001"],"title":"A.5.6 — Contact with special interest groups","type":"control"},{"id":"ctrl:iso-27001:A.5.7","rendered":false,"sources":["iso-27001"],"title":"A.5.7 — Threat intelligence","type":"control"},{"id":"ctrl:iso-27001:A.5.8","rendered":false,"sources":["iso-27001"],"title":"A.5.8 — Information security in project management","type":"control"},{"id":"ctrl:iso-27001:A.5.9","rendered":false,"sources":["iso-27001"],"title":"A.5.9 — Inventory of information and other associated assets","type":"control"},{"id":"ctrl:iso-27001:A.6.1","rendered":false,"sources":["iso-27001"],"title":"A.6.1 — Screening","type":"control"},{"id":"ctrl:iso-27001:A.6.2","rendered":false,"sources":["iso-27001"],"title":"A.6.2 — Terms and conditions of employment","type":"control"},{"id":"ctrl:iso-27001:A.6.3","rendered":false,"sources":["iso-27001"],"title":"A.6.3 — Information security awareness, education and training","type":"control"},{"id":"ctrl:iso-27001:A.6.4","rendered":false,"sources":["iso-27001"],"title":"A.6.4 — Disciplinary process","type":"control"},{"id":"ctrl:iso-27001:A.6.5","rendered":false,"sources":["iso-27001"],"title":"A.6.5 — Responsibilities after termination or change of employment","type":"control"},{"id":"ctrl:iso-27001:A.6.6","rendered":false,"sources":["iso-27001"],"title":"A.6.6 — Confidentiality or non-disclosure agreements","type":"control"},{"id":"ctrl:iso-27001:A.6.7","rendered":false,"sources":["iso-27001"],"title":"A.6.7 — Remote working","type":"control"},{"id":"ctrl:iso-27001:A.6.8","rendered":false,"sources":["iso-27001"],"title":"A.6.8 — Information security event reporting","type":"control"},{"id":"ctrl:iso-27001:A.7.1","rendered":false,"sources":["iso-27001"],"title":"A.7.1 — Physical security perimeters","type":"control"},{"id":"ctrl:iso-27001:A.7.10","rendered":false,"sources":["iso-27001"],"title":"A.7.10 — Storage media","type":"control"},{"id":"ctrl:iso-27001:A.7.11","rendered":false,"sources":["iso-27001"],"title":"A.7.11 — Supporting utilities","type":"control"},{"id":"ctrl:iso-27001:A.7.12","rendered":false,"sources":["iso-27001"],"title":"A.7.12 — Cabling security","type":"control"},{"id":"ctrl:iso-27001:A.7.13","rendered":false,"sources":["iso-27001"],"title":"A.7.13 — Equipment maintenance","type":"control"},{"id":"ctrl:iso-27001:A.7.14","rendered":false,"sources":["iso-27001"],"title":"A.7.14 — Secure disposal or re-use of equipment","type":"control"},{"id":"ctrl:iso-27001:A.7.2","rendered":false,"sources":["iso-27001"],"title":"A.7.2 — Physical entry","type":"control"},{"id":"ctrl:iso-27001:A.7.3","rendered":false,"sources":["iso-27001"],"title":"A.7.3 — Securing offices, rooms and facilities","type":"control"},{"id":"ctrl:iso-27001:A.7.4","rendered":false,"sources":["iso-27001"],"title":"A.7.4 — Physical security monitoring","type":"control"},{"id":"ctrl:iso-27001:A.7.5","rendered":false,"sources":["iso-27001"],"title":"A.7.5 — Protecting against physical and environmental threats","type":"control"},{"id":"ctrl:iso-27001:A.7.6","rendered":false,"sources":["iso-27001"],"title":"A.7.6 — Working in secure areas","type":"control"},{"id":"ctrl:iso-27001:A.7.7","rendered":false,"sources":["iso-27001"],"title":"A.7.7 — Clear desk and clear screen","type":"control"},{"id":"ctrl:iso-27001:A.7.8","rendered":false,"sources":["iso-27001"],"title":"A.7.8 — Equipment siting and protection","type":"control"},{"id":"ctrl:iso-27001:A.7.9","rendered":false,"sources":["iso-27001"],"title":"A.7.9 — Security of assets off-premises","type":"control"},{"id":"ctrl:iso-27001:A.8.1","rendered":false,"sources":["iso-27001"],"title":"A.8.1 — User endpoint devices","type":"control"},{"id":"ctrl:iso-27001:A.8.10","rendered":false,"sources":["iso-27001"],"title":"A.8.10 — Information deletion","type":"control"},{"id":"ctrl:iso-27001:A.8.11","rendered":false,"sources":["iso-27001"],"title":"A.8.11 — Data masking","type":"control"},{"id":"ctrl:iso-27001:A.8.12","rendered":false,"sources":["iso-27001"],"title":"A.8.12 — Data leakage prevention","type":"control"},{"id":"ctrl:iso-27001:A.8.13","rendered":false,"sources":["iso-27001"],"title":"A.8.13 — Information backup","type":"control"},{"id":"ctrl:iso-27001:A.8.14","rendered":false,"sources":["iso-27001"],"title":"A.8.14 — Redundancy of information processing facilities","type":"control"},{"id":"ctrl:iso-27001:A.8.15","rendered":false,"sources":["iso-27001"],"title":"A.8.15 — Logging","type":"control"},{"id":"ctrl:iso-27001:A.8.16","rendered":false,"sources":["iso-27001"],"title":"A.8.16 — Monitoring activities","type":"control"},{"id":"ctrl:iso-27001:A.8.17","rendered":false,"sources":["iso-27001"],"title":"A.8.17 — Clock synchronization","type":"control"},{"id":"ctrl:iso-27001:A.8.18","rendered":false,"sources":["iso-27001"],"title":"A.8.18 — Use of privileged utility programs","type":"control"},{"id":"ctrl:iso-27001:A.8.19","rendered":false,"sources":["iso-27001"],"title":"A.8.19 — Installation of software on operational systems","type":"control"},{"id":"ctrl:iso-27001:A.8.2","rendered":false,"sources":["iso-27001"],"title":"A.8.2 — Privileged access rights","type":"control"},{"id":"ctrl:iso-27001:A.8.20","rendered":false,"sources":["iso-27001"],"title":"A.8.20 — Networks security","type":"control"},{"id":"ctrl:iso-27001:A.8.21","rendered":false,"sources":["iso-27001"],"title":"A.8.21 — Security of network services","type":"control"},{"id":"ctrl:iso-27001:A.8.22","rendered":false,"sources":["iso-27001"],"title":"A.8.22 — Segregation of networks","type":"control"},{"id":"ctrl:iso-27001:A.8.23","rendered":false,"sources":["iso-27001"],"title":"A.8.23 — Web filtering","type":"control"},{"id":"ctrl:iso-27001:A.8.24","rendered":false,"sources":["iso-27001"],"title":"A.8.24 — Use of cryptography","type":"control"},{"id":"ctrl:iso-27001:A.8.25","rendered":false,"sources":["iso-27001"],"title":"A.8.25 — Secure development life cycle","type":"control"},{"id":"ctrl:iso-27001:A.8.26","rendered":false,"sources":["iso-27001"],"title":"A.8.26 — Application security requirements","type":"control"},{"id":"ctrl:iso-27001:A.8.27","rendered":false,"sources":["iso-27001"],"title":"A.8.27 — Secure system architecture and engineering principles","type":"control"},{"id":"ctrl:iso-27001:A.8.28","rendered":false,"sources":["iso-27001"],"title":"A.8.28 — Secure coding","type":"control"},{"id":"ctrl:iso-27001:A.8.29","rendered":false,"sources":["iso-27001"],"title":"A.8.29 — Security testing in development and acceptance","type":"control"},{"id":"ctrl:iso-27001:A.8.3","rendered":false,"sources":["iso-27001"],"title":"A.8.3 — Information access restriction","type":"control"},{"id":"ctrl:iso-27001:A.8.30","rendered":false,"sources":["iso-27001"],"title":"A.8.30 — Outsourced development","type":"control"},{"id":"ctrl:iso-27001:A.8.31","rendered":false,"sources":["iso-27001"],"title":"A.8.31 — Separation of development, test and production environments","type":"control"},{"id":"ctrl:iso-27001:A.8.32","rendered":false,"sources":["iso-27001"],"title":"A.8.32 — Change management","type":"control"},{"id":"ctrl:iso-27001:A.8.33","rendered":false,"sources":["iso-27001"],"title":"A.8.33 — Test information","type":"control"},{"id":"ctrl:iso-27001:A.8.34","rendered":false,"sources":["iso-27001"],"title":"A.8.34 — Protection of information systems during audit testing","type":"control"},{"id":"ctrl:iso-27001:A.8.4","rendered":false,"sources":["iso-27001"],"title":"A.8.4 — Access to source code","type":"control"},{"id":"ctrl:iso-27001:A.8.5","rendered":false,"sources":["iso-27001"],"title":"A.8.5 — Secure authentication","type":"control"},{"id":"ctrl:iso-27001:A.8.6","rendered":false,"sources":["iso-27001"],"title":"A.8.6 — Capacity management","type":"control"},{"id":"ctrl:iso-27001:A.8.7","rendered":false,"sources":["iso-27001"],"title":"A.8.7 — Protection against malware","type":"control"},{"id":"ctrl:iso-27001:A.8.8","rendered":false,"sources":["iso-27001"],"title":"A.8.8 — Management of technical vulnerabilities","type":"control"},{"id":"ctrl:iso-27001:A.8.9","rendered":false,"sources":["iso-27001"],"title":"A.8.9 — Configuration management","type":"control"},{"id":"ctrl:iso-31000:31000-FW1","rendered":false,"sources":["iso-31000"],"title":"31000-FW1 — Leadership and commitment","type":"control"},{"id":"ctrl:iso-31000:31000-FW2","rendered":false,"sources":["iso-31000"],"title":"31000-FW2 — Integration","type":"control"},{"id":"ctrl:iso-31000:31000-FW3","rendered":false,"sources":["iso-31000"],"title":"31000-FW3 — Design","type":"control"},{"id":"ctrl:iso-31000:31000-FW4","rendered":false,"sources":["iso-31000"],"title":"31000-FW4 — Implementation","type":"control"},{"id":"ctrl:iso-31000:31000-FW5","rendered":false,"sources":["iso-31000"],"title":"31000-FW5 — Evaluation","type":"control"},{"id":"ctrl:iso-31000:31000-FW6","rendered":false,"sources":["iso-31000"],"title":"31000-FW6 — Improvement","type":"control"},{"id":"ctrl:iso-31000:31000-P1","rendered":false,"sources":["iso-31000"],"title":"31000-P1 — Integrated","type":"control"},{"id":"ctrl:iso-31000:31000-P2","rendered":false,"sources":["iso-31000"],"title":"31000-P2 — Structured and comprehensive","type":"control"},{"id":"ctrl:iso-31000:31000-P3","rendered":false,"sources":["iso-31000"],"title":"31000-P3 — Customized","type":"control"},{"id":"ctrl:iso-31000:31000-P4","rendered":false,"sources":["iso-31000"],"title":"31000-P4 — Inclusive","type":"control"},{"id":"ctrl:iso-31000:31000-P5","rendered":false,"sources":["iso-31000"],"title":"31000-P5 — Dynamic","type":"control"},{"id":"ctrl:iso-31000:31000-P6","rendered":false,"sources":["iso-31000"],"title":"31000-P6 — Best available information","type":"control"},{"id":"ctrl:iso-31000:31000-P7","rendered":false,"sources":["iso-31000"],"title":"31000-P7 — Human and cultural factors","type":"control"},{"id":"ctrl:iso-31000:31000-P8","rendered":false,"sources":["iso-31000"],"title":"31000-P8 — Continual improvement","type":"control"},{"id":"ctrl:iso-31000:31000-PR1","rendered":false,"sources":["iso-31000"],"title":"31000-PR1 — Communication and consultation","type":"control"},{"id":"ctrl:iso-31000:31000-PR2","rendered":false,"sources":["iso-31000"],"title":"31000-PR2 — Scope, context and criteria","type":"control"},{"id":"ctrl:iso-31000:31000-PR3","rendered":false,"sources":["iso-31000"],"title":"31000-PR3 — Risk assessment: risk identification","type":"control"},{"id":"ctrl:iso-31000:31000-PR4","rendered":false,"sources":["iso-31000"],"title":"31000-PR4 — Risk assessment: risk analysis","type":"control"},{"id":"ctrl:iso-31000:31000-PR5","rendered":false,"sources":["iso-31000"],"title":"31000-PR5 — Risk assessment: risk evaluation","type":"control"},{"id":"ctrl:iso-31000:31000-PR6","rendered":false,"sources":["iso-31000"],"title":"31000-PR6 — Risk treatment","type":"control"},{"id":"ctrl:iso-31000:31000-PR7","rendered":false,"sources":["iso-31000"],"title":"31000-PR7 — Monitoring and review","type":"control"},{"id":"ctrl:iso-31000:31000-PR8","rendered":false,"sources":["iso-31000"],"title":"31000-PR8 — Recording and reporting","type":"control"},{"id":"ctrl:iso-42001:A.10.2","rendered":false,"sources":["iso-42001"],"title":"A.10.2 — Allocating responsibilities","type":"control"},{"id":"ctrl:iso-42001:A.10.3","rendered":false,"sources":["iso-42001"],"title":"A.10.3 — Suppliers","type":"control"},{"id":"ctrl:iso-42001:A.10.4","rendered":false,"sources":["iso-42001"],"title":"A.10.4 — Customers","type":"control"},{"id":"ctrl:iso-42001:A.2.2","rendered":false,"sources":["iso-42001"],"title":"A.2.2 — AI policy","type":"control"},{"id":"ctrl:iso-42001:A.2.3","rendered":false,"sources":["iso-42001"],"title":"A.2.3 — Alignment with other organizational policies","type":"control"},{"id":"ctrl:iso-42001:A.2.4","rendered":false,"sources":["iso-42001"],"title":"A.2.4 — Review of the AI policy","type":"control"},{"id":"ctrl:iso-42001:A.3.2","rendered":false,"sources":["iso-42001"],"title":"A.3.2 — AI roles and responsibilities","type":"control"},{"id":"ctrl:iso-42001:A.3.3","rendered":false,"sources":["iso-42001"],"title":"A.3.3 — Reporting of concerns","type":"control"},{"id":"ctrl:iso-42001:A.4.2","rendered":false,"sources":["iso-42001"],"title":"A.4.2 — Resource documentation","type":"control"},{"id":"ctrl:iso-42001:A.4.3","rendered":false,"sources":["iso-42001"],"title":"A.4.3 — Data resources","type":"control"},{"id":"ctrl:iso-42001:A.4.4","rendered":false,"sources":["iso-42001"],"title":"A.4.4 — Tooling resources","type":"control"},{"id":"ctrl:iso-42001:A.4.5","rendered":false,"sources":["iso-42001"],"title":"A.4.5 — System and computing resources","type":"control"},{"id":"ctrl:iso-42001:A.4.6","rendered":false,"sources":["iso-42001"],"title":"A.4.6 — Human resources","type":"control"},{"id":"ctrl:iso-42001:A.5.2","rendered":false,"sources":["iso-42001"],"title":"A.5.2 — AI system impact assessment process","type":"control"},{"id":"ctrl:iso-42001:A.5.3","rendered":false,"sources":["iso-42001"],"title":"A.5.3 — Documentation of AI system impact assessments","type":"control"},{"id":"ctrl:iso-42001:A.5.4","rendered":false,"sources":["iso-42001"],"title":"A.5.4 — Assessing AI system impact on individuals or groups of individuals","type":"control"},{"id":"ctrl:iso-42001:A.5.5","rendered":false,"sources":["iso-42001"],"title":"A.5.5 — Assessing societal impacts of AI systems","type":"control"},{"id":"ctrl:iso-42001:A.6.1.2","rendered":false,"sources":["iso-42001"],"title":"A.6.1.2 — Objectives for responsible development of AI systems","type":"control"},{"id":"ctrl:iso-42001:A.6.1.3","rendered":false,"sources":["iso-42001"],"title":"A.6.1.3 — Processes for responsible AI system design and development","type":"control"},{"id":"ctrl:iso-42001:A.6.2.2","rendered":false,"sources":["iso-42001"],"title":"A.6.2.2 — AI system requirements and specification","type":"control"},{"id":"ctrl:iso-42001:A.6.2.3","rendered":false,"sources":["iso-42001"],"title":"A.6.2.3 — Documentation of AI system design and development","type":"control"},{"id":"ctrl:iso-42001:A.6.2.4","rendered":false,"sources":["iso-42001"],"title":"A.6.2.4 — AI system verification and validation","type":"control"},{"id":"ctrl:iso-42001:A.6.2.5","rendered":false,"sources":["iso-42001"],"title":"A.6.2.5 — AI system deployment","type":"control"},{"id":"ctrl:iso-42001:A.6.2.6","rendered":false,"sources":["iso-42001"],"title":"A.6.2.6 — AI system operation and monitoring","type":"control"},{"id":"ctrl:iso-42001:A.6.2.7","rendered":false,"sources":["iso-42001"],"title":"A.6.2.7 — AI system technical documentation","type":"control"},{"id":"ctrl:iso-42001:A.6.2.8","rendered":false,"sources":["iso-42001"],"title":"A.6.2.8 — AI system recording of event logs","type":"control"},{"id":"ctrl:iso-42001:A.7.2","rendered":false,"sources":["iso-42001"],"title":"A.7.2 — Data for development and enhancement of AI systems","type":"control"},{"id":"ctrl:iso-42001:A.7.3","rendered":false,"sources":["iso-42001"],"title":"A.7.3 — Acquisition of data","type":"control"},{"id":"ctrl:iso-42001:A.7.4","rendered":false,"sources":["iso-42001"],"title":"A.7.4 — Data quality for AI systems","type":"control"},{"id":"ctrl:iso-42001:A.7.5","rendered":false,"sources":["iso-42001"],"title":"A.7.5 — Data provenance","type":"control"},{"id":"ctrl:iso-42001:A.7.6","rendered":false,"sources":["iso-42001"],"title":"A.7.6 — Data preparation","type":"control"},{"id":"ctrl:iso-42001:A.8.2","rendered":false,"sources":["iso-42001"],"title":"A.8.2 — System documentation and information for users","type":"control"},{"id":"ctrl:iso-42001:A.8.3","rendered":false,"sources":["iso-42001"],"title":"A.8.3 — External reporting","type":"control"},{"id":"ctrl:iso-42001:A.8.4","rendered":false,"sources":["iso-42001"],"title":"A.8.4 — Communication of incidents","type":"control"},{"id":"ctrl:iso-42001:A.8.5","rendered":false,"sources":["iso-42001"],"title":"A.8.5 — Information for interested parties","type":"control"},{"id":"ctrl:iso-42001:A.9.2","rendered":false,"sources":["iso-42001"],"title":"A.9.2 — Processes for responsible use of AI systems","type":"control"},{"id":"ctrl:iso-42001:A.9.3","rendered":false,"sources":["iso-42001"],"title":"A.9.3 — Objectives for responsible use of AI systems","type":"control"},{"id":"ctrl:iso-42001:A.9.4","rendered":false,"sources":["iso-42001"],"title":"A.9.4 — Intended use of the AI system","type":"control"},{"id":"ctrl:nis2:NIS2-Art20","rendered":false,"sources":["nis2"],"title":"NIS2-Art20 — Governance and management body accountability / training","type":"control"},{"id":"ctrl:nis2:NIS2-Art21a","rendered":false,"sources":["nis2"],"title":"NIS2-Art21a — Policies on risk analysis and information system security","type":"control"},{"id":"ctrl:nis2:NIS2-Art21b","rendered":false,"sources":["nis2"],"title":"NIS2-Art21b — Incident handling","type":"control"},{"id":"ctrl:nis2:NIS2-Art21c","rendered":false,"sources":["nis2"],"title":"NIS2-Art21c — Business continuity, backup management and disaster recovery, crisis management","type":"control"},{"id":"ctrl:nis2:NIS2-Art21d","rendered":false,"sources":["nis2"],"title":"NIS2-Art21d — Supply chain security","type":"control"},{"id":"ctrl:nis2:NIS2-Art21e","rendered":false,"sources":["nis2"],"title":"NIS2-Art21e — Security in acquisition, development and maintenance of network and information systems (incl. vulnerability handling and disclosure)","type":"control"},{"id":"ctrl:nis2:NIS2-Art21f","rendered":false,"sources":["nis2"],"title":"NIS2-Art21f — Policies and procedures to assess the effectiveness of cybersecurity risk-management measures","type":"control"},{"id":"ctrl:nis2:NIS2-Art21g","rendered":false,"sources":["nis2"],"title":"NIS2-Art21g — Basic cyber hygiene practices and cybersecurity training","type":"control"},{"id":"ctrl:nis2:NIS2-Art21h","rendered":false,"sources":["nis2"],"title":"NIS2-Art21h — Policies on the use of cryptography and encryption","type":"control"},{"id":"ctrl:nis2:NIS2-Art21i","rendered":false,"sources":["nis2"],"title":"NIS2-Art21i — Human resources security, access control policies and asset management","type":"control"},{"id":"ctrl:nis2:NIS2-Art21j","rendered":false,"sources":["nis2"],"title":"NIS2-Art21j — Use of multi-factor authentication, secured communications and emergency communication systems","type":"control"},{"id":"ctrl:nis2:NIS2-Art23","rendered":false,"sources":["nis2"],"title":"NIS2-Art23 — Reporting obligations (early warning 24h, incident notification 72h, final report 1 month)","type":"control"},{"id":"ctrl:nist-800-53:AC-1","rendered":false,"sources":["nist-800-53"],"title":"AC-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:AC-10","rendered":false,"sources":["nist-800-53"],"title":"AC-10 — Concurrent Session Control","type":"control"},{"id":"ctrl:nist-800-53:AC-11","rendered":false,"sources":["nist-800-53"],"title":"AC-11 — Device Lock","type":"control"},{"id":"ctrl:nist-800-53:AC-12","rendered":false,"sources":["nist-800-53"],"title":"AC-12 — Session Termination","type":"control"},{"id":"ctrl:nist-800-53:AC-14","rendered":false,"sources":["nist-800-53"],"title":"AC-14 — Permitted Actions Without Identification or Authentication","type":"control"},{"id":"ctrl:nist-800-53:AC-16","rendered":false,"sources":["nist-800-53"],"title":"AC-16 — Security and Privacy Attributes","type":"control"},{"id":"ctrl:nist-800-53:AC-17","rendered":false,"sources":["nist-800-53"],"title":"AC-17 — Remote Access","type":"control"},{"id":"ctrl:nist-800-53:AC-18","rendered":false,"sources":["nist-800-53"],"title":"AC-18 — Wireless Access","type":"control"},{"id":"ctrl:nist-800-53:AC-19","rendered":false,"sources":["nist-800-53"],"title":"AC-19 — Access Control for Mobile Devices","type":"control"},{"id":"ctrl:nist-800-53:AC-2","rendered":false,"sources":["nist-800-53"],"title":"AC-2 — Account Management","type":"control"},{"id":"ctrl:nist-800-53:AC-20","rendered":false,"sources":["nist-800-53"],"title":"AC-20 — Use of External Systems","type":"control"},{"id":"ctrl:nist-800-53:AC-21","rendered":false,"sources":["nist-800-53"],"title":"AC-21 — Information Sharing","type":"control"},{"id":"ctrl:nist-800-53:AC-22","rendered":false,"sources":["nist-800-53"],"title":"AC-22 — Publicly Accessible Content","type":"control"},{"id":"ctrl:nist-800-53:AC-24","rendered":false,"sources":["nist-800-53"],"title":"AC-24 — Access Control Decisions","type":"control"},{"id":"ctrl:nist-800-53:AC-25","rendered":false,"sources":["nist-800-53"],"title":"AC-25 — Reference Monitor","type":"control"},{"id":"ctrl:nist-800-53:AC-3","rendered":false,"sources":["nist-800-53"],"title":"AC-3 — Access Enforcement","type":"control"},{"id":"ctrl:nist-800-53:AC-4","rendered":false,"sources":["nist-800-53"],"title":"AC-4 — Information Flow Enforcement","type":"control"},{"id":"ctrl:nist-800-53:AC-5","rendered":false,"sources":["nist-800-53"],"title":"AC-5 — Separation of Duties","type":"control"},{"id":"ctrl:nist-800-53:AC-6","rendered":false,"sources":["nist-800-53"],"title":"AC-6 — Least Privilege","type":"control"},{"id":"ctrl:nist-800-53:AC-7","rendered":false,"sources":["nist-800-53"],"title":"AC-7 — Unsuccessful Logon Attempts","type":"control"},{"id":"ctrl:nist-800-53:AC-8","rendered":false,"sources":["nist-800-53"],"title":"AC-8 — System Use Notification","type":"control"},{"id":"ctrl:nist-800-53:AC-9","rendered":false,"sources":["nist-800-53"],"title":"AC-9 — Previous Logon Notification","type":"control"},{"id":"ctrl:nist-800-53:AT-1","rendered":false,"sources":["nist-800-53"],"title":"AT-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:AT-2","rendered":false,"sources":["nist-800-53"],"title":"AT-2 — Literacy Training and Awareness","type":"control"},{"id":"ctrl:nist-800-53:AT-3","rendered":false,"sources":["nist-800-53"],"title":"AT-3 — Role-based Training","type":"control"},{"id":"ctrl:nist-800-53:AT-4","rendered":false,"sources":["nist-800-53"],"title":"AT-4 — Training Records","type":"control"},{"id":"ctrl:nist-800-53:AT-6","rendered":false,"sources":["nist-800-53"],"title":"AT-6 — Training Feedback","type":"control"},{"id":"ctrl:nist-800-53:AU-1","rendered":false,"sources":["nist-800-53"],"title":"AU-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:AU-10","rendered":false,"sources":["nist-800-53"],"title":"AU-10 — Non-repudiation","type":"control"},{"id":"ctrl:nist-800-53:AU-11","rendered":false,"sources":["nist-800-53"],"title":"AU-11 — Audit Record Retention","type":"control"},{"id":"ctrl:nist-800-53:AU-12","rendered":false,"sources":["nist-800-53"],"title":"AU-12 — Audit Record Generation","type":"control"},{"id":"ctrl:nist-800-53:AU-13","rendered":false,"sources":["nist-800-53"],"title":"AU-13 — Monitoring for Information Disclosure","type":"control"},{"id":"ctrl:nist-800-53:AU-14","rendered":false,"sources":["nist-800-53"],"title":"AU-14 — Session Audit","type":"control"},{"id":"ctrl:nist-800-53:AU-16","rendered":false,"sources":["nist-800-53"],"title":"AU-16 — Cross-organizational Audit Logging","type":"control"},{"id":"ctrl:nist-800-53:AU-2","rendered":false,"sources":["nist-800-53"],"title":"AU-2 — Event Logging","type":"control"},{"id":"ctrl:nist-800-53:AU-3","rendered":false,"sources":["nist-800-53"],"title":"AU-3 — Content of Audit Records","type":"control"},{"id":"ctrl:nist-800-53:AU-4","rendered":false,"sources":["nist-800-53"],"title":"AU-4 — Audit Log Storage Capacity","type":"control"},{"id":"ctrl:nist-800-53:AU-5","rendered":false,"sources":["nist-800-53"],"title":"AU-5 — Response to Audit Logging Process Failures","type":"control"},{"id":"ctrl:nist-800-53:AU-6","rendered":false,"sources":["nist-800-53"],"title":"AU-6 — Audit Record Review, Analysis, and Reporting","type":"control"},{"id":"ctrl:nist-800-53:AU-7","rendered":false,"sources":["nist-800-53"],"title":"AU-7 — Audit Record Reduction and Report Generation","type":"control"},{"id":"ctrl:nist-800-53:AU-8","rendered":false,"sources":["nist-800-53"],"title":"AU-8 — Time Stamps","type":"control"},{"id":"ctrl:nist-800-53:AU-9","rendered":false,"sources":["nist-800-53"],"title":"AU-9 — Protection of Audit Information","type":"control"},{"id":"ctrl:nist-800-53:CA-1","rendered":false,"sources":["nist-800-53"],"title":"CA-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:CA-2","rendered":false,"sources":["nist-800-53"],"title":"CA-2 — Control Assessments","type":"control"},{"id":"ctrl:nist-800-53:CA-3","rendered":false,"sources":["nist-800-53"],"title":"CA-3 — Information Exchange","type":"control"},{"id":"ctrl:nist-800-53:CA-5","rendered":false,"sources":["nist-800-53"],"title":"CA-5 — Plan of Action and Milestones","type":"control"},{"id":"ctrl:nist-800-53:CA-6","rendered":false,"sources":["nist-800-53"],"title":"CA-6 — Authorization","type":"control"},{"id":"ctrl:nist-800-53:CA-7","rendered":false,"sources":["nist-800-53"],"title":"CA-7 — Continuous Monitoring","type":"control"},{"id":"ctrl:nist-800-53:CA-8","rendered":false,"sources":["nist-800-53"],"title":"CA-8 — Penetration Testing","type":"control"},{"id":"ctrl:nist-800-53:CA-9","rendered":false,"sources":["nist-800-53"],"title":"CA-9 — Internal System Connections","type":"control"},{"id":"ctrl:nist-800-53:CM-1","rendered":false,"sources":["nist-800-53"],"title":"CM-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:CM-10","rendered":false,"sources":["nist-800-53"],"title":"CM-10 — Software Usage Restrictions","type":"control"},{"id":"ctrl:nist-800-53:CM-11","rendered":false,"sources":["nist-800-53"],"title":"CM-11 — User-installed Software","type":"control"},{"id":"ctrl:nist-800-53:CM-12","rendered":false,"sources":["nist-800-53"],"title":"CM-12 — Information Location","type":"control"},{"id":"ctrl:nist-800-53:CM-13","rendered":false,"sources":["nist-800-53"],"title":"CM-13 — Data Action Mapping","type":"control"},{"id":"ctrl:nist-800-53:CM-14","rendered":false,"sources":["nist-800-53"],"title":"CM-14 — Signed Components","type":"control"},{"id":"ctrl:nist-800-53:CM-2","rendered":false,"sources":["nist-800-53"],"title":"CM-2 — Baseline Configuration","type":"control"},{"id":"ctrl:nist-800-53:CM-3","rendered":false,"sources":["nist-800-53"],"title":"CM-3 — Configuration Change Control","type":"control"},{"id":"ctrl:nist-800-53:CM-4","rendered":false,"sources":["nist-800-53"],"title":"CM-4 — Impact Analyses","type":"control"},{"id":"ctrl:nist-800-53:CM-5","rendered":false,"sources":["nist-800-53"],"title":"CM-5 — Access Restrictions for Change","type":"control"},{"id":"ctrl:nist-800-53:CM-6","rendered":false,"sources":["nist-800-53"],"title":"CM-6 — Configuration Settings","type":"control"},{"id":"ctrl:nist-800-53:CM-7","rendered":false,"sources":["nist-800-53"],"title":"CM-7 — Least Functionality","type":"control"},{"id":"ctrl:nist-800-53:CM-8","rendered":false,"sources":["nist-800-53"],"title":"CM-8 — System Component Inventory","type":"control"},{"id":"ctrl:nist-800-53:CM-9","rendered":false,"sources":["nist-800-53"],"title":"CM-9 — Configuration Management Plan","type":"control"},{"id":"ctrl:nist-800-53:CP-1","rendered":false,"sources":["nist-800-53"],"title":"CP-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:CP-10","rendered":false,"sources":["nist-800-53"],"title":"CP-10 — System Recovery and Reconstitution","type":"control"},{"id":"ctrl:nist-800-53:CP-11","rendered":false,"sources":["nist-800-53"],"title":"CP-11 — Alternate Communications Protocols","type":"control"},{"id":"ctrl:nist-800-53:CP-12","rendered":false,"sources":["nist-800-53"],"title":"CP-12 — Safe Mode","type":"control"},{"id":"ctrl:nist-800-53:CP-13","rendered":false,"sources":["nist-800-53"],"title":"CP-13 — Alternative Security Mechanisms","type":"control"},{"id":"ctrl:nist-800-53:CP-2","rendered":false,"sources":["nist-800-53"],"title":"CP-2 — Contingency Plan","type":"control"},{"id":"ctrl:nist-800-53:CP-3","rendered":false,"sources":["nist-800-53"],"title":"CP-3 — Contingency Training","type":"control"},{"id":"ctrl:nist-800-53:CP-4","rendered":false,"sources":["nist-800-53"],"title":"CP-4 — Contingency Plan Testing","type":"control"},{"id":"ctrl:nist-800-53:CP-6","rendered":false,"sources":["nist-800-53"],"title":"CP-6 — Alternate Storage Site","type":"control"},{"id":"ctrl:nist-800-53:CP-7","rendered":false,"sources":["nist-800-53"],"title":"CP-7 — Alternate Processing Site","type":"control"},{"id":"ctrl:nist-800-53:CP-8","rendered":false,"sources":["nist-800-53"],"title":"CP-8 — Telecommunications Services","type":"control"},{"id":"ctrl:nist-800-53:CP-9","rendered":false,"sources":["nist-800-53"],"title":"CP-9 — System Backup","type":"control"},{"id":"ctrl:nist-800-53:IA-1","rendered":false,"sources":["nist-800-53"],"title":"IA-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:IA-10","rendered":false,"sources":["nist-800-53"],"title":"IA-10 — Adaptive Authentication","type":"control"},{"id":"ctrl:nist-800-53:IA-11","rendered":false,"sources":["nist-800-53"],"title":"IA-11 — Re-authentication","type":"control"},{"id":"ctrl:nist-800-53:IA-12","rendered":false,"sources":["nist-800-53"],"title":"IA-12 — Identity Proofing","type":"control"},{"id":"ctrl:nist-800-53:IA-2","rendered":false,"sources":["nist-800-53"],"title":"IA-2 — Identification and Authentication (Organizational Users)","type":"control"},{"id":"ctrl:nist-800-53:IA-3","rendered":false,"sources":["nist-800-53"],"title":"IA-3 — Device Identification and Authentication","type":"control"},{"id":"ctrl:nist-800-53:IA-4","rendered":false,"sources":["nist-800-53"],"title":"IA-4 — Identifier Management","type":"control"},{"id":"ctrl:nist-800-53:IA-5","rendered":false,"sources":["nist-800-53"],"title":"IA-5 — Authenticator Management","type":"control"},{"id":"ctrl:nist-800-53:IA-6","rendered":false,"sources":["nist-800-53"],"title":"IA-6 — Authentication Feedback","type":"control"},{"id":"ctrl:nist-800-53:IA-7","rendered":false,"sources":["nist-800-53"],"title":"IA-7 — Cryptographic Module Authentication","type":"control"},{"id":"ctrl:nist-800-53:IA-8","rendered":false,"sources":["nist-800-53"],"title":"IA-8 — Identification and Authentication (Non-organizational Users)","type":"control"},{"id":"ctrl:nist-800-53:IA-9","rendered":false,"sources":["nist-800-53"],"title":"IA-9 — Service Identification and Authentication","type":"control"},{"id":"ctrl:nist-800-53:IR-1","rendered":false,"sources":["nist-800-53"],"title":"IR-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:IR-2","rendered":false,"sources":["nist-800-53"],"title":"IR-2 — Incident Response Training","type":"control"},{"id":"ctrl:nist-800-53:IR-3","rendered":false,"sources":["nist-800-53"],"title":"IR-3 — Incident Response Testing","type":"control"},{"id":"ctrl:nist-800-53:IR-4","rendered":false,"sources":["nist-800-53"],"title":"IR-4 — Incident Handling","type":"control"},{"id":"ctrl:nist-800-53:IR-5","rendered":false,"sources":["nist-800-53"],"title":"IR-5 — Incident Monitoring","type":"control"},{"id":"ctrl:nist-800-53:IR-6","rendered":false,"sources":["nist-800-53"],"title":"IR-6 — Incident Reporting","type":"control"},{"id":"ctrl:nist-800-53:IR-7","rendered":false,"sources":["nist-800-53"],"title":"IR-7 — Incident Response Assistance","type":"control"},{"id":"ctrl:nist-800-53:IR-8","rendered":false,"sources":["nist-800-53"],"title":"IR-8 — Incident Response Plan","type":"control"},{"id":"ctrl:nist-800-53:IR-9","rendered":false,"sources":["nist-800-53"],"title":"IR-9 — Information Spillage Response","type":"control"},{"id":"ctrl:nist-800-53:MA-1","rendered":false,"sources":["nist-800-53"],"title":"MA-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:MA-2","rendered":false,"sources":["nist-800-53"],"title":"MA-2 — Controlled Maintenance","type":"control"},{"id":"ctrl:nist-800-53:MA-3","rendered":false,"sources":["nist-800-53"],"title":"MA-3 — Maintenance Tools","type":"control"},{"id":"ctrl:nist-800-53:MA-4","rendered":false,"sources":["nist-800-53"],"title":"MA-4 — Nonlocal Maintenance","type":"control"},{"id":"ctrl:nist-800-53:MA-5","rendered":false,"sources":["nist-800-53"],"title":"MA-5 — Maintenance Personnel","type":"control"},{"id":"ctrl:nist-800-53:MA-6","rendered":false,"sources":["nist-800-53"],"title":"MA-6 — Timely Maintenance","type":"control"},{"id":"ctrl:nist-800-53:MA-7","rendered":false,"sources":["nist-800-53"],"title":"MA-7 — Field Maintenance","type":"control"},{"id":"ctrl:nist-800-53:MP-1","rendered":false,"sources":["nist-800-53"],"title":"MP-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:MP-2","rendered":false,"sources":["nist-800-53"],"title":"MP-2 — Media Access","type":"control"},{"id":"ctrl:nist-800-53:MP-3","rendered":false,"sources":["nist-800-53"],"title":"MP-3 — Media Marking","type":"control"},{"id":"ctrl:nist-800-53:MP-4","rendered":false,"sources":["nist-800-53"],"title":"MP-4 — Media Storage","type":"control"},{"id":"ctrl:nist-800-53:MP-5","rendered":false,"sources":["nist-800-53"],"title":"MP-5 — Media Transport","type":"control"},{"id":"ctrl:nist-800-53:MP-6","rendered":false,"sources":["nist-800-53"],"title":"MP-6 — Media Sanitization","type":"control"},{"id":"ctrl:nist-800-53:MP-7","rendered":false,"sources":["nist-800-53"],"title":"MP-7 — Media Use","type":"control"},{"id":"ctrl:nist-800-53:MP-8","rendered":false,"sources":["nist-800-53"],"title":"MP-8 — Media Downgrading","type":"control"},{"id":"ctrl:nist-800-53:PE-1","rendered":false,"sources":["nist-800-53"],"title":"PE-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:PE-10","rendered":false,"sources":["nist-800-53"],"title":"PE-10 — Emergency Shutoff","type":"control"},{"id":"ctrl:nist-800-53:PE-11","rendered":false,"sources":["nist-800-53"],"title":"PE-11 — Emergency Power","type":"control"},{"id":"ctrl:nist-800-53:PE-12","rendered":false,"sources":["nist-800-53"],"title":"PE-12 — Emergency Lighting","type":"control"},{"id":"ctrl:nist-800-53:PE-13","rendered":false,"sources":["nist-800-53"],"title":"PE-13 — Fire Protection","type":"control"},{"id":"ctrl:nist-800-53:PE-14","rendered":false,"sources":["nist-800-53"],"title":"PE-14 — Environmental Controls","type":"control"},{"id":"ctrl:nist-800-53:PE-15","rendered":false,"sources":["nist-800-53"],"title":"PE-15 — Water Damage Protection","type":"control"},{"id":"ctrl:nist-800-53:PE-16","rendered":false,"sources":["nist-800-53"],"title":"PE-16 — Delivery and Removal","type":"control"},{"id":"ctrl:nist-800-53:PE-17","rendered":false,"sources":["nist-800-53"],"title":"PE-17 — Alternate Work Site","type":"control"},{"id":"ctrl:nist-800-53:PE-18","rendered":false,"sources":["nist-800-53"],"title":"PE-18 — Location of System Components","type":"control"},{"id":"ctrl:nist-800-53:PE-19","rendered":false,"sources":["nist-800-53"],"title":"PE-19 — Information Leakage","type":"control"},{"id":"ctrl:nist-800-53:PE-2","rendered":false,"sources":["nist-800-53"],"title":"PE-2 — Physical Access Authorizations","type":"control"},{"id":"ctrl:nist-800-53:PE-20","rendered":false,"sources":["nist-800-53"],"title":"PE-20 — Asset Monitoring and Tracking","type":"control"},{"id":"ctrl:nist-800-53:PE-21","rendered":false,"sources":["nist-800-53"],"title":"PE-21 — Electromagnetic Pulse Protection","type":"control"},{"id":"ctrl:nist-800-53:PE-22","rendered":false,"sources":["nist-800-53"],"title":"PE-22 — Component Marking","type":"control"},{"id":"ctrl:nist-800-53:PE-23","rendered":false,"sources":["nist-800-53"],"title":"PE-23 — Facility Location","type":"control"},{"id":"ctrl:nist-800-53:PE-3","rendered":false,"sources":["nist-800-53"],"title":"PE-3 — Physical Access Control","type":"control"},{"id":"ctrl:nist-800-53:PE-4","rendered":false,"sources":["nist-800-53"],"title":"PE-4 — Access Control for Transmission","type":"control"},{"id":"ctrl:nist-800-53:PE-5","rendered":false,"sources":["nist-800-53"],"title":"PE-5 — Access Control for Output Devices","type":"control"},{"id":"ctrl:nist-800-53:PE-6","rendered":false,"sources":["nist-800-53"],"title":"PE-6 — Monitoring Physical Access","type":"control"},{"id":"ctrl:nist-800-53:PE-8","rendered":false,"sources":["nist-800-53"],"title":"PE-8 — Visitor Access Records","type":"control"},{"id":"ctrl:nist-800-53:PE-9","rendered":false,"sources":["nist-800-53"],"title":"PE-9 — Power Equipment and Cabling","type":"control"},{"id":"ctrl:nist-800-53:PL-1","rendered":false,"sources":["nist-800-53"],"title":"PL-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:PL-10","rendered":false,"sources":["nist-800-53"],"title":"PL-10 — Baseline Selection","type":"control"},{"id":"ctrl:nist-800-53:PL-11","rendered":false,"sources":["nist-800-53"],"title":"PL-11 — Baseline Tailoring","type":"control"},{"id":"ctrl:nist-800-53:PL-2","rendered":false,"sources":["nist-800-53"],"title":"PL-2 — System Security and Privacy Plans","type":"control"},{"id":"ctrl:nist-800-53:PL-4","rendered":false,"sources":["nist-800-53"],"title":"PL-4 — Rules of Behavior","type":"control"},{"id":"ctrl:nist-800-53:PL-7","rendered":false,"sources":["nist-800-53"],"title":"PL-7 — Concept of Operations","type":"control"},{"id":"ctrl:nist-800-53:PL-8","rendered":false,"sources":["nist-800-53"],"title":"PL-8 — Security and Privacy Architectures","type":"control"},{"id":"ctrl:nist-800-53:PL-9","rendered":false,"sources":["nist-800-53"],"title":"PL-9 — Central Management","type":"control"},{"id":"ctrl:nist-800-53:PM-1","rendered":false,"sources":["nist-800-53"],"title":"PM-1 — Information Security Program Plan","type":"control"},{"id":"ctrl:nist-800-53:PM-10","rendered":false,"sources":["nist-800-53"],"title":"PM-10 — Authorization Process","type":"control"},{"id":"ctrl:nist-800-53:PM-11","rendered":false,"sources":["nist-800-53"],"title":"PM-11 — Mission and Business Process Definition","type":"control"},{"id":"ctrl:nist-800-53:PM-12","rendered":false,"sources":["nist-800-53"],"title":"PM-12 — Insider Threat Program","type":"control"},{"id":"ctrl:nist-800-53:PM-13","rendered":false,"sources":["nist-800-53"],"title":"PM-13 — Security and Privacy Workforce","type":"control"},{"id":"ctrl:nist-800-53:PM-14","rendered":false,"sources":["nist-800-53"],"title":"PM-14 — Testing, Training, and Monitoring","type":"control"},{"id":"ctrl:nist-800-53:PM-15","rendered":false,"sources":["nist-800-53"],"title":"PM-15 — Security and Privacy Groups and Associations","type":"control"},{"id":"ctrl:nist-800-53:PM-16","rendered":false,"sources":["nist-800-53"],"title":"PM-16 — Threat Awareness Program","type":"control"},{"id":"ctrl:nist-800-53:PM-17","rendered":false,"sources":["nist-800-53"],"title":"PM-17 — Protecting Controlled Unclassified Information on External Systems","type":"control"},{"id":"ctrl:nist-800-53:PM-18","rendered":false,"sources":["nist-800-53"],"title":"PM-18 — Privacy Program Plan","type":"control"},{"id":"ctrl:nist-800-53:PM-19","rendered":false,"sources":["nist-800-53"],"title":"PM-19 — Privacy Program Leadership Role","type":"control"},{"id":"ctrl:nist-800-53:PM-2","rendered":false,"sources":["nist-800-53"],"title":"PM-2 — Information Security Program Leadership Role","type":"control"},{"id":"ctrl:nist-800-53:PM-20","rendered":false,"sources":["nist-800-53"],"title":"PM-20 — Dissemination of Privacy Program Information","type":"control"},{"id":"ctrl:nist-800-53:PM-21","rendered":false,"sources":["nist-800-53"],"title":"PM-21 — Accounting of Disclosures","type":"control"},{"id":"ctrl:nist-800-53:PM-22","rendered":false,"sources":["nist-800-53"],"title":"PM-22 — Personally Identifiable Information Quality Management","type":"control"},{"id":"ctrl:nist-800-53:PM-23","rendered":false,"sources":["nist-800-53"],"title":"PM-23 — Data Governance Body","type":"control"},{"id":"ctrl:nist-800-53:PM-24","rendered":false,"sources":["nist-800-53"],"title":"PM-24 — Data Integrity Board","type":"control"},{"id":"ctrl:nist-800-53:PM-25","rendered":false,"sources":["nist-800-53"],"title":"PM-25 — Minimization of Personally Identifiable Information Used in Testing, Training, and Research","type":"control"},{"id":"ctrl:nist-800-53:PM-26","rendered":false,"sources":["nist-800-53"],"title":"PM-26 — Complaint Management","type":"control"},{"id":"ctrl:nist-800-53:PM-27","rendered":false,"sources":["nist-800-53"],"title":"PM-27 — Privacy Reporting","type":"control"},{"id":"ctrl:nist-800-53:PM-28","rendered":false,"sources":["nist-800-53"],"title":"PM-28 — Risk Framing","type":"control"},{"id":"ctrl:nist-800-53:PM-29","rendered":false,"sources":["nist-800-53"],"title":"PM-29 — Risk Management Program Leadership Roles","type":"control"},{"id":"ctrl:nist-800-53:PM-3","rendered":false,"sources":["nist-800-53"],"title":"PM-3 — Information Security and Privacy Resources","type":"control"},{"id":"ctrl:nist-800-53:PM-30","rendered":false,"sources":["nist-800-53"],"title":"PM-30 — Supply Chain Risk Management Strategy","type":"control"},{"id":"ctrl:nist-800-53:PM-31","rendered":false,"sources":["nist-800-53"],"title":"PM-31 — Continuous Monitoring Strategy","type":"control"},{"id":"ctrl:nist-800-53:PM-32","rendered":false,"sources":["nist-800-53"],"title":"PM-32 — Purposing","type":"control"},{"id":"ctrl:nist-800-53:PM-4","rendered":false,"sources":["nist-800-53"],"title":"PM-4 — Plan of Action and Milestones Process","type":"control"},{"id":"ctrl:nist-800-53:PM-5","rendered":false,"sources":["nist-800-53"],"title":"PM-5 — System Inventory","type":"control"},{"id":"ctrl:nist-800-53:PM-6","rendered":false,"sources":["nist-800-53"],"title":"PM-6 — Measures of Performance","type":"control"},{"id":"ctrl:nist-800-53:PM-7","rendered":false,"sources":["nist-800-53"],"title":"PM-7 — Enterprise Architecture","type":"control"},{"id":"ctrl:nist-800-53:PM-8","rendered":false,"sources":["nist-800-53"],"title":"PM-8 — Critical Infrastructure Plan","type":"control"},{"id":"ctrl:nist-800-53:PM-9","rendered":false,"sources":["nist-800-53"],"title":"PM-9 — Risk Management Strategy","type":"control"},{"id":"ctrl:nist-800-53:PS-1","rendered":false,"sources":["nist-800-53"],"title":"PS-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:PS-2","rendered":false,"sources":["nist-800-53"],"title":"PS-2 — Position Risk Designation","type":"control"},{"id":"ctrl:nist-800-53:PS-3","rendered":false,"sources":["nist-800-53"],"title":"PS-3 — Personnel Screening","type":"control"},{"id":"ctrl:nist-800-53:PS-4","rendered":false,"sources":["nist-800-53"],"title":"PS-4 — Personnel Termination","type":"control"},{"id":"ctrl:nist-800-53:PS-5","rendered":false,"sources":["nist-800-53"],"title":"PS-5 — Personnel Transfer","type":"control"},{"id":"ctrl:nist-800-53:PS-6","rendered":false,"sources":["nist-800-53"],"title":"PS-6 — Access Agreements","type":"control"},{"id":"ctrl:nist-800-53:PS-7","rendered":false,"sources":["nist-800-53"],"title":"PS-7 — External Personnel Security","type":"control"},{"id":"ctrl:nist-800-53:PS-8","rendered":false,"sources":["nist-800-53"],"title":"PS-8 — Personnel Sanctions","type":"control"},{"id":"ctrl:nist-800-53:PS-9","rendered":false,"sources":["nist-800-53"],"title":"PS-9 — Position Descriptions","type":"control"},{"id":"ctrl:nist-800-53:PT-1","rendered":false,"sources":["nist-800-53"],"title":"PT-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:PT-2","rendered":false,"sources":["nist-800-53"],"title":"PT-2 — Authority to Process Personally Identifiable Information","type":"control"},{"id":"ctrl:nist-800-53:PT-3","rendered":false,"sources":["nist-800-53"],"title":"PT-3 — Personally Identifiable Information Processing Purposes","type":"control"},{"id":"ctrl:nist-800-53:PT-4","rendered":false,"sources":["nist-800-53"],"title":"PT-4 — Consent","type":"control"},{"id":"ctrl:nist-800-53:PT-5","rendered":false,"sources":["nist-800-53"],"title":"PT-5 — Privacy Notice","type":"control"},{"id":"ctrl:nist-800-53:PT-6","rendered":false,"sources":["nist-800-53"],"title":"PT-6 — System of Records Notice","type":"control"},{"id":"ctrl:nist-800-53:PT-7","rendered":false,"sources":["nist-800-53"],"title":"PT-7 — Specific Categories of Personally Identifiable Information","type":"control"},{"id":"ctrl:nist-800-53:PT-8","rendered":false,"sources":["nist-800-53"],"title":"PT-8 — Computer Matching Requirements","type":"control"},{"id":"ctrl:nist-800-53:RA-1","rendered":false,"sources":["nist-800-53"],"title":"RA-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:RA-10","rendered":false,"sources":["nist-800-53"],"title":"RA-10 — Threat Hunting","type":"control"},{"id":"ctrl:nist-800-53:RA-2","rendered":false,"sources":["nist-800-53"],"title":"RA-2 — Security Categorization","type":"control"},{"id":"ctrl:nist-800-53:RA-3","rendered":false,"sources":["nist-800-53"],"title":"RA-3 — Risk Assessment","type":"control"},{"id":"ctrl:nist-800-53:RA-5","rendered":false,"sources":["nist-800-53"],"title":"RA-5 — Vulnerability Monitoring and Scanning","type":"control"},{"id":"ctrl:nist-800-53:RA-7","rendered":false,"sources":["nist-800-53"],"title":"RA-7 — Risk Response","type":"control"},{"id":"ctrl:nist-800-53:RA-8","rendered":false,"sources":["nist-800-53"],"title":"RA-8 — Privacy Impact Assessments","type":"control"},{"id":"ctrl:nist-800-53:RA-9","rendered":false,"sources":["nist-800-53"],"title":"RA-9 — Criticality Analysis","type":"control"},{"id":"ctrl:nist-800-53:SA-1","rendered":false,"sources":["nist-800-53"],"title":"SA-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:SA-10","rendered":false,"sources":["nist-800-53"],"title":"SA-10 — Developer Configuration Management","type":"control"},{"id":"ctrl:nist-800-53:SA-11","rendered":false,"sources":["nist-800-53"],"title":"SA-11 — Developer Testing and Evaluation","type":"control"},{"id":"ctrl:nist-800-53:SA-15","rendered":false,"sources":["nist-800-53"],"title":"SA-15 — Development Process, Standards, and Tools","type":"control"},{"id":"ctrl:nist-800-53:SA-16","rendered":false,"sources":["nist-800-53"],"title":"SA-16 — Developer-provided Training","type":"control"},{"id":"ctrl:nist-800-53:SA-17","rendered":false,"sources":["nist-800-53"],"title":"SA-17 — Developer Security and Privacy Architecture and Design","type":"control"},{"id":"ctrl:nist-800-53:SA-2","rendered":false,"sources":["nist-800-53"],"title":"SA-2 — Allocation of Resources","type":"control"},{"id":"ctrl:nist-800-53:SA-20","rendered":false,"sources":["nist-800-53"],"title":"SA-20 — Customized Development of Critical Components","type":"control"},{"id":"ctrl:nist-800-53:SA-21","rendered":false,"sources":["nist-800-53"],"title":"SA-21 — Developer Screening","type":"control"},{"id":"ctrl:nist-800-53:SA-22","rendered":false,"sources":["nist-800-53"],"title":"SA-22 — Unsupported System Components","type":"control"},{"id":"ctrl:nist-800-53:SA-23","rendered":false,"sources":["nist-800-53"],"title":"SA-23 — Specialization","type":"control"},{"id":"ctrl:nist-800-53:SA-3","rendered":false,"sources":["nist-800-53"],"title":"SA-3 — System Development Life Cycle","type":"control"},{"id":"ctrl:nist-800-53:SA-4","rendered":false,"sources":["nist-800-53"],"title":"SA-4 — Acquisition Process","type":"control"},{"id":"ctrl:nist-800-53:SA-5","rendered":false,"sources":["nist-800-53"],"title":"SA-5 — System Documentation","type":"control"},{"id":"ctrl:nist-800-53:SA-8","rendered":false,"sources":["nist-800-53"],"title":"SA-8 — Security and Privacy Engineering Principles","type":"control"},{"id":"ctrl:nist-800-53:SA-9","rendered":false,"sources":["nist-800-53"],"title":"SA-9 — External System Services","type":"control"},{"id":"ctrl:nist-800-53:SC-1","rendered":false,"sources":["nist-800-53"],"title":"SC-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:SC-10","rendered":false,"sources":["nist-800-53"],"title":"SC-10 — Network Disconnect","type":"control"},{"id":"ctrl:nist-800-53:SC-11","rendered":false,"sources":["nist-800-53"],"title":"SC-11 — Trusted Path","type":"control"},{"id":"ctrl:nist-800-53:SC-12","rendered":false,"sources":["nist-800-53"],"title":"SC-12 — Cryptographic Key Establishment and Management","type":"control"},{"id":"ctrl:nist-800-53:SC-13","rendered":false,"sources":["nist-800-53"],"title":"SC-13 — Cryptographic Protection","type":"control"},{"id":"ctrl:nist-800-53:SC-15","rendered":false,"sources":["nist-800-53"],"title":"SC-15 — Collaborative Computing Devices and Applications","type":"control"},{"id":"ctrl:nist-800-53:SC-16","rendered":false,"sources":["nist-800-53"],"title":"SC-16 — Transmission of Security and Privacy Attributes","type":"control"},{"id":"ctrl:nist-800-53:SC-17","rendered":false,"sources":["nist-800-53"],"title":"SC-17 — Public Key Infrastructure Certificates","type":"control"},{"id":"ctrl:nist-800-53:SC-18","rendered":false,"sources":["nist-800-53"],"title":"SC-18 — Mobile Code","type":"control"},{"id":"ctrl:nist-800-53:SC-2","rendered":false,"sources":["nist-800-53"],"title":"SC-2 — Separation of System and User Functionality","type":"control"},{"id":"ctrl:nist-800-53:SC-20","rendered":false,"sources":["nist-800-53"],"title":"SC-20 — Secure Name/Address Resolution Service (Authoritative Source)","type":"control"},{"id":"ctrl:nist-800-53:SC-21","rendered":false,"sources":["nist-800-53"],"title":"SC-21 — Secure Name/Address Resolution Service (Recursive or Caching Resolver)","type":"control"},{"id":"ctrl:nist-800-53:SC-22","rendered":false,"sources":["nist-800-53"],"title":"SC-22 — Architecture and Provisioning for Name/Address Resolution Service","type":"control"},{"id":"ctrl:nist-800-53:SC-23","rendered":false,"sources":["nist-800-53"],"title":"SC-23 — Session Authenticity","type":"control"},{"id":"ctrl:nist-800-53:SC-24","rendered":false,"sources":["nist-800-53"],"title":"SC-24 — Fail in Known State","type":"control"},{"id":"ctrl:nist-800-53:SC-25","rendered":false,"sources":["nist-800-53"],"title":"SC-25 — Thin Nodes","type":"control"},{"id":"ctrl:nist-800-53:SC-26","rendered":false,"sources":["nist-800-53"],"title":"SC-26 — Decoys","type":"control"},{"id":"ctrl:nist-800-53:SC-28","rendered":false,"sources":["nist-800-53"],"title":"SC-28 — Protection of Information at Rest","type":"control"},{"id":"ctrl:nist-800-53:SC-29","rendered":false,"sources":["nist-800-53"],"title":"SC-29 — Heterogeneity","type":"control"},{"id":"ctrl:nist-800-53:SC-3","rendered":false,"sources":["nist-800-53"],"title":"SC-3 — Security Function Isolation","type":"control"},{"id":"ctrl:nist-800-53:SC-30","rendered":false,"sources":["nist-800-53"],"title":"SC-30 — Concealment and Misdirection","type":"control"},{"id":"ctrl:nist-800-53:SC-31","rendered":false,"sources":["nist-800-53"],"title":"SC-31 — Covert Channel Analysis","type":"control"},{"id":"ctrl:nist-800-53:SC-32","rendered":false,"sources":["nist-800-53"],"title":"SC-32 — System Partitioning","type":"control"},{"id":"ctrl:nist-800-53:SC-34","rendered":false,"sources":["nist-800-53"],"title":"SC-34 — Non-modifiable Executable Programs","type":"control"},{"id":"ctrl:nist-800-53:SC-35","rendered":false,"sources":["nist-800-53"],"title":"SC-35 — External Malicious Code Identification","type":"control"},{"id":"ctrl:nist-800-53:SC-36","rendered":false,"sources":["nist-800-53"],"title":"SC-36 — Distributed Processing and Storage","type":"control"},{"id":"ctrl:nist-800-53:SC-37","rendered":false,"sources":["nist-800-53"],"title":"SC-37 — Out-of-band Channels","type":"control"},{"id":"ctrl:nist-800-53:SC-38","rendered":false,"sources":["nist-800-53"],"title":"SC-38 — Operations Security","type":"control"},{"id":"ctrl:nist-800-53:SC-39","rendered":false,"sources":["nist-800-53"],"title":"SC-39 — Process Isolation","type":"control"},{"id":"ctrl:nist-800-53:SC-4","rendered":false,"sources":["nist-800-53"],"title":"SC-4 — Information in Shared System Resources","type":"control"},{"id":"ctrl:nist-800-53:SC-40","rendered":false,"sources":["nist-800-53"],"title":"SC-40 — Wireless Link Protection","type":"control"},{"id":"ctrl:nist-800-53:SC-41","rendered":false,"sources":["nist-800-53"],"title":"SC-41 — Port and I/O Device Access","type":"control"},{"id":"ctrl:nist-800-53:SC-42","rendered":false,"sources":["nist-800-53"],"title":"SC-42 — Sensor Capability and Data","type":"control"},{"id":"ctrl:nist-800-53:SC-43","rendered":false,"sources":["nist-800-53"],"title":"SC-43 — Usage Restrictions","type":"control"},{"id":"ctrl:nist-800-53:SC-44","rendered":false,"sources":["nist-800-53"],"title":"SC-44 — Detonation Chambers","type":"control"},{"id":"ctrl:nist-800-53:SC-45","rendered":false,"sources":["nist-800-53"],"title":"SC-45 — System Time Synchronization","type":"control"},{"id":"ctrl:nist-800-53:SC-46","rendered":false,"sources":["nist-800-53"],"title":"SC-46 — Cross Domain Policy Enforcement","type":"control"},{"id":"ctrl:nist-800-53:SC-47","rendered":false,"sources":["nist-800-53"],"title":"SC-47 — Alternate Communications Paths","type":"control"},{"id":"ctrl:nist-800-53:SC-48","rendered":false,"sources":["nist-800-53"],"title":"SC-48 — Sensor Relocation","type":"control"},{"id":"ctrl:nist-800-53:SC-49","rendered":false,"sources":["nist-800-53"],"title":"SC-49 — Hardware-enforced Separation and Policy Enforcement","type":"control"},{"id":"ctrl:nist-800-53:SC-5","rendered":false,"sources":["nist-800-53"],"title":"SC-5 — Denial-of-service Protection","type":"control"},{"id":"ctrl:nist-800-53:SC-50","rendered":false,"sources":["nist-800-53"],"title":"SC-50 — Software-enforced Separation and Policy Enforcement","type":"control"},{"id":"ctrl:nist-800-53:SC-51","rendered":false,"sources":["nist-800-53"],"title":"SC-51 — Hardware-based Protection","type":"control"},{"id":"ctrl:nist-800-53:SC-6","rendered":false,"sources":["nist-800-53"],"title":"SC-6 — Resource Availability","type":"control"},{"id":"ctrl:nist-800-53:SC-7","rendered":false,"sources":["nist-800-53"],"title":"SC-7 — Boundary Protection","type":"control"},{"id":"ctrl:nist-800-53:SC-8","rendered":false,"sources":["nist-800-53"],"title":"SC-8 — Transmission Confidentiality and Integrity","type":"control"},{"id":"ctrl:nist-800-53:SI-1","rendered":false,"sources":["nist-800-53"],"title":"SI-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:SI-10","rendered":false,"sources":["nist-800-53"],"title":"SI-10 — Information Input Validation","type":"control"},{"id":"ctrl:nist-800-53:SI-11","rendered":false,"sources":["nist-800-53"],"title":"SI-11 — Error Handling","type":"control"},{"id":"ctrl:nist-800-53:SI-12","rendered":false,"sources":["nist-800-53"],"title":"SI-12 — Information Management and Retention","type":"control"},{"id":"ctrl:nist-800-53:SI-13","rendered":false,"sources":["nist-800-53"],"title":"SI-13 — Predictable Failure Prevention","type":"control"},{"id":"ctrl:nist-800-53:SI-14","rendered":false,"sources":["nist-800-53"],"title":"SI-14 — Non-persistence","type":"control"},{"id":"ctrl:nist-800-53:SI-15","rendered":false,"sources":["nist-800-53"],"title":"SI-15 — Information Output Filtering","type":"control"},{"id":"ctrl:nist-800-53:SI-16","rendered":false,"sources":["nist-800-53"],"title":"SI-16 — Memory Protection","type":"control"},{"id":"ctrl:nist-800-53:SI-17","rendered":false,"sources":["nist-800-53"],"title":"SI-17 — Fail-safe Procedures","type":"control"},{"id":"ctrl:nist-800-53:SI-18","rendered":false,"sources":["nist-800-53"],"title":"SI-18 — Personally Identifiable Information Quality Operations","type":"control"},{"id":"ctrl:nist-800-53:SI-19","rendered":false,"sources":["nist-800-53"],"title":"SI-19 — De-identification","type":"control"},{"id":"ctrl:nist-800-53:SI-2","rendered":false,"sources":["nist-800-53"],"title":"SI-2 — Flaw Remediation","type":"control"},{"id":"ctrl:nist-800-53:SI-20","rendered":false,"sources":["nist-800-53"],"title":"SI-20 — Tainting","type":"control"},{"id":"ctrl:nist-800-53:SI-21","rendered":false,"sources":["nist-800-53"],"title":"SI-21 — Information Refresh","type":"control"},{"id":"ctrl:nist-800-53:SI-22","rendered":false,"sources":["nist-800-53"],"title":"SI-22 — Information Diversity","type":"control"},{"id":"ctrl:nist-800-53:SI-23","rendered":false,"sources":["nist-800-53"],"title":"SI-23 — Information Fragmentation","type":"control"},{"id":"ctrl:nist-800-53:SI-3","rendered":false,"sources":["nist-800-53"],"title":"SI-3 — Malicious Code Protection","type":"control"},{"id":"ctrl:nist-800-53:SI-4","rendered":false,"sources":["nist-800-53"],"title":"SI-4 — System Monitoring","type":"control"},{"id":"ctrl:nist-800-53:SI-5","rendered":false,"sources":["nist-800-53"],"title":"SI-5 — Security Alerts, Advisories, and Directives","type":"control"},{"id":"ctrl:nist-800-53:SI-6","rendered":false,"sources":["nist-800-53"],"title":"SI-6 — Security and Privacy Function Verification","type":"control"},{"id":"ctrl:nist-800-53:SI-7","rendered":false,"sources":["nist-800-53"],"title":"SI-7 — Software, Firmware, and Information Integrity","type":"control"},{"id":"ctrl:nist-800-53:SI-8","rendered":false,"sources":["nist-800-53"],"title":"SI-8 — Spam Protection","type":"control"},{"id":"ctrl:nist-800-53:SR-1","rendered":false,"sources":["nist-800-53"],"title":"SR-1 — Policy and Procedures","type":"control"},{"id":"ctrl:nist-800-53:SR-10","rendered":false,"sources":["nist-800-53"],"title":"SR-10 — Inspection of Systems or Components","type":"control"},{"id":"ctrl:nist-800-53:SR-11","rendered":false,"sources":["nist-800-53"],"title":"SR-11 — Component Authenticity","type":"control"},{"id":"ctrl:nist-800-53:SR-12","rendered":false,"sources":["nist-800-53"],"title":"SR-12 — Component Disposal","type":"control"},{"id":"ctrl:nist-800-53:SR-2","rendered":false,"sources":["nist-800-53"],"title":"SR-2 — Supply Chain Risk Management Plan","type":"control"},{"id":"ctrl:nist-800-53:SR-3","rendered":false,"sources":["nist-800-53"],"title":"SR-3 — Supply Chain Controls and Processes","type":"control"},{"id":"ctrl:nist-800-53:SR-4","rendered":false,"sources":["nist-800-53"],"title":"SR-4 — Provenance","type":"control"},{"id":"ctrl:nist-800-53:SR-5","rendered":false,"sources":["nist-800-53"],"title":"SR-5 — Acquisition Strategies, Tools, and Methods","type":"control"},{"id":"ctrl:nist-800-53:SR-6","rendered":false,"sources":["nist-800-53"],"title":"SR-6 — Supplier Assessments and Reviews","type":"control"},{"id":"ctrl:nist-800-53:SR-7","rendered":false,"sources":["nist-800-53"],"title":"SR-7 — Supply Chain Operations Security","type":"control"},{"id":"ctrl:nist-800-53:SR-8","rendered":false,"sources":["nist-800-53"],"title":"SR-8 — Notification Agreements","type":"control"},{"id":"ctrl:nist-800-53:SR-9","rendered":false,"sources":["nist-800-53"],"title":"SR-9 — Tamper Resistance and Detection","type":"control"},{"id":"ctrl:nist-ai-agent-identity:NIST-AGI-01","rendered":false,"sources":["nist-ai-agent-identity"],"title":"NIST-AGI-01 — Distinct agent identities and identity boundaries","type":"control"},{"id":"ctrl:nist-ai-agent-identity:NIST-AGI-02","rendered":false,"sources":["nist-ai-agent-identity"],"title":"NIST-AGI-02 — Agent authentication and credential lifecycle","type":"control"},{"id":"ctrl:nist-ai-agent-identity:NIST-AGI-03","rendered":false,"sources":["nist-ai-agent-identity"],"title":"NIST-AGI-03 — Context-sensitive authorization and least privilege","type":"control"},{"id":"ctrl:nist-ai-agent-identity:NIST-AGI-04","rendered":false,"sources":["nist-ai-agent-identity"],"title":"NIST-AGI-04 — Delegated authority and human accountability","type":"control"},{"id":"ctrl:nist-ai-agent-identity:NIST-AGI-05","rendered":false,"sources":["nist-ai-agent-identity"],"title":"NIST-AGI-05 — Verifiable agent action logs and authorization traceability","type":"control"},{"id":"ctrl:nist-ai-agent-identity:NIST-AGI-06","rendered":false,"sources":["nist-ai-agent-identity"],"title":"NIST-AGI-06 — Prompt-injection prevention and limits on resulting harm","type":"control"},{"id":"ctrl:nist-ai-agent-identity:NIST-AGI-07","rendered":false,"sources":["nist-ai-agent-identity"],"title":"NIST-AGI-07 — Prompt provenance and data-flow tracking","type":"control"},{"id":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-01","rendered":false,"sources":["nist-ai-tevv-athlon"],"title":"NIST-TEVV-01 — Define evaluation objectives, context, and measurements","type":"control"},{"id":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-02","rendered":false,"sources":["nist-ai-tevv-athlon"],"title":"NIST-TEVV-02 — Run evaluations and examine results and limitations","type":"control"},{"id":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-03","rendered":false,"sources":["nist-ai-tevv-athlon"],"title":"NIST-TEVV-03 — Evaluate AI systems in realistic operating settings","type":"control"},{"id":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-04","rendered":false,"sources":["nist-ai-tevv-athlon"],"title":"NIST-TEVV-04 — Test for disclosure of confidential information","type":"control"},{"id":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-05","rendered":false,"sources":["nist-ai-tevv-athlon"],"title":"NIST-TEVV-05 — Test direct and indirect prompt injection","type":"control"},{"id":"ctrl:nist-ai-tevv-athlon:NIST-TEVV-06","rendered":false,"sources":["nist-ai-tevv-athlon"],"title":"NIST-TEVV-06 — Test agent tool misuse and unauthorized external actions","type":"control"},{"id":"ctrl:nist-csf-2:DE.AE-02","rendered":false,"sources":["nist-csf-2"],"title":"DE.AE-02 — Adverse Event Analysis: Potentially adverse events are analyzed to better understand associated activities","type":"control"},{"id":"ctrl:nist-csf-2:DE.AE-03","rendered":false,"sources":["nist-csf-2"],"title":"DE.AE-03 — Adverse Event Analysis: Information is correlated from multiple sources","type":"control"},{"id":"ctrl:nist-csf-2:DE.AE-04","rendered":false,"sources":["nist-csf-2"],"title":"DE.AE-04 — Adverse Event Analysis: The estimated impact and scope of adverse events are understood","type":"control"},{"id":"ctrl:nist-csf-2:DE.AE-06","rendered":false,"sources":["nist-csf-2"],"title":"DE.AE-06 — Adverse Event Analysis: Information on adverse events is provided to authorized staff and tools","type":"control"},{"id":"ctrl:nist-csf-2:DE.AE-07","rendered":false,"sources":["nist-csf-2"],"title":"DE.AE-07 — Adverse Event Analysis: Cyber threat intelligence and other contextual information are integrated into the analysis","type":"control"},{"id":"ctrl:nist-csf-2:DE.AE-08","rendered":false,"sources":["nist-csf-2"],"title":"DE.AE-08 — Adverse Event Analysis: Incidents are declared when adverse events meet the defined incident criteria","type":"control"},{"id":"ctrl:nist-csf-2:DE.CM-01","rendered":false,"sources":["nist-csf-2"],"title":"DE.CM-01 — Continuous Monitoring: Networks and network services are monitored to find potentially adverse events","type":"control"},{"id":"ctrl:nist-csf-2:DE.CM-02","rendered":false,"sources":["nist-csf-2"],"title":"DE.CM-02 — Continuous Monitoring: The physical environment is monitored to find potentially adverse events","type":"control"},{"id":"ctrl:nist-csf-2:DE.CM-03","rendered":false,"sources":["nist-csf-2"],"title":"DE.CM-03 — Continuous Monitoring: Personnel activity and technology usage are monitored to find potentially adverse events","type":"control"},{"id":"ctrl:nist-csf-2:DE.CM-06","rendered":false,"sources":["nist-csf-2"],"title":"DE.CM-06 — Continuous Monitoring: External service provider activities and services are monitored to find potentially adverse events","type":"control"},{"id":"ctrl:nist-csf-2:DE.CM-09","rendered":false,"sources":["nist-csf-2"],"title":"DE.CM-09 — Continuous Monitoring: Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events","type":"control"},{"id":"ctrl:nist-csf-2:GV.OC-01","rendered":false,"sources":["nist-csf-2"],"title":"GV.OC-01 — Organizational Context: The organizational mission is understood and informs cybersecurity risk management","type":"control"},{"id":"ctrl:nist-csf-2:GV.OC-02","rendered":false,"sources":["nist-csf-2"],"title":"GV.OC-02 — Organizational Context: Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered","type":"control"},{"id":"ctrl:nist-csf-2:GV.OC-03","rendered":false,"sources":["nist-csf-2"],"title":"GV.OC-03 — Organizational Context: Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed","type":"control"},{"id":"ctrl:nist-csf-2:GV.OC-04","rendered":false,"sources":["nist-csf-2"],"title":"GV.OC-04 — Organizational Context: Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated","type":"control"},{"id":"ctrl:nist-csf-2:GV.OC-05","rendered":false,"sources":["nist-csf-2"],"title":"GV.OC-05 — Organizational Context: Outcomes, capabilities, and services that the organization depends on are understood and communicated","type":"control"},{"id":"ctrl:nist-csf-2:GV.OV-01","rendered":false,"sources":["nist-csf-2"],"title":"GV.OV-01 — Oversight: Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction","type":"control"},{"id":"ctrl:nist-csf-2:GV.OV-02","rendered":false,"sources":["nist-csf-2"],"title":"GV.OV-02 — Oversight: The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks","type":"control"},{"id":"ctrl:nist-csf-2:GV.OV-03","rendered":false,"sources":["nist-csf-2"],"title":"GV.OV-03 — Oversight: Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed","type":"control"},{"id":"ctrl:nist-csf-2:GV.PO-01","rendered":false,"sources":["nist-csf-2"],"title":"GV.PO-01 — Policy: Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced","type":"control"},{"id":"ctrl:nist-csf-2:GV.PO-02","rendered":false,"sources":["nist-csf-2"],"title":"GV.PO-02 — Policy: Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission","type":"control"},{"id":"ctrl:nist-csf-2:GV.RM-01","rendered":false,"sources":["nist-csf-2"],"title":"GV.RM-01 — Risk Management Strategy: Risk management objectives are established and agreed to by organizational stakeholders","type":"control"},{"id":"ctrl:nist-csf-2:GV.RM-02","rendered":false,"sources":["nist-csf-2"],"title":"GV.RM-02 — Risk Management Strategy: Risk appetite and risk tolerance statements are established, communicated, and maintained","type":"control"},{"id":"ctrl:nist-csf-2:GV.RM-03","rendered":false,"sources":["nist-csf-2"],"title":"GV.RM-03 — Risk Management Strategy: Cybersecurity risk management activities and outcomes are included in enterprise risk management processes","type":"control"},{"id":"ctrl:nist-csf-2:GV.RM-04","rendered":false,"sources":["nist-csf-2"],"title":"GV.RM-04 — Risk Management Strategy: Strategic direction that describes appropriate risk response options is established and communicated","type":"control"},{"id":"ctrl:nist-csf-2:GV.RM-05","rendered":false,"sources":["nist-csf-2"],"title":"GV.RM-05 — Risk Management Strategy: Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties","type":"control"},{"id":"ctrl:nist-csf-2:GV.RM-06","rendered":false,"sources":["nist-csf-2"],"title":"GV.RM-06 — Risk Management Strategy: A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated","type":"control"},{"id":"ctrl:nist-csf-2:GV.RM-07","rendered":false,"sources":["nist-csf-2"],"title":"GV.RM-07 — Risk Management Strategy: Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions","type":"control"},{"id":"ctrl:nist-csf-2:GV.RR-01","rendered":false,"sources":["nist-csf-2"],"title":"GV.RR-01 — Roles, Responsibilities, and Authorities: Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving","type":"control"},{"id":"ctrl:nist-csf-2:GV.RR-02","rendered":false,"sources":["nist-csf-2"],"title":"GV.RR-02 — Roles, Responsibilities, and Authorities: Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced","type":"control"},{"id":"ctrl:nist-csf-2:GV.RR-03","rendered":false,"sources":["nist-csf-2"],"title":"GV.RR-03 — Roles, Responsibilities, and Authorities: Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies","type":"control"},{"id":"ctrl:nist-csf-2:GV.RR-04","rendered":false,"sources":["nist-csf-2"],"title":"GV.RR-04 — Roles, Responsibilities, and Authorities: Cybersecurity is included in human resources practices","type":"control"},{"id":"ctrl:nist-csf-2:GV.SC-01","rendered":false,"sources":["nist-csf-2"],"title":"GV.SC-01 — Cybersecurity Supply Chain Risk Management: A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders","type":"control"},{"id":"ctrl:nist-csf-2:GV.SC-02","rendered":false,"sources":["nist-csf-2"],"title":"GV.SC-02 — Cybersecurity Supply Chain Risk Management: Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally","type":"control"},{"id":"ctrl:nist-csf-2:GV.SC-03","rendered":false,"sources":["nist-csf-2"],"title":"GV.SC-03 — Cybersecurity Supply Chain Risk Management: Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes","type":"control"},{"id":"ctrl:nist-csf-2:GV.SC-04","rendered":false,"sources":["nist-csf-2"],"title":"GV.SC-04 — Cybersecurity Supply Chain Risk Management: Suppliers are known and prioritized by criticality","type":"control"},{"id":"ctrl:nist-csf-2:GV.SC-05","rendered":false,"sources":["nist-csf-2"],"title":"GV.SC-05 — Cybersecurity Supply Chain Risk Management: Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties","type":"control"},{"id":"ctrl:nist-csf-2:GV.SC-06","rendered":false,"sources":["nist-csf-2"],"title":"GV.SC-06 — Cybersecurity Supply Chain Risk Management: Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships","type":"control"},{"id":"ctrl:nist-csf-2:GV.SC-07","rendered":false,"sources":["nist-csf-2"],"title":"GV.SC-07 — Cybersecurity Supply Chain Risk Management: The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship","type":"control"},{"id":"ctrl:nist-csf-2:GV.SC-08","rendered":false,"sources":["nist-csf-2"],"title":"GV.SC-08 — Cybersecurity Supply Chain Risk Management: Relevant suppliers and other third parties are included in incident planning, response, and recovery activities","type":"control"},{"id":"ctrl:nist-csf-2:GV.SC-09","rendered":false,"sources":["nist-csf-2"],"title":"GV.SC-09 — Cybersecurity Supply Chain Risk Management: Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle","type":"control"},{"id":"ctrl:nist-csf-2:GV.SC-10","rendered":false,"sources":["nist-csf-2"],"title":"GV.SC-10 — Cybersecurity Supply Chain Risk Management: Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement","type":"control"},{"id":"ctrl:nist-csf-2:ID.AM-01","rendered":false,"sources":["nist-csf-2"],"title":"ID.AM-01 — Asset Management: Inventories of hardware managed by the organization are maintained","type":"control"},{"id":"ctrl:nist-csf-2:ID.AM-02","rendered":false,"sources":["nist-csf-2"],"title":"ID.AM-02 — Asset Management: Inventories of software, services, and systems managed by the organization are maintained","type":"control"},{"id":"ctrl:nist-csf-2:ID.AM-03","rendered":false,"sources":["nist-csf-2"],"title":"ID.AM-03 — Asset Management: Representations of the organization's authorized network communication and internal and external network data flows are maintained","type":"control"},{"id":"ctrl:nist-csf-2:ID.AM-04","rendered":false,"sources":["nist-csf-2"],"title":"ID.AM-04 — Asset Management: Inventories of services provided by suppliers are maintained","type":"control"},{"id":"ctrl:nist-csf-2:ID.AM-05","rendered":false,"sources":["nist-csf-2"],"title":"ID.AM-05 — Asset Management: Assets are prioritized based on classification, criticality, resources, and impact on the mission","type":"control"},{"id":"ctrl:nist-csf-2:ID.AM-07","rendered":false,"sources":["nist-csf-2"],"title":"ID.AM-07 — Asset Management: Inventories of data and corresponding metadata for designated data types are maintained","type":"control"},{"id":"ctrl:nist-csf-2:ID.AM-08","rendered":false,"sources":["nist-csf-2"],"title":"ID.AM-08 — Asset Management: Systems, hardware, software, services, and data are managed throughout their life cycles","type":"control"},{"id":"ctrl:nist-csf-2:ID.IM-01","rendered":false,"sources":["nist-csf-2"],"title":"ID.IM-01 — Improvement: Improvements are identified from evaluations","type":"control"},{"id":"ctrl:nist-csf-2:ID.IM-02","rendered":false,"sources":["nist-csf-2"],"title":"ID.IM-02 — Improvement: Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties","type":"control"},{"id":"ctrl:nist-csf-2:ID.IM-03","rendered":false,"sources":["nist-csf-2"],"title":"ID.IM-03 — Improvement: Improvements are identified from execution of operational processes, procedures, and activities","type":"control"},{"id":"ctrl:nist-csf-2:ID.IM-04","rendered":false,"sources":["nist-csf-2"],"title":"ID.IM-04 — Improvement: Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained, and improved","type":"control"},{"id":"ctrl:nist-csf-2:ID.RA-01","rendered":false,"sources":["nist-csf-2"],"title":"ID.RA-01 — Risk Assessment: Vulnerabilities in assets are identified, validated, and recorded","type":"control"},{"id":"ctrl:nist-csf-2:ID.RA-02","rendered":false,"sources":["nist-csf-2"],"title":"ID.RA-02 — Risk Assessment: Cyber threat intelligence is received from information sharing forums and sources","type":"control"},{"id":"ctrl:nist-csf-2:ID.RA-03","rendered":false,"sources":["nist-csf-2"],"title":"ID.RA-03 — Risk Assessment: Internal and external threats to the organization are identified and recorded","type":"control"},{"id":"ctrl:nist-csf-2:ID.RA-04","rendered":false,"sources":["nist-csf-2"],"title":"ID.RA-04 — Risk Assessment: Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded","type":"control"},{"id":"ctrl:nist-csf-2:ID.RA-05","rendered":false,"sources":["nist-csf-2"],"title":"ID.RA-05 — Risk Assessment: Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization","type":"control"},{"id":"ctrl:nist-csf-2:ID.RA-06","rendered":false,"sources":["nist-csf-2"],"title":"ID.RA-06 — Risk Assessment: Risk responses are chosen, prioritized, planned, tracked, and communicated","type":"control"},{"id":"ctrl:nist-csf-2:ID.RA-07","rendered":false,"sources":["nist-csf-2"],"title":"ID.RA-07 — Risk Assessment: Changes and exceptions are managed, assessed for risk impact, recorded, and tracked","type":"control"},{"id":"ctrl:nist-csf-2:ID.RA-08","rendered":false,"sources":["nist-csf-2"],"title":"ID.RA-08 — Risk Assessment: Processes for receiving, analyzing, and responding to vulnerability disclosures are established","type":"control"},{"id":"ctrl:nist-csf-2:ID.RA-09","rendered":false,"sources":["nist-csf-2"],"title":"ID.RA-09 — Risk Assessment: The authenticity and integrity of hardware and software are assessed prior to acquisition and use","type":"control"},{"id":"ctrl:nist-csf-2:ID.RA-10","rendered":false,"sources":["nist-csf-2"],"title":"ID.RA-10 — Risk Assessment: Critical suppliers are assessed prior to acquisition","type":"control"},{"id":"ctrl:nist-csf-2:PR.AA-01","rendered":false,"sources":["nist-csf-2"],"title":"PR.AA-01 — Identity Management, Authentication, and Access Control: Identities and credentials for authorized users, services, and hardware are managed by the organization","type":"control"},{"id":"ctrl:nist-csf-2:PR.AA-02","rendered":false,"sources":["nist-csf-2"],"title":"PR.AA-02 — Identity Management, Authentication, and Access Control: Identities are proofed and bound to credentials based on the context of interactions","type":"control"},{"id":"ctrl:nist-csf-2:PR.AA-03","rendered":false,"sources":["nist-csf-2"],"title":"PR.AA-03 — Identity Management, Authentication, and Access Control: Users, services, and hardware are authenticated","type":"control"},{"id":"ctrl:nist-csf-2:PR.AA-04","rendered":false,"sources":["nist-csf-2"],"title":"PR.AA-04 — Identity Management, Authentication, and Access Control: Identity assertions are protected, conveyed, and verified","type":"control"},{"id":"ctrl:nist-csf-2:PR.AA-05","rendered":false,"sources":["nist-csf-2"],"title":"PR.AA-05 — Identity Management, Authentication, and Access Control: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties","type":"control"},{"id":"ctrl:nist-csf-2:PR.AA-06","rendered":false,"sources":["nist-csf-2"],"title":"PR.AA-06 — Identity Management, Authentication, and Access Control: Physical access to assets is managed, monitored, and enforced commensurate with risk","type":"control"},{"id":"ctrl:nist-csf-2:PR.AT-01","rendered":false,"sources":["nist-csf-2"],"title":"PR.AT-01 — Awareness and Training: Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind","type":"control"},{"id":"ctrl:nist-csf-2:PR.AT-02","rendered":false,"sources":["nist-csf-2"],"title":"PR.AT-02 — Awareness and Training: Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind","type":"control"},{"id":"ctrl:nist-csf-2:PR.DS-01","rendered":false,"sources":["nist-csf-2"],"title":"PR.DS-01 — Data Security: The confidentiality, integrity, and availability of data-at-rest are protected","type":"control"},{"id":"ctrl:nist-csf-2:PR.DS-02","rendered":false,"sources":["nist-csf-2"],"title":"PR.DS-02 — Data Security: The confidentiality, integrity, and availability of data-in-transit are protected","type":"control"},{"id":"ctrl:nist-csf-2:PR.DS-10","rendered":false,"sources":["nist-csf-2"],"title":"PR.DS-10 — Data Security: The confidentiality, integrity, and availability of data-in-use are protected","type":"control"},{"id":"ctrl:nist-csf-2:PR.DS-11","rendered":false,"sources":["nist-csf-2"],"title":"PR.DS-11 — Data Security: Backups of data are created, protected, maintained, and tested","type":"control"},{"id":"ctrl:nist-csf-2:PR.IR-01","rendered":false,"sources":["nist-csf-2"],"title":"PR.IR-01 — Technology Infrastructure Resilience: Networks and environments are protected from unauthorized logical access and usage","type":"control"},{"id":"ctrl:nist-csf-2:PR.IR-02","rendered":false,"sources":["nist-csf-2"],"title":"PR.IR-02 — Technology Infrastructure Resilience: The organization's technology assets are protected from environmental threats","type":"control"},{"id":"ctrl:nist-csf-2:PR.IR-03","rendered":false,"sources":["nist-csf-2"],"title":"PR.IR-03 — Technology Infrastructure Resilience: Mechanisms are implemented to achieve resilience requirements in normal and adverse situations","type":"control"},{"id":"ctrl:nist-csf-2:PR.IR-04","rendered":false,"sources":["nist-csf-2"],"title":"PR.IR-04 — Technology Infrastructure Resilience: Adequate resource capacity to ensure availability is maintained","type":"control"},{"id":"ctrl:nist-csf-2:PR.PS-01","rendered":false,"sources":["nist-csf-2"],"title":"PR.PS-01 — Platform Security: Configuration management practices are established and applied","type":"control"},{"id":"ctrl:nist-csf-2:PR.PS-02","rendered":false,"sources":["nist-csf-2"],"title":"PR.PS-02 — Platform Security: Software is maintained, replaced, and removed commensurate with risk","type":"control"},{"id":"ctrl:nist-csf-2:PR.PS-03","rendered":false,"sources":["nist-csf-2"],"title":"PR.PS-03 — Platform Security: Hardware is maintained, replaced, and removed commensurate with risk","type":"control"},{"id":"ctrl:nist-csf-2:PR.PS-04","rendered":false,"sources":["nist-csf-2"],"title":"PR.PS-04 — Platform Security: Log records are generated and made available for continuous monitoring","type":"control"},{"id":"ctrl:nist-csf-2:PR.PS-05","rendered":false,"sources":["nist-csf-2"],"title":"PR.PS-05 — Platform Security: Installation and execution of unauthorized software are prevented","type":"control"},{"id":"ctrl:nist-csf-2:PR.PS-06","rendered":false,"sources":["nist-csf-2"],"title":"PR.PS-06 — Platform Security: Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle","type":"control"},{"id":"ctrl:nist-csf-2:RC.CO-03","rendered":false,"sources":["nist-csf-2"],"title":"RC.CO-03 — Incident Recovery Communication: Recovery activities and progress in restoring operational capabilities are communicated to designated internal and external stakeholders","type":"control"},{"id":"ctrl:nist-csf-2:RC.CO-04","rendered":false,"sources":["nist-csf-2"],"title":"RC.CO-04 — Incident Recovery Communication: Public updates on incident recovery are shared using approved methods and messaging","type":"control"},{"id":"ctrl:nist-csf-2:RC.RP-01","rendered":false,"sources":["nist-csf-2"],"title":"RC.RP-01 — Incident Recovery Plan Execution: The recovery portion of the incident response plan is executed once initiated from the incident response process","type":"control"},{"id":"ctrl:nist-csf-2:RC.RP-02","rendered":false,"sources":["nist-csf-2"],"title":"RC.RP-02 — Incident Recovery Plan Execution: Recovery actions are selected, scoped, prioritized, and performed","type":"control"},{"id":"ctrl:nist-csf-2:RC.RP-03","rendered":false,"sources":["nist-csf-2"],"title":"RC.RP-03 — Incident Recovery Plan Execution: The integrity of backups and other restoration assets is verified before using them for restoration","type":"control"},{"id":"ctrl:nist-csf-2:RC.RP-04","rendered":false,"sources":["nist-csf-2"],"title":"RC.RP-04 — Incident Recovery Plan Execution: Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms","type":"control"},{"id":"ctrl:nist-csf-2:RC.RP-05","rendered":false,"sources":["nist-csf-2"],"title":"RC.RP-05 — Incident Recovery Plan Execution: The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed","type":"control"},{"id":"ctrl:nist-csf-2:RC.RP-06","rendered":false,"sources":["nist-csf-2"],"title":"RC.RP-06 — Incident Recovery Plan Execution: The end of incident recovery is declared based on criteria, and incident-related documentation is completed","type":"control"},{"id":"ctrl:nist-csf-2:RS.AN-03","rendered":false,"sources":["nist-csf-2"],"title":"RS.AN-03 — Incident Analysis: Analysis is performed to establish what has taken place during an incident and the root cause of the incident","type":"control"},{"id":"ctrl:nist-csf-2:RS.AN-06","rendered":false,"sources":["nist-csf-2"],"title":"RS.AN-06 — Incident Analysis: Actions performed during an investigation are recorded, and the records' integrity and provenance are preserved","type":"control"},{"id":"ctrl:nist-csf-2:RS.AN-07","rendered":false,"sources":["nist-csf-2"],"title":"RS.AN-07 — Incident Analysis: Incident data and metadata are collected, and their integrity and provenance are preserved","type":"control"},{"id":"ctrl:nist-csf-2:RS.AN-08","rendered":false,"sources":["nist-csf-2"],"title":"RS.AN-08 — Incident Analysis: An incident's magnitude is estimated and validated","type":"control"},{"id":"ctrl:nist-csf-2:RS.CO-02","rendered":false,"sources":["nist-csf-2"],"title":"RS.CO-02 — Incident Response Reporting and Communication: Internal and external stakeholders are notified of incidents","type":"control"},{"id":"ctrl:nist-csf-2:RS.CO-03","rendered":false,"sources":["nist-csf-2"],"title":"RS.CO-03 — Incident Response Reporting and Communication: Information is shared with designated internal and external stakeholders","type":"control"},{"id":"ctrl:nist-csf-2:RS.MA-01","rendered":false,"sources":["nist-csf-2"],"title":"RS.MA-01 — Incident Management: The incident response plan is executed in coordination with relevant third parties once an incident is declared","type":"control"},{"id":"ctrl:nist-csf-2:RS.MA-02","rendered":false,"sources":["nist-csf-2"],"title":"RS.MA-02 — Incident Management: Incident reports are triaged and validated","type":"control"},{"id":"ctrl:nist-csf-2:RS.MA-03","rendered":false,"sources":["nist-csf-2"],"title":"RS.MA-03 — Incident Management: Incidents are categorized and prioritized","type":"control"},{"id":"ctrl:nist-csf-2:RS.MA-04","rendered":false,"sources":["nist-csf-2"],"title":"RS.MA-04 — Incident Management: Incidents are escalated or elevated as needed","type":"control"},{"id":"ctrl:nist-csf-2:RS.MA-05","rendered":false,"sources":["nist-csf-2"],"title":"RS.MA-05 — Incident Management: The criteria for initiating incident recovery are applied","type":"control"},{"id":"ctrl:nist-csf-2:RS.MI-01","rendered":false,"sources":["nist-csf-2"],"title":"RS.MI-01 — Incident Mitigation: Incidents are contained","type":"control"},{"id":"ctrl:nist-csf-2:RS.MI-02","rendered":false,"sources":["nist-csf-2"],"title":"RS.MI-02 — Incident Mitigation: Incidents are eradicated","type":"control"},{"id":"ctrl:nydfs-500:500.10","rendered":false,"sources":["nydfs-500"],"title":"500.10 — Cybersecurity personnel and intelligence","type":"control"},{"id":"ctrl:nydfs-500:500.11","rendered":false,"sources":["nydfs-500"],"title":"500.11 — Third-party service provider security policy","type":"control"},{"id":"ctrl:nydfs-500:500.12","rendered":false,"sources":["nydfs-500"],"title":"500.12 — Multi-factor authentication","type":"control"},{"id":"ctrl:nydfs-500:500.13","rendered":false,"sources":["nydfs-500"],"title":"500.13 — Asset management and data retention limitations","type":"control"},{"id":"ctrl:nydfs-500:500.14","rendered":false,"sources":["nydfs-500"],"title":"500.14 — Monitoring and training","type":"control"},{"id":"ctrl:nydfs-500:500.15","rendered":false,"sources":["nydfs-500"],"title":"500.15 — Encryption of nonpublic information","type":"control"},{"id":"ctrl:nydfs-500:500.16","rendered":false,"sources":["nydfs-500"],"title":"500.16 — Incident response and business continuity management","type":"control"},{"id":"ctrl:nydfs-500:500.17","rendered":false,"sources":["nydfs-500"],"title":"500.17 — Notices to superintendent (incident notification and annual certification)","type":"control"},{"id":"ctrl:nydfs-500:500.18","rendered":false,"sources":["nydfs-500"],"title":"500.18 — Confidentiality","type":"control"},{"id":"ctrl:nydfs-500:500.19","rendered":false,"sources":["nydfs-500"],"title":"500.19 — Exemptions","type":"control"},{"id":"ctrl:nydfs-500:500.2","rendered":false,"sources":["nydfs-500"],"title":"500.2 — Cybersecurity program","type":"control"},{"id":"ctrl:nydfs-500:500.3","rendered":false,"sources":["nydfs-500"],"title":"500.3 — Cybersecurity policy","type":"control"},{"id":"ctrl:nydfs-500:500.4","rendered":false,"sources":["nydfs-500"],"title":"500.4 — Chief Information Security Officer (CISO)","type":"control"},{"id":"ctrl:nydfs-500:500.5","rendered":false,"sources":["nydfs-500"],"title":"500.5 — Vulnerability management (penetration testing and scanning)","type":"control"},{"id":"ctrl:nydfs-500:500.6","rendered":false,"sources":["nydfs-500"],"title":"500.6 — Audit trail","type":"control"},{"id":"ctrl:nydfs-500:500.7","rendered":false,"sources":["nydfs-500"],"title":"500.7 — Access privileges and management","type":"control"},{"id":"ctrl:nydfs-500:500.8","rendered":false,"sources":["nydfs-500"],"title":"500.8 — Application security","type":"control"},{"id":"ctrl:nydfs-500:500.9","rendered":false,"sources":["nydfs-500"],"title":"500.9 — Risk assessment","type":"control"},{"id":"ctrl:pci-dss:PCI-Req1","rendered":false,"sources":["pci-dss"],"title":"PCI-Req1 — Install and maintain network security controls","type":"control"},{"id":"ctrl:pci-dss:PCI-Req10","rendered":false,"sources":["pci-dss"],"title":"PCI-Req10 — Log and monitor all access to system components and cardholder data","type":"control"},{"id":"ctrl:pci-dss:PCI-Req11","rendered":false,"sources":["pci-dss"],"title":"PCI-Req11 — Test security of systems and networks regularly","type":"control"},{"id":"ctrl:pci-dss:PCI-Req12","rendered":false,"sources":["pci-dss"],"title":"PCI-Req12 — Support information security with organizational policies and programs","type":"control"},{"id":"ctrl:pci-dss:PCI-Req2","rendered":false,"sources":["pci-dss"],"title":"PCI-Req2 — Apply secure configurations to all system components","type":"control"},{"id":"ctrl:pci-dss:PCI-Req3","rendered":false,"sources":["pci-dss"],"title":"PCI-Req3 — Protect stored account data","type":"control"},{"id":"ctrl:pci-dss:PCI-Req4","rendered":false,"sources":["pci-dss"],"title":"PCI-Req4 — Protect cardholder data with strong cryptography during transmission over open, public networks","type":"control"},{"id":"ctrl:pci-dss:PCI-Req5","rendered":false,"sources":["pci-dss"],"title":"PCI-Req5 — Protect all systems and networks from malicious software","type":"control"},{"id":"ctrl:pci-dss:PCI-Req6","rendered":false,"sources":["pci-dss"],"title":"PCI-Req6 — Develop and maintain secure systems and software","type":"control"},{"id":"ctrl:pci-dss:PCI-Req7","rendered":false,"sources":["pci-dss"],"title":"PCI-Req7 — Restrict access to system components and cardholder data by business need to know","type":"control"},{"id":"ctrl:pci-dss:PCI-Req8","rendered":false,"sources":["pci-dss"],"title":"PCI-Req8 — Identify users and authenticate access to system components","type":"control"},{"id":"ctrl:pci-dss:PCI-Req9","rendered":false,"sources":["pci-dss"],"title":"PCI-Req9 — Restrict physical access to cardholder data","type":"control"},{"id":"ctrl:soc1:SOC1-1","rendered":false,"sources":["soc1"],"title":"SOC1-1 — Logical access — controls provide reasonable assurance that logical access to applications, data, and infrastructure is restricted to authorized and appropriate users (authentication, authorization, provisioning/deprovisioning, periodic access review, privileged access).","type":"control"},{"id":"ctrl:soc1:SOC1-10","rendered":false,"sources":["soc1"],"title":"SOC1-10 — Physical security and environmental controls — controls provide reasonable assurance that physical access to facilities and data centers is restricted and that environmental protections safeguard systems.","type":"control"},{"id":"ctrl:soc1:SOC1-11","rendered":false,"sources":["soc1"],"title":"SOC1-11 — System monitoring and incident management — controls provide reasonable assurance that system performance, security events, and incidents are monitored, identified, and resolved.","type":"control"},{"id":"ctrl:soc1:SOC1-12","rendered":false,"sources":["soc1"],"title":"SOC1-12 — Vendor / subservice organization management — controls provide reasonable assurance that subservice organizations relevant to user entities' ICFR are appropriately managed and monitored.","type":"control"},{"id":"ctrl:soc1:SOC1-2","rendered":false,"sources":["soc1"],"title":"SOC1-2 — Change management — controls provide reasonable assurance that changes to applications and infrastructure are authorized, tested, approved, and migrated to production appropriately.","type":"control"},{"id":"ctrl:soc1:SOC1-3","rendered":false,"sources":["soc1"],"title":"SOC1-3 — Program development / SDLC — controls provide reasonable assurance that new systems and applications are developed, tested, approved, and implemented in accordance with management's intent.","type":"control"},{"id":"ctrl:soc1:SOC1-4","rendered":false,"sources":["soc1"],"title":"SOC1-4 — Computer operations / job scheduling — controls provide reasonable assurance that production batch jobs and scheduled processing are appropriately defined, executed, monitored, and that exceptions/failures are identified and resolved.","type":"control"},{"id":"ctrl:soc1:SOC1-5","rendered":false,"sources":["soc1"],"title":"SOC1-5 — Backup and recovery — controls provide reasonable assurance that data is backed up, retained, and recoverable, and that restoration is tested.","type":"control"},{"id":"ctrl:soc1:SOC1-6","rendered":false,"sources":["soc1"],"title":"SOC1-6 — Data transmission / interface controls — controls provide reasonable assurance that data transmitted to and from the system and across interfaces is complete, accurate, authorized, and timely.","type":"control"},{"id":"ctrl:soc1:SOC1-7","rendered":false,"sources":["soc1"],"title":"SOC1-7 — Data input — controls provide reasonable assurance that transactions and data input into the system are complete, accurate, and authorized.","type":"control"},{"id":"ctrl:soc1:SOC1-8","rendered":false,"sources":["soc1"],"title":"SOC1-8 — Data processing — controls provide reasonable assurance that transactions are processed completely, accurately, and in the proper period.","type":"control"},{"id":"ctrl:soc1:SOC1-9","rendered":false,"sources":["soc1"],"title":"SOC1-9 — Data output / reporting — controls provide reasonable assurance that output and reports provided to user entities are complete, accurate, and distributed only to authorized recipients.","type":"control"},{"id":"ctrl:soc2:A1.1","rendered":false,"sources":["soc2"],"title":"A1.1 — The entity maintains, monitors, and evaluates current processing capacity and use of system components (infrastructure, data, and software) to manage capacity demand and to enable the implementation of additional capacity to help meet its objectives.","type":"control"},{"id":"ctrl:soc2:A1.2","rendered":false,"sources":["soc2"],"title":"A1.2 — The entity authorizes, designs, develops or acquires, implements, operates, approves, maintains, and monitors environmental protections, software, data back-up processes, and recovery infrastructure to meet its objectives.","type":"control"},{"id":"ctrl:soc2:A1.3","rendered":false,"sources":["soc2"],"title":"A1.3 — The entity tests recovery plan procedures supporting system recovery to meet its objectives.","type":"control"},{"id":"ctrl:soc2:C1.1","rendered":false,"sources":["soc2"],"title":"C1.1 — The entity identifies and maintains confidential information to meet the entity's objectives related to confidentiality.","type":"control"},{"id":"ctrl:soc2:C1.2","rendered":false,"sources":["soc2"],"title":"C1.2 — The entity disposes of confidential information to meet the entity's objectives related to confidentiality.","type":"control"},{"id":"ctrl:soc2:CC1.1","rendered":false,"sources":["soc2"],"title":"CC1.1 — The entity demonstrates a commitment to integrity and ethical values.","type":"control"},{"id":"ctrl:soc2:CC1.2","rendered":false,"sources":["soc2"],"title":"CC1.2 — The board of directors demonstrates independence from management and exercises oversight of the development and performance of internal control.","type":"control"},{"id":"ctrl:soc2:CC1.3","rendered":false,"sources":["soc2"],"title":"CC1.3 — Management establishes, with board oversight, structures, reporting lines, and appropriate authorities and responsibilities in the pursuit of objectives.","type":"control"},{"id":"ctrl:soc2:CC1.4","rendered":false,"sources":["soc2"],"title":"CC1.4 — The entity demonstrates a commitment to attract, develop, and retain competent individuals in alignment with objectives.","type":"control"},{"id":"ctrl:soc2:CC1.5","rendered":false,"sources":["soc2"],"title":"CC1.5 — The entity holds individuals accountable for their internal control responsibilities in the pursuit of objectives.","type":"control"},{"id":"ctrl:soc2:CC2.1","rendered":false,"sources":["soc2"],"title":"CC2.1 — The entity obtains or generates and uses relevant, quality information to support the functioning of internal control.","type":"control"},{"id":"ctrl:soc2:CC2.2","rendered":false,"sources":["soc2"],"title":"CC2.2 — The entity internally communicates information, including objectives and responsibilities for internal control, necessary to support the functioning of internal control.","type":"control"},{"id":"ctrl:soc2:CC2.3","rendered":false,"sources":["soc2"],"title":"CC2.3 — The entity communicates with external parties regarding matters affecting the functioning of internal control.","type":"control"},{"id":"ctrl:soc2:CC3.1","rendered":false,"sources":["soc2"],"title":"CC3.1 — The entity specifies objectives with sufficient clarity to enable the identification and assessment of risks relating to objectives.","type":"control"},{"id":"ctrl:soc2:CC3.2","rendered":false,"sources":["soc2"],"title":"CC3.2 — The entity identifies risks to the achievement of its objectives across the entity and analyzes risks as a basis for determining how the risks should be managed.","type":"control"},{"id":"ctrl:soc2:CC3.3","rendered":false,"sources":["soc2"],"title":"CC3.3 — The entity considers the potential for fraud in assessing risks to the achievement of objectives.","type":"control"},{"id":"ctrl:soc2:CC3.4","rendered":false,"sources":["soc2"],"title":"CC3.4 — The entity identifies and assesses changes that could significantly impact the system of internal control.","type":"control"},{"id":"ctrl:soc2:CC4.1","rendered":false,"sources":["soc2"],"title":"CC4.1 — The entity selects, develops, and performs ongoing and/or separate evaluations to ascertain whether the components of internal control are present and functioning.","type":"control"},{"id":"ctrl:soc2:CC4.2","rendered":false,"sources":["soc2"],"title":"CC4.2 — The entity evaluates and communicates internal control deficiencies in a timely manner to those parties responsible for taking corrective action, including senior management and the board of directors, as appropriate.","type":"control"},{"id":"ctrl:soc2:CC5.1","rendered":false,"sources":["soc2"],"title":"CC5.1 — The entity selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.","type":"control"},{"id":"ctrl:soc2:CC5.2","rendered":false,"sources":["soc2"],"title":"CC5.2 — The entity also selects and develops general control activities over technology to support the achievement of objectives.","type":"control"},{"id":"ctrl:soc2:CC5.3","rendered":false,"sources":["soc2"],"title":"CC5.3 — The entity deploys control activities through policies that establish what is expected and in procedures that put policies into action.","type":"control"},{"id":"ctrl:soc2:CC6.1","rendered":false,"sources":["soc2"],"title":"CC6.1 — The entity implements logical access security software, infrastructure, and architectures over protected information assets to protect them from security events to meet the entity's objectives.","type":"control"},{"id":"ctrl:soc2:CC6.2","rendered":false,"sources":["soc2"],"title":"CC6.2 — Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users whose access is administered by the entity. For those users whose access is administered by the entity, user system credentials are removed when user access is no longer authorized.","type":"control"},{"id":"ctrl:soc2:CC6.3","rendered":false,"sources":["soc2"],"title":"CC6.3 — The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties, to meet the entity's objectives.","type":"control"},{"id":"ctrl:soc2:CC6.4","rendered":false,"sources":["soc2"],"title":"CC6.4 — The entity restricts physical access to facilities and protected information assets (for example, data center facilities, back-up media storage, and other sensitive locations) to authorized personnel to meet the entity's objectives.","type":"control"},{"id":"ctrl:soc2:CC6.5","rendered":false,"sources":["soc2"],"title":"CC6.5 — The entity discontinues logical and physical protections over physical assets only after the ability to read or recover data and software from those assets has been diminished and is no longer required to meet the entity's objectives.","type":"control"},{"id":"ctrl:soc2:CC6.6","rendered":false,"sources":["soc2"],"title":"CC6.6 — The entity implements logical access security measures to protect against threats from sources outside its system boundaries.","type":"control"},{"id":"ctrl:soc2:CC6.7","rendered":false,"sources":["soc2"],"title":"CC6.7 — The entity restricts the transmission, movement, and removal of information to authorized internal and external users and processes, and protects it during transmission, movement, or removal to meet the entity's objectives.","type":"control"},{"id":"ctrl:soc2:CC6.8","rendered":false,"sources":["soc2"],"title":"CC6.8 — The entity implements controls to prevent or detect and act upon the introduction of unauthorized or malicious software to meet the entity's objectives.","type":"control"},{"id":"ctrl:soc2:CC7.1","rendered":false,"sources":["soc2"],"title":"CC7.1 — To meet its objectives, the entity uses detection and monitoring procedures to identify (1) changes to configurations that result in the introduction of new vulnerabilities, and (2) susceptibilities to newly discovered vulnerabilities.","type":"control"},{"id":"ctrl:soc2:CC7.2","rendered":false,"sources":["soc2"],"title":"CC7.2 — The entity monitors system components and the operation of those components for anomalies that are indicative of malicious acts, natural disasters, and errors affecting the entity's ability to meet its objectives; anomalies are analyzed to determine whether they represent security events.","type":"control"},{"id":"ctrl:soc2:CC7.3","rendered":false,"sources":["soc2"],"title":"CC7.3 — The entity evaluates security events to determine whether they could or have resulted in a failure of the entity to meet its objectives (security incidents) and, if so, takes actions to prevent or address such failures.","type":"control"},{"id":"ctrl:soc2:CC7.4","rendered":false,"sources":["soc2"],"title":"CC7.4 — The entity responds to identified security incidents by executing a defined incident response program to understand, contain, remediate, and communicate security incidents, as appropriate.","type":"control"},{"id":"ctrl:soc2:CC7.5","rendered":false,"sources":["soc2"],"title":"CC7.5 — The entity identifies, develops, and implements activities to recover from identified security incidents.","type":"control"},{"id":"ctrl:soc2:CC8.1","rendered":false,"sources":["soc2"],"title":"CC8.1 — The entity authorizes, designs, develops or acquires, configures, documents, tests, approves, and implements changes to infrastructure, data, software, and procedures to meet its objectives.","type":"control"},{"id":"ctrl:soc2:CC9.1","rendered":false,"sources":["soc2"],"title":"CC9.1 — The entity identifies, selects, and develops risk mitigation activities for risks arising from potential business disruptions.","type":"control"},{"id":"ctrl:soc2:CC9.2","rendered":false,"sources":["soc2"],"title":"CC9.2 — The entity assesses and manages risks associated with vendors and business partners.","type":"control"},{"id":"ctrl:soc2:P1.1","rendered":false,"sources":["soc2"],"title":"P1.1 — The entity provides notice to data subjects about its privacy practices to meet the entity's objectives related to privacy. The notice is updated and communicated to data subjects in a timely manner for changes to the entity's privacy practices, including changes in the use of personal information, to meet the entity's objectives related to privacy.","type":"control"},{"id":"ctrl:soc2:P2.1","rendered":false,"sources":["soc2"],"title":"P2.1 — The entity communicates choices available regarding the collection, use, retention, disclosure, and disposal of personal information to the data subjects and the consequences, if any, of each choice. Explicit consent for the collection, use, retention, disclosure, and disposal of personal information is obtained from data subjects or other authorized persons, if required. Such consent is obtained only for the intended purpose of the information to meet the entity's objectives related to privacy. The entity's basis for determining implicit consent for the collection, use, retention, disclosure, and disposal of personal information is documented.","type":"control"},{"id":"ctrl:soc2:P3.1","rendered":false,"sources":["soc2"],"title":"P3.1 — Personal information is collected consistent with the entity's objectives related to privacy.","type":"control"},{"id":"ctrl:soc2:P3.2","rendered":false,"sources":["soc2"],"title":"P3.2 — For information requiring explicit consent, the entity communicates the need for such consent, as well as the consequences of a failure to provide consent for the request for personal information, and obtains the consent prior to the collection of the information to meet the entity's objectives related to privacy.","type":"control"},{"id":"ctrl:soc2:P4.1","rendered":false,"sources":["soc2"],"title":"P4.1 — The entity limits the use of personal information to the purposes identified in the entity's objectives related to privacy.","type":"control"},{"id":"ctrl:soc2:P4.2","rendered":false,"sources":["soc2"],"title":"P4.2 — The entity retains personal information consistent with the entity's objectives related to privacy.","type":"control"},{"id":"ctrl:soc2:P4.3","rendered":false,"sources":["soc2"],"title":"P4.3 — The entity securely disposes of personal information to meet the entity's objectives related to privacy.","type":"control"},{"id":"ctrl:soc2:P5.1","rendered":false,"sources":["soc2"],"title":"P5.1 — The entity grants identified and authenticated data subjects the ability to access their stored personal information for review and, upon request, provides physical or electronic copies of that information to data subjects to meet the entity's objectives related to privacy. If access is denied, data subjects are informed of the denial and reason for such denial, as required, to meet the entity's objectives related to privacy.","type":"control"},{"id":"ctrl:soc2:P5.2","rendered":false,"sources":["soc2"],"title":"P5.2 — The entity corrects, amends, or appends personal information based on information provided by data subjects and communicates such information to third parties, as committed or required, to meet the entity's objectives related to privacy. If a request for correction is denied, data subjects are informed of the denial and reason for such denial to meet the entity's objectives related to privacy.","type":"control"},{"id":"ctrl:soc2:P6.1","rendered":false,"sources":["soc2"],"title":"P6.1 — The entity discloses personal information to third parties with the explicit consent of data subjects, and such consent is obtained prior to disclosure to meet the entity's objectives related to privacy.","type":"control"},{"id":"ctrl:soc2:P6.2","rendered":false,"sources":["soc2"],"title":"P6.2 — The entity creates and retains a complete, accurate, and timely record of authorized disclosures of personal information to meet the entity's objectives related to privacy.","type":"control"},{"id":"ctrl:soc2:P6.3","rendered":false,"sources":["soc2"],"title":"P6.3 — The entity creates and retains a complete, accurate, and timely record of detected or reported unauthorized disclosures (including breaches) of personal information to meet the entity's objectives related to privacy.","type":"control"},{"id":"ctrl:soc2:P6.4","rendered":false,"sources":["soc2"],"title":"P6.4 — The entity obtains privacy commitments from vendors and other third parties who have access to personal information to meet the entity's objectives related to privacy. The entity assesses those parties' compliance on a periodic and as-needed basis and takes corrective action, if necessary.","type":"control"},{"id":"ctrl:soc2:P6.5","rendered":false,"sources":["soc2"],"title":"P6.5 — The entity obtains commitments from vendors and other third parties with access to personal information to notify the entity in the event of actual or suspected unauthorized disclosures of personal information. Such notifications are reported to appropriate personnel and acted on in accordance with established incident response procedures to meet the entity's objectives related to privacy.","type":"control"},{"id":"ctrl:soc2:P6.6","rendered":false,"sources":["soc2"],"title":"P6.6 — The entity provides notification of breaches and incidents to affected data subjects, regulators, and others to meet the entity's objectives related to privacy.","type":"control"},{"id":"ctrl:soc2:P6.7","rendered":false,"sources":["soc2"],"title":"P6.7 — The entity provides data subjects with an accounting of the personal information held and disclosure of the data subjects' personal information, upon the data subjects' request, to meet the entity's objectives related to privacy.","type":"control"},{"id":"ctrl:soc2:P7.1","rendered":false,"sources":["soc2"],"title":"P7.1 — The entity collects and maintains accurate, up-to-date, complete, and relevant personal information to meet the entity's objectives related to privacy.","type":"control"},{"id":"ctrl:soc2:P8.1","rendered":false,"sources":["soc2"],"title":"P8.1 — The entity implements a process for receiving, addressing, resolving, and communicating the resolution of inquiries, complaints, and disputes from data subjects and others and periodically monitors compliance to meet the entity's objectives related to privacy. Corrections and other necessary actions related to identified deficiencies are made or taken in a timely manner.","type":"control"},{"id":"ctrl:soc2:PI1.1","rendered":false,"sources":["soc2"],"title":"PI1.1 — The entity obtains or generates, uses, and communicates relevant, quality information regarding the objectives related to processing, including definitions of data processed and product and service specifications, to support the use of products and services.","type":"control"},{"id":"ctrl:soc2:PI1.2","rendered":false,"sources":["soc2"],"title":"PI1.2 — The entity implements policies and procedures over system inputs, including controls over completeness and accuracy, to result in products, services, and reporting to meet the entity's objectives.","type":"control"},{"id":"ctrl:soc2:PI1.3","rendered":false,"sources":["soc2"],"title":"PI1.3 — The entity implements policies and procedures over system processing to result in products, services, and reporting to meet the entity's objectives.","type":"control"},{"id":"ctrl:soc2:PI1.4","rendered":false,"sources":["soc2"],"title":"PI1.4 — The entity implements policies and procedures to make available or deliver output completely, accurately, and timely in accordance with specifications to meet the entity's objectives.","type":"control"},{"id":"ctrl:soc2:PI1.5","rendered":false,"sources":["soc2"],"title":"PI1.5 — The entity implements policies and procedures to store inputs, items in processing, and outputs completely, accurately, and timely in accordance with system specifications to meet the entity's objectives.","type":"control"},{"id":"ctrl:sox:ELC-CA","rendered":false,"sources":["sox"],"title":"ELC-CA — Control Activities (entity-level) — policies and procedures, period-end financial reporting process oversight, and entity-wide control activities including technology general controls policies.","type":"control"},{"id":"ctrl:sox:ELC-CE","rendered":false,"sources":["sox"],"title":"ELC-CE — Control Environment — tone at the top, integrity and ethical values, code of conduct, board/audit committee oversight, organizational structure, assignment of authority and responsibility, commitment to competence, HR policies.","type":"control"},{"id":"ctrl:sox:ELC-IC","rendered":false,"sources":["sox"],"title":"ELC-IC — Information & Communication — quality of financial reporting information, internal communication of control responsibilities, and external communication channels (including whistleblower/ethics hotline).","type":"control"},{"id":"ctrl:sox:ELC-MGMT-OVR","rendered":false,"sources":["sox"],"title":"ELC-MGMT-OVR — Anti-fraud and management override controls — controls addressing the risk of management override of controls, including journal-entry review and review of significant estimates.","type":"control"},{"id":"ctrl:sox:ELC-MON","rendered":false,"sources":["sox"],"title":"ELC-MON — Monitoring Activities — ongoing and separate evaluations (internal audit, management self-assessment, disclosure committee), and evaluation/communication of control deficiencies.","type":"control"},{"id":"ctrl:sox:ELC-PERFR","rendered":false,"sources":["sox"],"title":"ELC-PERFR — Period-End Financial Reporting Process — controls over the close process, consolidation, journal entries, estimates, and preparation of financial statements and disclosures.","type":"control"},{"id":"ctrl:sox:ELC-RA","rendered":false,"sources":["sox"],"title":"ELC-RA — Risk Assessment — entity objective-setting, identification and analysis of risks to financial reporting, fraud risk assessment, and assessment of changes affecting internal control.","type":"control"},{"id":"ctrl:sox:ITGC-AC","rendered":false,"sources":["sox"],"title":"ITGC-AC — Access to programs and data — logical and physical access security: authentication, authorization, user provisioning/deprovisioning, periodic access recertification, privileged/administrative access, and segregation of duties enforced via access.","type":"control"},{"id":"ctrl:sox:ITGC-CM","rendered":false,"sources":["sox"],"title":"ITGC-CM — Program change management — changes to applications, databases, and infrastructure are requested, authorized, tested, approved, and migrated to production by appropriate personnel with segregation between development and production.","type":"control"},{"id":"ctrl:sox:ITGC-DEV","rendered":false,"sources":["sox"],"title":"ITGC-DEV — Program development / SDLC — new systems and significant implementations are designed, developed, tested, approved, and converted/migrated in accordance with management's specifications.","type":"control"},{"id":"ctrl:sox:ITGC-OPS","rendered":false,"sources":["sox"],"title":"ITGC-OPS — Computer operations — job scheduling and batch processing, backup and recovery, incident/problem management, and monitoring of system processing and availability.","type":"control"},{"id":"ctrl:sox:PLC-AUTH","rendered":false,"sources":["sox"],"title":"PLC-AUTH — Authorization and approval — transactions, journal entries, and changes are reviewed and approved by authorized personnel in accordance with delegation-of-authority policies before being recorded or executed.","type":"control"},{"id":"ctrl:sox:PLC-CALC","rendered":false,"sources":["sox"],"title":"PLC-CALC — Automated processing / configurable controls — system-enforced calculations, three-way matches, tolerance checks, and configurable application controls operating as designed.","type":"control"},{"id":"ctrl:sox:PLC-EXCEPTION","rendered":false,"sources":["sox"],"title":"PLC-EXCEPTION — Exception and edit-report controls — review and timely resolution of system-generated exception, error, and edit reports.","type":"control"},{"id":"ctrl:sox:PLC-INPUT","rendered":false,"sources":["sox"],"title":"PLC-INPUT — Input controls — edit/validation checks, completeness checks, and field/format controls that ensure data entered into systems is complete, accurate, and valid.","type":"control"},{"id":"ctrl:sox:PLC-INTF","rendered":false,"sources":["sox"],"title":"PLC-INTF — Interface controls — controls ensuring data transferred between systems and across interfaces is complete, accurate, and processed only once (reconciliation of record counts/control totals, error handling).","type":"control"},{"id":"ctrl:sox:PLC-IPE","rendered":false,"sources":["sox"],"title":"PLC-IPE — Information Produced by the Entity (IPE) / completeness and accuracy — controls over the completeness and accuracy of system-generated reports, queries, and spreadsheets used in the operation of controls or in financial reporting.","type":"control"},{"id":"ctrl:sox:PLC-MRC","rendered":false,"sources":["sox"],"title":"PLC-MRC — Management review controls — reviews of financial information, account analyses, budget-to-actual variances, estimates, and reconciliations performed at an appropriate level of precision with documented investigation and resolution of items.","type":"control"},{"id":"ctrl:sox:PLC-PHYS","rendered":false,"sources":["sox"],"title":"PLC-PHYS — Physical safeguards / custody controls — controls over physical custody of assets, inventory counts, and safeguarding of negotiable instruments and records.","type":"control"},{"id":"ctrl:sox:PLC-RECON","rendered":false,"sources":["sox"],"title":"PLC-RECON — Reconciliations — account and subledger-to-general-ledger reconciliations performed completely and accurately, with timely review, approval, and resolution of reconciling items.","type":"control"},{"id":"ctrl:sox:PLC-SOD","rendered":false,"sources":["sox"],"title":"PLC-SOD — Segregation of duties — incompatible duties (authorization, recording, custody, reconciliation) are divided among different people to reduce the risk of error or fraud.","type":"control"},{"id":"risk:access-excess-privilege","rendered":true,"sources":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"title":"Excessive privilege and wrong assignment of access rights","type":"risk"},{"id":"risk:access-privilege-abuse-repudiation","rendered":true,"sources":["aiuc-1","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"title":"Abuse of rights, forged rights, and repudiation of actions","type":"risk"},{"id":"risk:access-provisioning-review-gap","rendered":true,"sources":["iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","soc1","soc2","sox"],"title":"Weak account provisioning/de-registration and access review","type":"risk"},{"id":"risk:access-unauthorized-use-equipment","rendered":true,"sources":["aiuc-1","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2","sox"],"title":"Unauthorized use of equipment and unauthorized access escalation","type":"risk"},{"id":"risk:access-weak-authentication","rendered":true,"sources":["hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss"],"title":"Weak authentication and password management","type":"risk"},{"id":"risk:ai-accountability-liability","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"AI accountability gaps and organizational liability","type":"risk"},{"id":"risk:ai-adversarial-poisoning-attacks","rendered":true,"sources":["aiuc-1","cobit-2019","eu-ai-act","iso-27001","iso-42001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"Adversarial attacks, data poisoning and prompt injection","type":"risk"},{"id":"risk:ai-agent-unauthorized-actions","rendered":true,"sources":["aiuc-1","eu-ai-act","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"Unauthorized or unsafe autonomous agent actions and tool calls","type":"risk"},{"id":"risk:ai-bias-discrimination","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"Harmful AI bias and discrimination against protected groups","type":"risk"},{"id":"risk:ai-catastrophic-cyber-misuse","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001","nist-ai-tevv-athlon"],"title":"Misuse of AI systems for offensive cyber operations or catastrophic harm","type":"risk"},{"id":"risk:ai-emergent-integration-risk","rendered":true,"sources":["aiuc-1","cobit-2019","eu-ai-act","iso-27001","iso-42001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","soc1","soc2","sox"],"title":"Emergent behaviour and unsafe AI system integration","type":"risk"},{"id":"risk:ai-endpoint-abuse-model-extraction","rendered":true,"sources":["aiuc-1","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"AI endpoint abuse, scraping and model extraction","type":"risk"},{"id":"risk:ai-environmental-footprint","rendered":true,"sources":["coso-erm","iso-31000","iso-42001","soc2"],"title":"Environmental footprint of AI training and infrastructure","type":"risk"},{"id":"risk:ai-gpai-systemic-transparency","rendered":true,"sources":["aiuc-1","cobit-2019","dora","eu-ai-act","iso-27001","iso-42001","nis2","nist-800-53","nist-csf-2","nydfs-500"],"title":"GPAI transparency, systemic-risk and synthetic-content obligations","type":"risk"},{"id":"risk:ai-highrisk-biometrics","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001"],"title":"Rights harm from biometric-identification AI","type":"risk"},{"id":"risk:ai-highrisk-critical-infra","rendered":true,"sources":["aiuc-1","ccpa","cobit-2019","eu-ai-act","iia-2024","iia-pos-2026-three-lines","iso-27001","iso-42001"],"title":"Public-safety harm from AI in critical infrastructure","type":"risk"},{"id":"risk:ai-highrisk-education","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity"],"title":"Unfair exclusion by AI in education and training","type":"risk"},{"id":"risk:ai-highrisk-employment","rendered":true,"sources":["aiuc-1","eu-ai-act","iia-2024","iso-42001"],"title":"Discriminatory outcomes from AI in employment","type":"risk"},{"id":"risk:ai-highrisk-essential-services","rendered":true,"sources":["aiuc-1","eu-ai-act","iia-2024","iso-42001"],"title":"Unlawful denial of essential services by AI","type":"risk"},{"id":"risk:ai-highrisk-justice-democracy","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001"],"title":"Harm to due process and democratic integrity from AI","type":"risk"},{"id":"risk:ai-highrisk-law-enforcement","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"Rights violations from AI in law enforcement","type":"risk"},{"id":"risk:ai-highrisk-migration-border","rendered":true,"sources":["aiuc-1","eu-ai-act","iia-2024","iso-42001"],"title":"Wrongful denial by AI in migration and border control","type":"risk"},{"id":"risk:ai-inaccurate-unreliable-output","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-31000","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"Inaccurate, unreliable or hallucinated AI outputs","type":"risk"},{"id":"risk:ai-inappropriate-task-allocation","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001","nist-ai-tevv-athlon"],"title":"Inappropriate human/AI task allocation and end-of-life risk","type":"risk"},{"id":"risk:ai-insecure-generated-code","rendered":true,"sources":["aiuc-1","iso-27001","nist-800-53"],"title":"Insecure AI-generated code and hallucinated or typosquatted dependencies","type":"risk"},{"id":"risk:ai-insufficient-human-oversight","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"Insufficient human oversight and automation complacency","type":"risk"},{"id":"risk:ai-lack-explainability-transparency","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity"],"title":"Lack of AI explainability, documentation and disclosure","type":"risk"},{"id":"risk:ai-model-drift-monitoring","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"Model/data drift and inadequate post-deployment monitoring","type":"risk"},{"id":"risk:ai-model-resilience-fallback-gap","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"Insufficient AI resilience and fallback mechanisms","type":"risk"},{"id":"risk:ai-poor-training-data-quality","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity"],"title":"Poor-quality, unrepresentative or mislabeled training data","type":"risk"},{"id":"risk:ai-power-concentration-societal","rendered":true,"sources":["aiuc-1","coso-erm","eu-ai-act","iso-31000","iso-42001","nist-csf-2"],"title":"AI power concentration and erosion of societal trust","type":"risk"},{"id":"risk:ai-privacy-leakage","rendered":true,"sources":["aiuc-1","eu-ai-act","hipaa","iso-27001","iso-42001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"AI privacy leakage and re-identification","type":"risk"},{"id":"risk:ai-prohibited-practices","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001"],"title":"Deployment of prohibited AI practices (EU AI Act Art.5)","type":"risk"},{"id":"risk:ai-safety-harm-to-people","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-31000","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"AI safety failures causing physical or psychological harm","type":"risk"},{"id":"risk:ai-secrets-credential-leakage","rendered":true,"sources":["aiuc-1","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"Credential and secret leakage through AI inputs, outputs, logs and generated code","type":"risk"},{"id":"risk:ai-supply-chain-concentration","rendered":true,"sources":["aiuc-1","cobit-2019","dora","eu-ai-act","iso-27001","iso-42001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2"],"title":"AI supply-chain compromise and provider concentration","type":"risk"},{"id":"risk:asset-aging-hardware-no-replacement","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"Aging hardware with no periodic replacement scheme","type":"risk"},{"id":"risk:asset-inventory-gap","rendered":true,"sources":["coso-ic","gdpr","iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"Incomplete asset inventory and classification","type":"risk"},{"id":"risk:asset-uncontrolled-copying-removable-media","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","pci-dss","soc2"],"title":"Uncontrolled copying to removable media / unmanaged software installs","type":"risk"},{"id":"risk:aware-insufficient-training","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","nydfs-500","soc2"],"title":"Inadequate security awareness and training","type":"risk"},{"id":"risk:aware-no-acceptable-use-policy","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","nydfs-500","sox"],"title":"No acceptable-use policy for messaging and telecoms","type":"risk"},{"id":"risk:aware-phishing-social-engineering","rendered":true,"sources":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss"],"title":"Phishing, spear-phishing and social engineering","type":"risk"},{"id":"risk:aware-role-based-training-gap","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","nydfs-500","soc2"],"title":"Missing role-based and ongoing security/privacy training","type":"risk"},{"id":"risk:aware-user-error-mishandling","rendered":true,"sources":["aiuc-1","gdpr","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","soc1","soc2"],"title":"User error and mishandling of sensitive information","type":"risk"},{"id":"risk:bcdr-it-resilience-outage","rendered":true,"sources":["cobit-2019","dora","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"title":"IT resilience failure — unplanned outage, data loss, slow recovery","type":"risk"},{"id":"risk:bcdr-no-tested-continuity-plan","rendered":true,"sources":["cobit-2019","dora","iso-27001","nist-800-53","nydfs-500","soc1","soc2","sox"],"title":"Absent or untested business continuity / disaster recovery plan","type":"risk"},{"id":"risk:bcdr-single-point-concentration","rendered":true,"sources":["cobit-2019","iso-27001","nist-800-53","nist-csf-2","nydfs-500","soc2"],"title":"Single-site / single-region / single-supply concentration","type":"risk"},{"id":"risk:compliance-client-suitability-fiduciary","rendered":true,"sources":["coso-erm","iso-31000","nist-800-53","nist-csf-2"],"title":"Client suitability, disclosure and fiduciary breaches","type":"risk"},{"id":"risk:compliance-environmental-regulatory","rendered":true,"sources":["cobit-2019","iia-2024","iso-27001","nist-csf-2"],"title":"Environmental regulatory non-compliance","type":"risk"},{"id":"risk:compliance-improper-market-practices","rendered":true,"sources":["cobit-2019","coso-erm","iso-27001","nis2","nist-800-53","nist-csf-2"],"title":"Improper business or market practices","type":"risk"},{"id":"risk:compliance-ip-infringement","rendered":true,"sources":["cobit-2019","iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"Intellectual property loss or infringement","type":"risk"},{"id":"risk:compliance-litigation-enforcement","rendered":true,"sources":["cobit-2019","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"title":"Litigation, investigation and enforcement exposure","type":"risk"},{"id":"risk:compliance-no-independent-audit","rendered":true,"sources":["ccpa","cobit-2019","iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-27001","nis2","nist-800-53"],"title":"Lack of independent audit and compliance review","type":"risk"},{"id":"risk:compliance-regulatory-policy-change","rendered":true,"sources":["cobit-2019","coso-erm","coso-ic","iso-27001","iso-31000","soc2"],"title":"Adverse regulatory or policy change","type":"risk"},{"id":"risk:compliance-sector-regulatory-breach","rendered":true,"sources":["aiuc-1","cobit-2019","eu-ai-act","gdpr","iso-27001","nist-800-53"],"title":"Sector regulatory non-compliance (financial, healthcare, trade)","type":"risk"},{"id":"risk:compliance-selection-exposure-limits","rendered":true,"sources":["cobit-2019","iia-2024","nist-csf-2"],"title":"Client selection, sponsorship and exposure-limit breaches","type":"risk"},{"id":"risk:config-internet-exposed-misconfig","rendered":true,"sources":["aiuc-1","iso-27001","nist-800-53","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc2"],"title":"Internet-exposed or misconfigured systems","type":"risk"},{"id":"risk:config-poor-baseline-drift","rendered":true,"sources":["coso-ic","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"title":"Poor configuration management and insecure baseline drift","type":"risk"},{"id":"risk:config-weak-change-control","rendered":true,"sources":["cobit-2019","coso-ic","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"title":"Absent or weak change-control procedures","type":"risk"},{"id":"risk:crypto-cleartext-credential-transfer","rendered":true,"sources":["aiuc-1","hipaa","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"title":"Credentials and sensitive data transmitted in clear text","type":"risk"},{"id":"risk:crypto-counterfeit-certificates","rendered":true,"sources":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"title":"Compromised or counterfeit certificates / certificate authority","type":"risk"},{"id":"risk:crypto-weak-or-absent-encryption","rendered":true,"sources":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"title":"Weak or absent encryption and key management","type":"risk"},{"id":"risk:cyber-adversary-threat-sources","rendered":true,"sources":["aiuc-1","cobit-2019","coso-ic","gdpr","iso-27001","iso-31000","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2","sox"],"title":"Attacks by capable, motivated threat actors","type":"risk"},{"id":"risk:cyber-coordinated-campaign","rendered":true,"sources":["aiuc-1","cobit-2019","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","soc2"],"title":"Coordinated multi-stage / APT campaigns","type":"risk"},{"id":"risk:cyber-reconnaissance","rendered":true,"sources":["cobit-2019","iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"Adversary reconnaissance and information gathering","type":"risk"},{"id":"risk:data-breach-unauthorized-disclosure","rendered":true,"sources":["aiuc-1","ccpa","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","soc2"],"title":"Unauthorized disclosure / breach of sensitive information","type":"risk"},{"id":"risk:data-corruption-integrity-loss","rendered":true,"sources":["aiuc-1","ccpa","cobit-2019","eu-ai-act","hipaa","iso-27001","nist-800-53","soc2"],"title":"Corruption or integrity loss of critical data","type":"risk"},{"id":"risk:data-excessive-collection-purpose-creep","rendered":true,"sources":["ccpa","gdpr","hipaa","iso-27001","nist-800-53","soc2"],"title":"Excessive collection, purpose creep and secondary use","type":"risk"},{"id":"risk:data-exfiltration-espionage","rendered":true,"sources":["aiuc-1","cobit-2019","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc2"],"title":"Data exfiltration and theft of information by attackers","type":"risk"},{"id":"risk:data-inventory-flows-unmapped","rendered":true,"sources":["coso-ic","gdpr","nist-800-53","nist-csf-2","soc2"],"title":"Undocumented data inventory and unmapped data flows","type":"risk"},{"id":"risk:data-privacy-harms-to-individuals","rendered":true,"sources":["aiuc-1","ccpa","eu-ai-act","gdpr","hipaa","iso-42001","nist-800-53","nist-ai-agent-identity","soc2"],"title":"Privacy harms: distortion, stigmatization, unwarranted restriction","type":"risk"},{"id":"risk:data-privacy-program-noncompliance","rendered":true,"sources":["aiuc-1","ccpa","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","soc2"],"title":"Privacy-program non-compliance (GDPR, CCPA, state laws)","type":"risk"},{"id":"risk:data-reidentification-inference","rendered":true,"sources":["aiuc-1","ccpa","hipaa","iso-27001","nist-800-53"],"title":"Re-identification and unanticipated revelation from data","type":"risk"},{"id":"risk:data-residual-media-disposal","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","pci-dss","soc2"],"title":"Residual data on improperly disposed or re-used media","type":"risk"},{"id":"risk:data-retention-noncompliance","rendered":true,"sources":["ccpa","gdpr","iso-27001","nist-800-53","soc2"],"title":"Unlawful retention or premature deletion of records","type":"risk"},{"id":"risk:data-surveillance-appropriation","rendered":true,"sources":["ccpa","hipaa","nist-800-53","soc2"],"title":"Excessive surveillance, appropriation and induced disclosure","type":"risk"},{"id":"risk:data-transparency-notice-dark-patterns","rendered":true,"sources":["ccpa","gdpr","hipaa","nist-800-53","nist-csf-2","soc2"],"title":"Inadequate transparency, notice and deceptive privacy communications","type":"risk"},{"id":"risk:esg-climate-physical","rendered":true,"sources":["cobit-2019","iso-27001","nist-800-53","nist-csf-2","nydfs-500"],"title":"Physical climate risk to facilities and supply chains","type":"risk"},{"id":"risk:esg-climate-transition","rendered":true,"sources":["iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2"],"title":"Climate transition risk — carbon pricing and stranded assets","type":"risk"},{"id":"risk:esg-greenwashing-disclosure","rendered":true,"sources":["iia-2024"],"title":"ESG disclosure gaps and greenwashing","type":"risk"},{"id":"risk:esg-social-human-rights","rendered":true,"sources":["coso-ic","iia-2024"],"title":"Social and human-rights failures in operations and supply chain","type":"risk"},{"id":"risk:fin-accuracy-measurement-errors","rendered":true,"sources":["cobit-2019","soc1","soc2","sox"],"title":"Measurement and calculation errors (accuracy)","type":"risk"},{"id":"risk:fin-completeness-understatement","rendered":true,"sources":["cobit-2019","soc1","soc2","sox"],"title":"Understatement of liabilities/expenses (completeness)","type":"risk"},{"id":"risk:fin-crime-aml-sanctions","rendered":true,"sources":["cobit-2019","coso-erm","coso-ic","iso-31000","nist-csf-2","soc2"],"title":"Money laundering, sanctions and financial-crime program failures","type":"risk"},{"id":"risk:fin-cutoff-period-errors","rendered":true,"sources":["cobit-2019","soc1","soc2","sox"],"title":"Period cut-off errors","type":"risk"},{"id":"risk:fin-data-quality-reporting-integrity","rendered":true,"sources":["cobit-2019","iso-27001","soc1","soc2","sox"],"title":"Data-quality and IPE integrity failures in reporting","type":"risk"},{"id":"risk:fin-existence-overstatement","rendered":true,"sources":["cobit-2019","nist-800-53","soc1","soc2","sox"],"title":"Overstatement of assets/revenue (existence & occurrence)","type":"risk"},{"id":"risk:fin-financial-statement-fraud","rendered":true,"sources":["cobit-2019","coso-ic","iia-2024","iso-27001","nist-800-53","soc2","sox"],"title":"Financial-statement fraud and management override","type":"risk"},{"id":"risk:fin-icfr-material-weakness","rendered":true,"sources":["cobit-2019","coso-erm","coso-ic","iia-2024","iso-27001","nis2","nist-800-53","nist-csf-2","soc2","sox"],"title":"Ineffective ICFR / undisclosed material weakness","type":"risk"},{"id":"risk:fin-journal-entry-management-override","rendered":true,"sources":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2","sox"],"title":"Manual journal entries and management-override risk","type":"risk"},{"id":"risk:fin-presentation-disclosure","rendered":true,"sources":["iia-2024","sox"],"title":"Presentation and disclosure deficiencies","type":"risk"},{"id":"risk:fin-revenue-recognition-misstatement","rendered":true,"sources":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc2","sox"],"title":"Revenue-recognition misstatement (fictitious, mis-timed, mis-measured)","type":"risk"},{"id":"risk:fin-rights-obligations-relatedparty","rendered":true,"sources":["sox"],"title":"Rights, obligations and related-party misstatement","type":"risk"},{"id":"risk:fin-segregation-of-duties","rendered":true,"sources":["aiuc-1","cobit-2019","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc2","sox"],"title":"Segregation-of-duties conflicts in financial processes","type":"risk"},{"id":"risk:fin-tax-provision-misstatement","rendered":true,"sources":["soc2","sox"],"title":"Tax provision, deferred-tax and uncertain-position misstatement","type":"risk"},{"id":"risk:fin-valuation-impairment","rendered":true,"sources":["sox"],"title":"Valuation and impairment misstatement","type":"risk"},{"id":"risk:financial-credit-market-risk","rendered":true,"sources":["iso-27001","iso-31000","nist-csf-2"],"title":"Credit and market (rate/FX) risk","type":"risk"},{"id":"risk:financial-liquidity-capital","rendered":true,"sources":["coso-erm","coso-ic","iso-31000","nist-800-53","nist-csf-2","nydfs-500","soc2","sox"],"title":"Liquidity, capital-structure and refinancing risk","type":"risk"},{"id":"risk:fraud-external","rendered":true,"sources":["hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc2"],"title":"External fraud — third-party theft, forgery, payment and account fraud","type":"risk"},{"id":"risk:fraud-internal-misappropriation","rendered":true,"sources":["coso-erm","coso-ic","iso-27001","nis2","nist-800-53","nist-csf-2","soc2","sox"],"title":"Internal fraud — asset misappropriation, embezzlement, forgery","type":"risk"},{"id":"risk:fraud-unauthorized-trading-activity","rendered":true,"sources":["coso-ic","iso-27001","nist-800-53","soc2","sox"],"title":"Unauthorized activity — rogue trading, position mismarking, concealment","type":"risk"},{"id":"risk:gov-organizational-change-resistance","rendered":true,"sources":["cobit-2019","coso-erm","coso-ic","nist-800-53","nydfs-500"],"title":"Organizational change and transformation failure","type":"risk"},{"id":"risk:gov-oversight-failure","rendered":true,"sources":["cobit-2019","coso-erm","coso-ic","iia-2024","iia-pos-2026-erm","nis2","nist-csf-2","soc2","sox"],"title":"Inadequate board and management oversight of risk and control","type":"risk"},{"id":"risk:gov-policy-absent","rendered":true,"sources":["cobit-2019","coso-erm","coso-ic","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"title":"Missing or insufficient security and privacy policies","type":"risk"},{"id":"risk:gov-project-change-management","rendered":true,"sources":["cobit-2019","iso-27001","iso-31000","nist-csf-2"],"title":"Major project / program delivery failure","type":"risk"},{"id":"risk:gov-strategy-innovation-obsolescence","rendered":true,"sources":["cobit-2019","nist-800-53","nydfs-500"],"title":"Innovation and R&D governance failure","type":"risk"},{"id":"risk:gov-weak-internal-control","rendered":true,"sources":["cobit-2019","coso-erm","coso-ic","iia-2024","iso-27001","nist-800-53","nist-csf-2","nydfs-500","soc2","sox"],"title":"Weak internal control environment enabling fraud and error","type":"risk"},{"id":"risk:hr-discrimination-harassment","rendered":true,"sources":["hipaa","iso-27001","nist-800-53"],"title":"Discrimination, harassment and hostile-workplace culture","type":"risk"},{"id":"risk:hr-employment-practices-disputes","rendered":true,"sources":["iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"title":"Employment-practice and labor-law violations","type":"risk"},{"id":"risk:hr-insufficient-screening","rendered":true,"sources":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc2"],"title":"Insufficient personnel screening and vetting","type":"risk"},{"id":"risk:hr-missing-security-terms-discipline","rendered":true,"sources":["ccpa","coso-ic","gdpr","hipaa","iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"Missing security terms in contracts and no disciplinary process","type":"risk"},{"id":"risk:hr-talent-loss-succession","rendered":true,"sources":["dora","nist-800-53","nist-csf-2","soc2"],"title":"Critical talent loss, scarcity and succession gaps","type":"risk"},{"id":"risk:hr-workplace-health-safety","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2"],"title":"Workplace health, safety and well-being failures","type":"risk"},{"id":"risk:ir-breach-notification-failure","rendered":true,"sources":["gdpr","hipaa","iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"Failure to detect, assess, and notify breaches on time","type":"risk"},{"id":"risk:ir-no-response-procedures","rendered":true,"sources":["coso-ic","iso-27001","nist-800-53","nist-csf-2"],"title":"No or insufficient incident-response procedures","type":"risk"},{"id":"risk:log-missing-audit-trail","rendered":true,"sources":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1"],"title":"Missing or insufficient logging and audit trails","type":"risk"},{"id":"risk:log-no-monitoring-supervision","rendered":true,"sources":["cobit-2019","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2"],"title":"No security monitoring or supervision of privileged activity","type":"risk"},{"id":"risk:net-cloud-multitenancy-exploit","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","pci-dss","soc2"],"title":"Cloud multi-tenancy isolation and data-scavenging exploits","type":"risk"},{"id":"risk:net-denial-of-service","rendered":true,"sources":["cobit-2019","dora","nist-800-53","nist-csf-2","soc2"],"title":"Denial-of-service and system saturation","type":"risk"},{"id":"risk:net-interception-mitm","rendered":true,"sources":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"title":"Communications interception, eavesdropping and man-in-the-middle","type":"risk"},{"id":"risk:net-poor-perimeter-architecture","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","pci-dss","soc2"],"title":"Poor network architecture and unprotected public connections","type":"risk"},{"id":"risk:net-remote-work-mobile-exposure","rendered":true,"sources":["hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc2"],"title":"Remote-work, mobile and split-tunneling exposure","type":"risk"},{"id":"risk:net-session-hijacking","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"Session hijacking and unauthorized-protocol egress","type":"risk"},{"id":"risk:net-untrustworthy-input-data","rendered":true,"sources":["cobit-2019","iso-27001","nist-800-53"],"title":"Acceptance of data from untrustworthy sources","type":"risk"},{"id":"risk:ops-advisory-duty-of-care","rendered":true,"sources":["iia-2024"],"title":"Negligent advisory activities and breach of duty of care","type":"risk"},{"id":"risk:ops-core-process-inefficiency","rendered":true,"sources":["cobit-2019","coso-erm","coso-ic","iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"Core process breakdown and inability to scale","type":"risk"},{"id":"risk:ops-counterparty-settlement-disputes","rendered":true,"sources":["coso-erm","iso-31000","nist-800-53","nist-csf-2","soc2"],"title":"Trade-counterparty performance and settlement disputes","type":"risk"},{"id":"risk:ops-documentation-account-management","rendered":true,"sources":["aiuc-1","gdpr","hipaa","iso-27001","iso-31000","nist-800-53","nist-ai-agent-identity","nist-csf-2"],"title":"Client intake, documentation and account-management failures","type":"risk"},{"id":"risk:ops-process-execution-errors","rendered":true,"sources":["cobit-2019","soc1","soc2","sox"],"title":"Transaction-processing and execution errors","type":"risk"},{"id":"risk:ops-product-flaws-design-model-error","rendered":true,"sources":["aiuc-1","cobit-2019","eu-ai-act","iso-27001","nist-800-53"],"title":"Product design and model errors","type":"risk"},{"id":"risk:ops-product-service-quality","rendered":true,"sources":["coso-erm","iso-31000","nist-csf-2","soc2"],"title":"Product and service quality failure","type":"risk"},{"id":"risk:ops-regulatory-reporting-failure","rendered":true,"sources":["iia-2024","iia-pos-2026-erm"],"title":"Failed or inaccurate mandatory regulatory reporting","type":"risk"},{"id":"risk:phys-cyber-physical-facility-attack","rendered":true,"sources":["hipaa","iso-27001","nist-800-53","nist-csf-2","soc1","soc2"],"title":"Physical and cyber-physical attacks on facilities and infrastructure","type":"risk"},{"id":"risk:phys-damage-physical-assets-disaster","rendered":true,"sources":["cobit-2019","iso-27001","nist-800-53","nist-csf-2","nydfs-500","soc2"],"title":"Physical damage to assets from disaster, terrorism or vandalism","type":"risk"},{"id":"risk:phys-environmental-degradation","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","soc1"],"title":"Environmental degradation of equipment (dust, humidity, temperature, EMI)","type":"risk"},{"id":"risk:phys-fire-water-suppression-gap","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","soc1"],"title":"Inadequate protection against fire, flood and physical hazards","type":"risk"},{"id":"risk:phys-inadequate-facility-access","rendered":true,"sources":["hipaa","iso-27001","nist-800-53","nist-csf-2","soc1","soc2"],"title":"Inadequate physical protection and access controls","type":"risk"},{"id":"risk:phys-remote-spying-shoulder-surfing","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"Remote spying and shoulder-surfing of screens/documents","type":"risk"},{"id":"risk:phys-theft-of-equipment-media","rendered":true,"sources":["hipaa","iso-27001","nist-800-53","nist-csf-2","pci-dss","soc1","soc2"],"title":"Theft of equipment, media or unattended devices","type":"risk"},{"id":"risk:privacy-cross-border-transfer","rendered":true,"sources":["aiuc-1","ccpa","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2"],"title":"Cross-border personal-data transfer without safeguards","type":"risk"},{"id":"risk:privacy-loss-of-trust","rendered":true,"sources":["ccpa","gdpr","hipaa","nist-800-53","soc2","sox"],"title":"Erosion of individual trust and confidence in data practices","type":"risk"},{"id":"risk:privacy-no-privacy-by-design","rendered":true,"sources":["aiuc-1","cobit-2019","eu-ai-act","hipaa","iso-27001","nist-800-53","soc2"],"title":"Absence of privacy-by-design and default","type":"risk"},{"id":"risk:privacy-power-imbalance-self-determination","rendered":true,"sources":["aiuc-1","ccpa","eu-ai-act","gdpr","hipaa","iso-42001","nist-800-53","soc2"],"title":"Power imbalance and loss of self-determination over personal data","type":"risk"},{"id":"risk:reputational-brand-crisis","rendered":true,"sources":["coso-erm","coso-ic","gdpr","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2","sox"],"title":"Brand and reputational crisis","type":"risk"},{"id":"risk:reputational-stakeholder-trust","rendered":true,"sources":["cobit-2019","coso-erm","coso-ic","gdpr","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-31000","nist-800-53","nist-csf-2","soc2","sox"],"title":"Stakeholder trust and social-license erosion","type":"risk"},{"id":"risk:risk-assessment-inadequate","rendered":true,"sources":["cobit-2019","coso-erm","coso-ic","eu-ai-act","iso-31000","nist-800-53","nist-csf-2","nydfs-500","soc2","sox"],"title":"Inadequate or absent risk assessment process","type":"risk"},{"id":"risk:risk-securities-law-noncompliance","rendered":true,"sources":["iia-2024"],"title":"Securities-law and SEC-reporting non-compliance","type":"risk"},{"id":"risk:sdlc-insecure-privileged-apps","rendered":true,"sources":["aiuc-1","cobit-2019","eu-ai-act","gdpr","iso-27001","nist-800-53","nist-csf-2","pci-dss","sox"],"title":"Applications running with excessive privilege / insecure design","type":"risk"},{"id":"risk:sdlc-malware-injection-compromise","rendered":true,"sources":["aiuc-1","cobit-2019","dora","eu-ai-act","iso-27001","nist-800-53","nist-csf-2","pci-dss"],"title":"Malware delivery, insertion and compromise of systems","type":"risk"},{"id":"risk:sdlc-ransomware","rendered":true,"sources":["aiuc-1","cobit-2019","dora","eu-ai-act","iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"Ransomware disrupting operations and data availability","type":"risk"},{"id":"risk:sdlc-vulnerabilities-in-software","rendered":true,"sources":["cobit-2019","iso-27001","nist-800-53","nist-ai-tevv-athlon","nist-csf-2","pci-dss","sox"],"title":"Vulnerabilities introduced during software development","type":"risk"},{"id":"risk:strategic-concentration","rendered":true,"sources":["coso-erm","iso-31000","nist-800-53","nist-csf-2"],"title":"Product, customer or market concentration","type":"risk"},{"id":"risk:strategic-disruption-substitution","rendered":true,"sources":["cobit-2019","coso-erm","coso-ic","iso-31000","soc2"],"title":"Competitive disruption and business-model obsolescence","type":"risk"},{"id":"risk:strategic-geopolitical","rendered":true,"sources":["cobit-2019","coso-erm","coso-ic","dora","iso-27001","iso-31000","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2"],"title":"Geopolitical, macroeconomic and sovereign risk","type":"risk"},{"id":"risk:strategic-innovation-emerging-tech","rendered":true,"sources":["aiuc-1","coso-erm","coso-ic","iso-31000","iso-42001","soc2"],"title":"Innovation shortfall and emerging-technology adoption risk","type":"risk"},{"id":"risk:strategic-ma-integration","rendered":true,"sources":["coso-erm","iso-31000","nist-csf-2"],"title":"Failed M&A, integration or divestiture","type":"risk"},{"id":"risk:strategic-misalignment-execution","rendered":true,"sources":["cobit-2019","coso-erm","coso-ic","iia-pos-2026-erm","iia-pos-2026-three-lines","nist-800-53","nist-csf-2","nydfs-500","soc2"],"title":"Strategic misalignment and execution failure","type":"risk"},{"id":"risk:tech-hardware-equipment-failure","rendered":true,"sources":["cobit-2019","dora","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"title":"Hardware and equipment failure","type":"risk"},{"id":"risk:tech-illegal-data-processing","rendered":true,"sources":["ccpa","gdpr","hipaa","nist-800-53","soc2"],"title":"Illegal processing of personal or sensitive data","type":"risk"},{"id":"risk:tech-loss-essential-services","rendered":true,"sources":["cobit-2019","iso-27001","nist-800-53","nist-csf-2","nydfs-500","soc1"],"title":"Loss of essential services (power, HVAC, telecoms)","type":"risk"},{"id":"risk:tech-maintainability-breach","rendered":true,"sources":["cobit-2019","gdpr","nist-800-53","nist-csf-2","pci-dss"],"title":"Loss of system maintainability","type":"risk"},{"id":"risk:tech-software-system-failure","rendered":true,"sources":["cobit-2019","dora","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"title":"Software and information-system failure","type":"risk"},{"id":"risk:tech-unlicensed-counterfeit-software","rendered":true,"sources":["cobit-2019","iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"Use of unlicensed, counterfeit or pirated software","type":"risk"},{"id":"risk:tprm-critical-vendor-failure","rendered":true,"sources":["cobit-2019","dora","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"title":"Critical vendor failure, insolvency or concentration","type":"risk"},{"id":"risk:tprm-supply-chain-disruption","rendered":true,"sources":["cobit-2019","dora","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2"],"title":"Supply-chain disruption of critical inputs","type":"risk"},{"id":"risk:tprm-supply-chain-injection","rendered":true,"sources":["cobit-2019","iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"Malicious supply-chain injection of tampered hardware/software","type":"risk"},{"id":"risk:tprm-vendor-compliance-vicarious-liability","rendered":true,"sources":["ccpa","cobit-2019","dora","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"title":"Third-party compliance failure creating vicarious liability","type":"risk"},{"id":"risk:tprm-vendor-service-nonperformance","rendered":true,"sources":["ccpa","cobit-2019","dora","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"title":"Vendor/outsourcing service non-performance and disputes","type":"risk"},{"id":"risk:tprm-weak-supplier-oversight","rendered":true,"sources":["ccpa","cobit-2019","dora","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"title":"Weak supplier security requirements and monitoring","type":"risk"},{"id":"risk:vuln-inadequate-testing-scanning","rendered":true,"sources":["cobit-2019","gdpr","iso-27001","nist-800-53","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"title":"Inadequate vulnerability scanning and pre-release testing","type":"risk"},{"id":"risk:vuln-unpatched-known-flaws","rendered":true,"sources":["dora","gdpr","iso-27001","nist-800-53","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc2"],"title":"Exploitation of known, unpatched vulnerabilities","type":"risk"},{"id":"risk:vuln-zero-day","rendered":true,"sources":["aiuc-1","cobit-2019","dora","eu-ai-act","iso-27001","nist-800-53","nist-csf-2","pci-dss"],"title":"Zero-day exploitation","type":"risk"},{"id":"std:aiuc-1","rendered":true,"sources":["aiuc-1"],"title":"AIUC-1 (Jul 2026)","type":"standard"},{"id":"std:ccpa","rendered":true,"sources":["ccpa"],"title":"CCPA/CPRA","type":"standard"},{"id":"std:cobit-2019","rendered":true,"sources":["cobit-2019"],"title":"COBIT 2019","type":"standard"},{"id":"std:coso-erm","rendered":true,"sources":["coso-erm"],"title":"COSO ERM 2017","type":"standard"},{"id":"std:coso-ic","rendered":true,"sources":["coso-ic"],"title":"COSO IC 2013","type":"standard"},{"id":"std:dora","rendered":true,"sources":["dora"],"title":"EU DORA","type":"standard"},{"id":"std:eu-ai-act","rendered":true,"sources":["eu-ai-act"],"title":"EU AI Act","type":"standard"},{"id":"std:gdpr","rendered":true,"sources":["gdpr"],"title":"EU GDPR","type":"standard"},{"id":"std:hipaa","rendered":true,"sources":["hipaa"],"title":"HIPAA","type":"standard"},{"id":"std:iia-2024","rendered":true,"sources":["iia-2024"],"title":"IIA 2024 Standards","type":"standard"},{"id":"std:iia-pos-2026-erm","rendered":true,"sources":["iia-pos-2026-erm"],"title":"The Role of the Internal Audit Function in Enterprise Risk Management","type":"standard"},{"id":"std:iia-pos-2026-three-lines","rendered":true,"sources":["iia-pos-2026-three-lines"],"title":"Three Lines Model: Assurance and Advice in Support of Effective Governance","type":"standard"},{"id":"std:iso-27001","rendered":true,"sources":["iso-27001"],"title":"ISO/IEC 27001:2022","type":"standard"},{"id":"std:iso-31000","rendered":true,"sources":["iso-31000"],"title":"ISO 31000:2018","type":"standard"},{"id":"std:iso-42001","rendered":true,"sources":["iso-42001"],"title":"ISO/IEC 42001:2023 (AI)","type":"standard"},{"id":"std:nis2","rendered":true,"sources":["nis2"],"title":"EU NIS2","type":"standard"},{"id":"std:nist-800-53","rendered":true,"sources":["nist-800-53"],"title":"NIST SP 800-53 Rev5","type":"standard"},{"id":"std:nist-ai-agent-identity","rendered":true,"sources":["nist-ai-agent-identity"],"title":"NIST Agent Identity (draft, Feb 2026)","type":"standard"},{"id":"std:nist-ai-tevv-athlon","rendered":true,"sources":["nist-ai-tevv-athlon"],"title":"NIST TEVV-Athlon (draft, Aug 2026)","type":"standard"},{"id":"std:nist-csf-2","rendered":true,"sources":["nist-csf-2"],"title":"NIST CSF 2.0","type":"standard"},{"id":"std:nydfs-500","rendered":true,"sources":["nydfs-500"],"title":"NYDFS Part 500","type":"standard"},{"id":"std:pci-dss","rendered":true,"sources":["pci-dss"],"title":"PCI DSS v4.0.1","type":"standard"},{"id":"std:soc1","rendered":true,"sources":["soc1"],"title":"SOC 1","type":"standard"},{"id":"std:soc2","rendered":true,"sources":["soc2"],"title":"SOC 2 (TSC)","type":"standard"},{"id":"std:sox","rendered":true,"sources":["sox"],"title":"SOX / PCAOB (ICFR)","type":"standard"},{"id":"uc:UC-ACCESS-01","rendered":true,"sources":["nist-800-53","soc1","soc2","sox"],"title":"UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle","type":"unified"},{"id":"uc:UC-ACCESS-02","rendered":true,"sources":["iso-27001","nydfs-500"],"title":"UC-ACCESS-02 — Review user access rights periodically","type":"unified"},{"id":"uc:UC-ACCESS-03","rendered":true,"sources":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc2"],"title":"UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties","type":"unified"},{"id":"uc:UC-ACCESS-04","rendered":true,"sources":["iso-27001","nist-csf-2"],"title":"UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software","type":"unified"},{"id":"uc:UC-ACCESS-05","rendered":true,"sources":["aiuc-1","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity"],"title":"UC-ACCESS-05 — Enforce approved authorizations for information and functions","type":"unified"},{"id":"uc:UC-ACCESS-06","rendered":true,"sources":["iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2"],"title":"UC-ACCESS-06 — Manage unique identities and identifiers end to end","type":"unified"},{"id":"uc:UC-ACCESS-07","rendered":true,"sources":["nist-800-53","nist-csf-2"],"title":"UC-ACCESS-07 — Proof identities before binding credentials","type":"unified"},{"id":"uc:UC-ACCESS-08","rendered":true,"sources":["iso-27001","nist-800-53","nist-ai-agent-identity"],"title":"UC-ACCESS-08 — Manage and protect authenticators across their lifecycle","type":"unified"},{"id":"uc:UC-ACCESS-09","rendered":true,"sources":["hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss"],"title":"UC-ACCESS-09 — Authenticate all users with multi-factor authentication","type":"unified"},{"id":"uc:UC-ACCESS-10","rendered":true,"sources":["nist-800-53","nist-ai-agent-identity"],"title":"UC-ACCESS-10 — Authenticate devices and services before granting connections","type":"unified"},{"id":"uc:UC-ACCESS-11","rendered":true,"sources":["nist-800-53"],"title":"UC-ACCESS-11 — Defend logons against brute-force and anomalous attempts","type":"unified"},{"id":"uc:UC-ACCESS-12","rendered":true,"sources":["nist-800-53"],"title":"UC-ACCESS-12 — Lock, limit, and terminate user sessions","type":"unified"},{"id":"uc:UC-ACCESS-13","rendered":true,"sources":["nist-800-53"],"title":"UC-ACCESS-13 — Notify users of system terms and previous logon activity","type":"unified"},{"id":"uc:UC-ACCESS-14","rendered":true,"sources":["aiuc-1","nist-800-53"],"title":"UC-ACCESS-14 — Authorize public content and external information sharing","type":"unified"},{"id":"uc:UC-ACCESS-15","rendered":true,"sources":["coso-ic"],"title":"UC-ACCESS-15 — Design control activities over technology access","type":"unified"},{"id":"uc:UC-ACCESS-16","rendered":true,"sources":["soc1"],"title":"UC-ACCESS-16 — Authorize, test, and approve changes and development","type":"unified"},{"id":"uc:UC-ACCESS-17","rendered":true,"sources":["soc1"],"title":"UC-ACCESS-17 — Execute, monitor, and recover production processing","type":"unified"},{"id":"uc:UC-ACCESS-18","rendered":true,"sources":["iso-27001","nist-csf-2","soc1"],"title":"UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents","type":"unified"},{"id":"uc:UC-ACCESS-19","rendered":true,"sources":["nist-csf-2","soc1"],"title":"UC-ACCESS-19 — Restrict physical access and maintain environmental safeguards","type":"unified"},{"id":"uc:UC-ACCESS-20","rendered":true,"sources":["soc1"],"title":"UC-ACCESS-20 — Ensure complete, accurate, and authorized data processing","type":"unified"},{"id":"uc:UC-ACCESS-21","rendered":true,"sources":["soc1"],"title":"UC-ACCESS-21 — Manage subservice organizations supporting the system","type":"unified"},{"id":"uc:UC-AI-01","rendered":true,"sources":["aiuc-1","iso-42001"],"title":"UC-AI-01 — Maintain and periodically review the AI policy","type":"unified"},{"id":"uc:UC-AI-02","rendered":true,"sources":["aiuc-1","iso-42001"],"title":"UC-AI-02 — Define AI roles, responsibilities, and competencies","type":"unified"},{"id":"uc:UC-AI-03","rendered":true,"sources":["iso-42001"],"title":"UC-AI-03 — Document AI system resources and dependencies","type":"unified"},{"id":"uc:UC-AI-04","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001"],"title":"UC-AI-04 — Assess impacts and classify AI systems before deployment","type":"unified"},{"id":"uc:UC-AI-05","rendered":true,"sources":["iso-42001","nist-ai-tevv-athlon"],"title":"UC-AI-05 — Set responsible AI development objectives and requirements","type":"unified"},{"id":"uc:UC-AI-06","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001"],"title":"UC-AI-06 — Maintain AI system technical documentation","type":"unified"},{"id":"uc:UC-AI-07","rendered":true,"sources":["aiuc-1","iso-42001","nist-ai-tevv-athlon"],"title":"UC-AI-07 — Verify, validate, and control AI deployment and changes","type":"unified"},{"id":"uc:UC-AI-08","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"UC-AI-08 — Log and monitor AI system behavior in operation","type":"unified"},{"id":"uc:UC-AI-09","rendered":true,"sources":["eu-ai-act","iso-42001","nist-ai-agent-identity"],"title":"UC-AI-09 — Govern AI data quality, provenance, and preparation","type":"unified"},{"id":"uc:UC-AI-10","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001"],"title":"UC-AI-10 — Meet transparency obligations for AI systems","type":"unified"},{"id":"uc:UC-AI-11","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001"],"title":"UC-AI-11 — Operate AI concern, incident, and external reporting channels","type":"unified"},{"id":"uc:UC-AI-12","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001"],"title":"UC-AI-12 — Enforce responsible and lawful use of AI systems","type":"unified"},{"id":"uc:UC-AI-13","rendered":true,"sources":["aiuc-1","eu-ai-act","iso-42001"],"title":"UC-AI-13 — Assign AI value-chain roles and discharge obligations","type":"unified"},{"id":"uc:UC-AI-14","rendered":true,"sources":["aiuc-1","iso-42001"],"title":"UC-AI-14 — Manage responsible AI with suppliers and customers","type":"unified"},{"id":"uc:UC-AI-15","rendered":true,"sources":["eu-ai-act"],"title":"UC-AI-15 — Fulfill general-purpose AI model provider obligations","type":"unified"},{"id":"uc:UC-AI-16","rendered":true,"sources":["aiuc-1","eu-ai-act"],"title":"UC-AI-16 — Ensure human oversight of AI decisions","type":"unified"},{"id":"uc:UC-AI-17","rendered":true,"sources":["aiuc-1"],"title":"UC-AI-17 — Define customer data-use and output-rights policies for AI services","type":"unified"},{"id":"uc:UC-AI-18","rendered":true,"sources":["aiuc-1","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"UC-AI-18 — Defend AI interfaces against adversarial input, injection, and endpoint abuse","type":"unified"},{"id":"uc:UC-AI-19","rendered":true,"sources":["aiuc-1","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"UC-AI-19 — Constrain agent actions and tool use to authorized scope","type":"unified"},{"id":"uc:UC-AI-20","rendered":true,"sources":["aiuc-1","nist-ai-tevv-athlon"],"title":"UC-AI-20 — Prevent harmful, out-of-scope, hallucinated, and over-exposed AI outputs","type":"unified"},{"id":"uc:UC-AI-21","rendered":true,"sources":["aiuc-1"],"title":"UC-AI-21 — Commission independent third-party AI evaluations on a quarterly cadence","type":"unified"},{"id":"uc:UC-AI-22","rendered":true,"sources":["aiuc-1"],"title":"UC-AI-22 — Prevent leakage of credentials and secrets through AI systems","type":"unified"},{"id":"uc:UC-AI-23","rendered":true,"sources":["aiuc-1"],"title":"UC-AI-23 — Prevent misuse of AI systems for cyber offense and catastrophic harm","type":"unified"},{"id":"uc:UC-AI-24","rendered":true,"sources":["aiuc-1","eu-ai-act"],"title":"UC-AI-24 — Operate an AI quality management system","type":"unified"},{"id":"uc:UC-AI-25","rendered":true,"sources":["aiuc-1"],"title":"UC-AI-25 — Guide code-generating systems toward secure patterns and safe dependencies","type":"unified"},{"id":"uc:UC-ASSET-01","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"UC-ASSET-01 — Maintain a complete inventory of systems, hardware, and software","type":"unified"},{"id":"uc:UC-ASSET-02","rendered":true,"sources":["coso-ic","gdpr","nist-csf-2"],"title":"UC-ASSET-02 — Inventory data and document processing activities and flows","type":"unified"},{"id":"uc:UC-ASSET-03","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"UC-ASSET-03 — Classify, prioritize, and label information and assets","type":"unified"},{"id":"uc:UC-ASSET-04","rendered":true,"sources":["iso-27001","nist-800-53","pci-dss","soc2"],"title":"UC-ASSET-04 — Control storage media through use, storage, and destruction","type":"unified"},{"id":"uc:UC-ASSET-05","rendered":true,"sources":["nist-csf-2"],"title":"UC-ASSET-05 — Inventory supplier services and assess critical suppliers","type":"unified"},{"id":"uc:UC-ASSET-06","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-ASSET-06 — Govern acceptable use of endpoints, off-site, and external systems","type":"unified"},{"id":"uc:UC-ASSET-07","rendered":true,"sources":["iso-27001","nist-csf-2"],"title":"UC-ASSET-07 — Manage assets through their life cycle and recover them at exit","type":"unified"},{"id":"uc:UC-ASSET-08","rendered":true,"sources":["iso-27001"],"title":"UC-ASSET-08 — Transfer information securely under defined rules and agreements","type":"unified"},{"id":"uc:UC-ASSET-09","rendered":true,"sources":["nist-csf-2"],"title":"UC-ASSET-09 — Receive, analyze, and act on threat and vulnerability intelligence","type":"unified"},{"id":"uc:UC-ASSET-10","rendered":true,"sources":["nist-csf-2"],"title":"UC-ASSET-10 — Assess and track changes and exceptions for risk impact","type":"unified"},{"id":"uc:UC-ASSET-11","rendered":true,"sources":["nist-csf-2"],"title":"UC-ASSET-11 — Improve security plans and processes from operational lessons","type":"unified"},{"id":"uc:UC-ASSET-12","rendered":true,"sources":["sox"],"title":"UC-ASSET-12 — Operate scheduled processing, backup, and availability monitoring","type":"unified"},{"id":"uc:UC-AUDIT-01","rendered":true,"sources":["iia-2024"],"title":"UC-AUDIT-01 — Maintain an independent internal audit function","type":"unified"},{"id":"uc:UC-AUDIT-02","rendered":true,"sources":["iia-2024"],"title":"UC-AUDIT-02 — Establish a board-approved internal audit mandate and charter","type":"unified"},{"id":"uc:UC-AUDIT-03","rendered":true,"sources":["iia-2024"],"title":"UC-AUDIT-03 — Ensure board oversight and support of internal audit","type":"unified"},{"id":"uc:UC-AUDIT-04","rendered":true,"sources":["iia-2024"],"title":"UC-AUDIT-04 — Uphold integrity and ethical conduct in internal auditing","type":"unified"},{"id":"uc:UC-AUDIT-05","rendered":true,"sources":["iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"title":"UC-AUDIT-05 — Maintain auditor objectivity and disclose impairments","type":"unified"},{"id":"uc:UC-AUDIT-06","rendered":true,"sources":["iia-2024"],"title":"UC-AUDIT-06 — Ensure auditor competency and continuing development","type":"unified"},{"id":"uc:UC-AUDIT-07","rendered":true,"sources":["iia-2024"],"title":"UC-AUDIT-07 — Exercise due professional care and professional skepticism","type":"unified"},{"id":"uc:UC-AUDIT-08","rendered":true,"sources":["iia-2024"],"title":"UC-AUDIT-08 — Protect confidential information obtained in audit work","type":"unified"},{"id":"uc:UC-AUDIT-09","rendered":true,"sources":["iia-2024","iia-pos-2026-erm"],"title":"UC-AUDIT-09 — Develop a risk-based internal audit strategy and plan","type":"unified"},{"id":"uc:UC-AUDIT-10","rendered":true,"sources":["iia-2024"],"title":"UC-AUDIT-10 — Manage internal audit financial, human, and technology resources","type":"unified"},{"id":"uc:UC-AUDIT-11","rendered":true,"sources":["iia-2024"],"title":"UC-AUDIT-11 — Establish audit methodologies and engagement work programs","type":"unified"},{"id":"uc:UC-AUDIT-12","rendered":true,"sources":["iia-2024"],"title":"UC-AUDIT-12 — Plan engagements with risk-based objectives, scope, and criteria","type":"unified"},{"id":"uc:UC-AUDIT-13","rendered":true,"sources":["iia-2024"],"title":"UC-AUDIT-13 — Gather and analyze evidence to develop engagement findings","type":"unified"},{"id":"uc:UC-AUDIT-14","rendered":true,"sources":["iia-2024"],"title":"UC-AUDIT-14 — Evaluate findings and develop recommendations and action plans","type":"unified"},{"id":"uc:UC-AUDIT-15","rendered":true,"sources":["iia-2024"],"title":"UC-AUDIT-15 — Document and supervise engagement work","type":"unified"},{"id":"uc:UC-AUDIT-16","rendered":true,"sources":["iia-2024"],"title":"UC-AUDIT-16 — Communicate final engagement results to stakeholders","type":"unified"},{"id":"uc:UC-AUDIT-17","rendered":true,"sources":["iia-2024","nist-csf-2"],"title":"UC-AUDIT-17 — Follow up on findings and escalate risk acceptance","type":"unified"},{"id":"uc:UC-AUDIT-18","rendered":true,"sources":["coso-ic","iia-2024"],"title":"UC-AUDIT-18 — Communicate with stakeholders on assurance matters","type":"unified"},{"id":"uc:UC-AUDIT-19","rendered":true,"sources":["iia-2024"],"title":"UC-AUDIT-19 — Operate an audit quality assurance and improvement program","type":"unified"},{"id":"uc:UC-AUDIT-20","rendered":true,"sources":["iia-2024"],"title":"UC-AUDIT-20 — Obtain external quality assessments of internal audit","type":"unified"},{"id":"uc:UC-AUDIT-21","rendered":true,"sources":["cobit-2019","coso-ic","nist-800-53","sox"],"title":"UC-AUDIT-21 — Assess control effectiveness through testing and monitoring","type":"unified"},{"id":"uc:UC-AUDIT-22","rendered":true,"sources":["cobit-2019","nist-csf-2"],"title":"UC-AUDIT-22 — Review risk strategy and performance with leadership","type":"unified"},{"id":"uc:UC-AUDIT-23","rendered":true,"sources":["ccpa","cobit-2019","iia-2024","iia-pos-2026-three-lines","iso-27001"],"title":"UC-AUDIT-23 — Coordinate independent assurance reviews across providers","type":"unified"},{"id":"uc:UC-AUDIT-24","rendered":true,"sources":["cobit-2019","iso-27001"],"title":"UC-AUDIT-24 — Manage compliance with external legal and regulatory requirements","type":"unified"},{"id":"uc:UC-AUDIT-25","rendered":true,"sources":["iso-27001","soc2"],"title":"UC-AUDIT-25 — Maintain quality records and information for internal control","type":"unified"},{"id":"uc:UC-AUDIT-26","rendered":true,"sources":["nist-800-53"],"title":"UC-AUDIT-26 — Authorize systems and internal connections before operation","type":"unified"},{"id":"uc:UC-AUDIT-27","rendered":true,"sources":["iia-pos-2026-erm","iia-pos-2026-three-lines"],"title":"UC-AUDIT-27 — Govern expanded internal audit ERM responsibilities","type":"unified"},{"id":"uc:UC-BCDR-01","rendered":true,"sources":["cobit-2019","iso-27001","nist-800-53","nydfs-500"],"title":"UC-BCDR-01 — Maintain business continuity and disaster recovery plans","type":"unified"},{"id":"uc:UC-BCDR-02","rendered":true,"sources":["dora"],"title":"UC-BCDR-02 — Establish and govern an ICT operational resilience framework","type":"unified"},{"id":"uc:UC-BCDR-03","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"UC-BCDR-03 — Back up data and verify restorability","type":"unified"},{"id":"uc:UC-BCDR-04","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2"],"title":"UC-BCDR-04 — Provide redundant and alternate processing, storage, and telecom","type":"unified"},{"id":"uc:UC-BCDR-05","rendered":true,"sources":["nist-800-53","nist-csf-2","soc2"],"title":"UC-BCDR-05 — Manage capacity to meet availability requirements","type":"unified"},{"id":"uc:UC-BCDR-06","rendered":true,"sources":["cobit-2019","dora"],"title":"UC-BCDR-06 — Resolve operational incidents and eliminate root causes","type":"unified"},{"id":"uc:UC-BCDR-07","rendered":true,"sources":["nist-800-53","nist-csf-2"],"title":"UC-BCDR-07 — Execute recovery plans to restore systems and operations","type":"unified"},{"id":"uc:UC-BCDR-08","rendered":true,"sources":["nist-csf-2"],"title":"UC-BCDR-08 — Declare recovery complete and set post-incident norms","type":"unified"},{"id":"uc:UC-BCDR-09","rendered":true,"sources":["nist-csf-2"],"title":"UC-BCDR-09 — Communicate recovery status to stakeholders","type":"unified"},{"id":"uc:UC-BCDR-10","rendered":true,"sources":["dora","nist-800-53","soc2"],"title":"UC-BCDR-10 — Test recovery capabilities and train contingency personnel","type":"unified"},{"id":"uc:UC-BCDR-11","rendered":true,"sources":["nist-800-53"],"title":"UC-BCDR-11 — Sustain operations via safe modes and alternate mechanisms","type":"unified"},{"id":"uc:UC-BCDR-12","rendered":true,"sources":["cobit-2019"],"title":"UC-BCDR-12 — Operate IT services according to defined procedures","type":"unified"},{"id":"uc:UC-BCDR-13","rendered":true,"sources":["cobit-2019"],"title":"UC-BCDR-13 — Operate continuous security protection services","type":"unified"},{"id":"uc:UC-BCDR-14","rendered":true,"sources":["cobit-2019"],"title":"UC-BCDR-14 — Embed control activities in business processes","type":"unified"},{"id":"uc:UC-BCDR-16","rendered":true,"sources":["dora"],"title":"UC-BCDR-16 — Participate in cyber threat intelligence sharing","type":"unified"},{"id":"uc:UC-CONFIG-01","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","pci-dss","soc2"],"title":"UC-CONFIG-01 — Harden systems to approved secure configuration baselines","type":"unified"},{"id":"uc:UC-CONFIG-02","rendered":true,"sources":["iso-27001","nist-800-53","soc2","sox"],"title":"UC-CONFIG-02 — Authorize, test, and approve changes before production","type":"unified"},{"id":"uc:UC-CONFIG-03","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-CONFIG-03 — Separate environments and protect production data in testing","type":"unified"},{"id":"uc:UC-CONFIG-04","rendered":true,"sources":["gdpr","nist-csf-2","pci-dss"],"title":"UC-CONFIG-04 — Build security and privacy into software design and upkeep","type":"unified"},{"id":"uc:UC-CONFIG-05","rendered":true,"sources":["iso-27001","nist-800-53","soc2"],"title":"UC-CONFIG-05 — Permit only authorized software installation and use","type":"unified"},{"id":"uc:UC-CONFIG-06","rendered":true,"sources":["nist-800-53","nist-csf-2"],"title":"UC-CONFIG-06 — Verify authenticity and integrity of hardware and software","type":"unified"},{"id":"uc:UC-CONFIG-07","rendered":true,"sources":["nist-800-53","nist-csf-2"],"title":"UC-CONFIG-07 — Perform controlled, timely maintenance of systems and hardware","type":"unified"},{"id":"uc:UC-CONFIG-08","rendered":true,"sources":["nist-800-53"],"title":"UC-CONFIG-08 — Control maintenance tools, personnel, and remote sessions","type":"unified"},{"id":"uc:UC-CONFIG-09","rendered":true,"sources":["coso-ic","nist-800-53"],"title":"UC-CONFIG-09 — Document configuration management policy, plan, and procedures","type":"unified"},{"id":"uc:UC-CONFIG-10","rendered":true,"sources":["aiuc-1","nist-800-53"],"title":"UC-CONFIG-10 — Map where information resides and how data is processed","type":"unified"},{"id":"uc:UC-CRYPTO-01","rendered":true,"sources":["aiuc-1","hipaa","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"title":"UC-CRYPTO-01 — Encrypt data at rest and in transit","type":"unified"},{"id":"uc:UC-CRYPTO-02","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-CRYPTO-02 — Use approved algorithms and validated cryptographic modules","type":"unified"},{"id":"uc:UC-CRYPTO-03","rendered":true,"sources":["nist-800-53"],"title":"UC-CRYPTO-03 — Manage cryptographic keys and certificates across their lifecycle","type":"unified"},{"id":"uc:UC-CRYPTO-04","rendered":true,"sources":["nist-csf-2"],"title":"UC-CRYPTO-04 — Protect data in use from unauthorized access","type":"unified"},{"id":"uc:UC-DATA-01","rendered":true,"sources":["gdpr","nist-800-53","soc2"],"title":"UC-DATA-01 — Process personal data only under a documented lawful basis","type":"unified"},{"id":"uc:UC-DATA-02","rendered":true,"sources":["ccpa","gdpr","hipaa","nist-800-53","soc2"],"title":"UC-DATA-02 — Obtain and honor consent for collection, use, and disclosure","type":"unified"},{"id":"uc:UC-DATA-03","rendered":true,"sources":["hipaa","nist-800-53","soc2"],"title":"UC-DATA-03 — Limit personal-data use to stated purposes and minimum necessary","type":"unified"},{"id":"uc:UC-DATA-04","rendered":true,"sources":["gdpr","nist-800-53"],"title":"UC-DATA-04 — Restrict processing of special categories of personal data","type":"unified"},{"id":"uc:UC-DATA-05","rendered":true,"sources":["ccpa","gdpr","hipaa","nist-800-53","soc2"],"title":"UC-DATA-05 — Provide privacy notices and transparency to data subjects","type":"unified"},{"id":"uc:UC-DATA-06","rendered":true,"sources":["ccpa","hipaa","soc2"],"title":"UC-DATA-06 — Provide data subjects access to their personal data","type":"unified"},{"id":"uc:UC-DATA-07","rendered":true,"sources":["ccpa","hipaa","nist-800-53","soc2"],"title":"UC-DATA-07 — Keep personal data accurate and honor correction requests","type":"unified"},{"id":"uc:UC-DATA-08","rendered":true,"sources":["ccpa","gdpr"],"title":"UC-DATA-08 — Execute deletion and other rights requests within deadlines","type":"unified"},{"id":"uc:UC-DATA-09","rendered":true,"sources":["iso-27001","nist-800-53","soc2"],"title":"UC-DATA-09 — Retain personal and confidential data per schedule, then destroy it","type":"unified"},{"id":"uc:UC-DATA-10","rendered":true,"sources":["nist-800-53"],"title":"UC-DATA-10 — Protect physical media containing sensitive data","type":"unified"},{"id":"uc:UC-DATA-11","rendered":true,"sources":["aiuc-1","gdpr","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon"],"title":"UC-DATA-11 — Control data flows, leakage, and cross-border transfers","type":"unified"},{"id":"uc:UC-DATA-12","rendered":true,"sources":["aiuc-1","hipaa","iso-27001","nist-800-53"],"title":"UC-DATA-12 — De-identify, mask, or pseudonymize personal data","type":"unified"},{"id":"uc:UC-DATA-13","rendered":true,"sources":["ccpa","hipaa","iso-27001"],"title":"UC-DATA-13 — Safeguard personal information with reasonable security","type":"unified"},{"id":"uc:UC-DATA-14","rendered":true,"sources":["soc2"],"title":"UC-DATA-14 — Maintain and provide an accounting of disclosures","type":"unified"},{"id":"uc:UC-DATA-15","rendered":true,"sources":["soc2"],"title":"UC-DATA-15 — Record and notify unauthorized disclosures of personal data","type":"unified"},{"id":"uc:UC-DATA-16","rendered":true,"sources":["soc2"],"title":"UC-DATA-16 — Bind third parties handling personal data to privacy commitments","type":"unified"},{"id":"uc:UC-DATA-17","rendered":true,"sources":["soc2"],"title":"UC-DATA-17 — Resolve privacy inquiries, complaints, and disputes","type":"unified"},{"id":"uc:UC-DATA-18","rendered":true,"sources":["nist-800-53"],"title":"UC-DATA-18 — Govern automated matching of PII under formal agreements","type":"unified"},{"id":"uc:UC-FIN-01","rendered":true,"sources":["sox"],"title":"UC-FIN-01 — Deploy financial control activities through policies","type":"unified"},{"id":"uc:UC-FIN-02","rendered":true,"sources":["sox"],"title":"UC-FIN-02 — Review financial results and the period-end close","type":"unified"},{"id":"uc:UC-FIN-03","rendered":true,"sources":["sox"],"title":"UC-FIN-03 — Perform and review account reconciliations","type":"unified"},{"id":"uc:UC-FIN-04","rendered":true,"sources":["nist-800-53","sox"],"title":"UC-FIN-04 — Authorize transactions with attributable approvals","type":"unified"},{"id":"uc:UC-FIN-05","rendered":true,"sources":["sox"],"title":"UC-FIN-05 — Segregate incompatible financial duties","type":"unified"},{"id":"uc:UC-FIN-06","rendered":true,"sources":["soc2","sox"],"title":"UC-FIN-06 — Validate completeness and accuracy of system inputs","type":"unified"},{"id":"uc:UC-FIN-07","rendered":true,"sources":["soc2","sox"],"title":"UC-FIN-07 — Control automated processing and resolve exceptions","type":"unified"},{"id":"uc:UC-FIN-08","rendered":true,"sources":["soc2","sox"],"title":"UC-FIN-08 — Control interface transfers and output delivery","type":"unified"},{"id":"uc:UC-FIN-09","rendered":true,"sources":["soc2","sox"],"title":"UC-FIN-09 — Ensure quality of information used in reporting","type":"unified"},{"id":"uc:UC-FIN-10","rendered":true,"sources":["soc2","sox"],"title":"UC-FIN-10 — Safeguard assets and stored financial data","type":"unified"},{"id":"uc:UC-GOV-01","rendered":true,"sources":["cobit-2019"],"title":"UC-GOV-01 — Establish and maintain the enterprise governance framework","type":"unified"},{"id":"uc:UC-GOV-02","rendered":true,"sources":["coso-erm","nist-csf-2"],"title":"UC-GOV-02 — Understand organizational context and stakeholder expectations","type":"unified"},{"id":"uc:UC-GOV-03","rendered":true,"sources":["iso-27001","nist-csf-2","nydfs-500"],"title":"UC-GOV-03 — Identify and manage legal, regulatory, and contractual obligations","type":"unified"},{"id":"uc:UC-GOV-04","rendered":true,"sources":["coso-erm","coso-ic","nist-csf-2","soc2","sox"],"title":"UC-GOV-04 — Set tone at the top: integrity, ethics, and risk-aware culture","type":"unified"},{"id":"uc:UC-GOV-05","rendered":true,"sources":["coso-erm","coso-ic","nis2","nist-csf-2","soc2"],"title":"UC-GOV-05 — Ensure board-level oversight of risk and internal control","type":"unified"},{"id":"uc:UC-GOV-06","rendered":true,"sources":["coso-erm","coso-ic","iso-27001","nist-csf-2","soc2"],"title":"UC-GOV-06 — Define security roles, responsibilities, and authorities","type":"unified"},{"id":"uc:UC-GOV-07","rendered":true,"sources":["coso-ic","iso-27001","nist-800-53","soc2"],"title":"UC-GOV-07 — Hold individuals accountable for control responsibilities","type":"unified"},{"id":"uc:UC-GOV-08","rendered":true,"sources":["iso-27001"],"title":"UC-GOV-08 — Segregate conflicting duties and areas of responsibility","type":"unified"},{"id":"uc:UC-GOV-09","rendered":true,"sources":["nist-800-53","nydfs-500"],"title":"UC-GOV-09 — Appoint accountable security leadership (CISO)","type":"unified"},{"id":"uc:UC-GOV-10","rendered":true,"sources":["cobit-2019","coso-erm","coso-ic","nydfs-500"],"title":"UC-GOV-10 — Attract, develop, and retain competent personnel","type":"unified"},{"id":"uc:UC-GOV-11","rendered":true,"sources":["cobit-2019","nist-800-53","nist-csf-2"],"title":"UC-GOV-11 — Allocate adequate resources and budget for security","type":"unified"},{"id":"uc:UC-GOV-12","rendered":true,"sources":["cobit-2019","coso-erm"],"title":"UC-GOV-12 — Align strategy and business objectives with mission and risk","type":"unified"},{"id":"uc:UC-GOV-13","rendered":true,"sources":["cobit-2019"],"title":"UC-GOV-13 — Govern the technology investment portfolio for value","type":"unified"},{"id":"uc:UC-GOV-14","rendered":true,"sources":["hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"title":"UC-GOV-14 — Establish and maintain approved security policies and procedures","type":"unified"},{"id":"uc:UC-GOV-15","rendered":true,"sources":["cobit-2019","nist-800-53","nydfs-500"],"title":"UC-GOV-15 — Operate a management-approved information security program","type":"unified"},{"id":"uc:UC-GOV-16","rendered":true,"sources":["nist-800-53","soc2"],"title":"UC-GOV-16 — Select and tailor a risk-based control baseline","type":"unified"},{"id":"uc:UC-GOV-17","rendered":true,"sources":["cobit-2019","coso-erm","nist-800-53","nist-csf-2"],"title":"UC-GOV-17 — Establish enterprise risk management strategy and appetite","type":"unified"},{"id":"uc:UC-GOV-18","rendered":true,"sources":["nist-800-53"],"title":"UC-GOV-18 — Document and approve system security and privacy plans","type":"unified"},{"id":"uc:UC-GOV-19","rendered":true,"sources":["cobit-2019","nist-800-53"],"title":"UC-GOV-19 — Maintain enterprise security and privacy architecture","type":"unified"},{"id":"uc:UC-GOV-20","rendered":true,"sources":["cobit-2019","nist-800-53"],"title":"UC-GOV-20 — Govern data as an asset with accountable oversight bodies","type":"unified"},{"id":"uc:UC-GOV-21","rendered":true,"sources":["cobit-2019","coso-erm","coso-ic","soc2"],"title":"UC-GOV-21 — Communicate and report risk and control information","type":"unified"},{"id":"uc:UC-GOV-22","rendered":true,"sources":["cobit-2019","iso-27001","nis2","nist-800-53"],"title":"UC-GOV-22 — Assess control effectiveness and authorize systems","type":"unified"},{"id":"uc:UC-GOV-23","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-GOV-23 — Maintain contacts with authorities and special interest groups","type":"unified"},{"id":"uc:UC-GOV-24","rendered":true,"sources":["nis2","nydfs-500"],"title":"UC-GOV-24 — Notify regulators of incidents and file required certifications","type":"unified"},{"id":"uc:UC-GOV-25","rendered":true,"sources":["gdpr","nist-800-53"],"title":"UC-GOV-25 — Operate a privacy program with accountable leadership","type":"unified"},{"id":"uc:UC-GOV-26","rendered":true,"sources":["gdpr","nist-800-53"],"title":"UC-GOV-26 — Enforce personal-data processing principles and minimization","type":"unified"},{"id":"uc:UC-GOV-27","rendered":true,"sources":["nist-800-53"],"title":"UC-GOV-27 — Manage privacy complaints and account for disclosures","type":"unified"},{"id":"uc:UC-GOV-29","rendered":true,"sources":["nis2","nist-800-53","nydfs-500"],"title":"UC-GOV-29 — Maintain secure acquisition, development, and maintenance policies","type":"unified"},{"id":"uc:UC-GOV-30","rendered":true,"sources":["nist-800-53","nydfs-500"],"title":"UC-GOV-30 — Maintain asset, media, and physical protection policies","type":"unified"},{"id":"uc:UC-GOV-31","rendered":true,"sources":["nis2","nist-800-53"],"title":"UC-GOV-31 — Maintain access control, identity, and personnel security policies","type":"unified"},{"id":"uc:UC-GOV-32","rendered":true,"sources":["nis2","nist-800-53"],"title":"UC-GOV-32 — Maintain security awareness and cyber-hygiene policies","type":"unified"},{"id":"uc:UC-GOV-33","rendered":true,"sources":["nist-800-53"],"title":"UC-GOV-33 — Maintain logging, monitoring, and system integrity policies","type":"unified"},{"id":"uc:UC-GOV-34","rendered":true,"sources":["nis2","nist-800-53","soc2"],"title":"UC-GOV-34 — Maintain business continuity and contingency planning policy","type":"unified"},{"id":"uc:UC-GOV-35","rendered":true,"sources":["nis2","nist-800-53"],"title":"UC-GOV-35 — Maintain incident response policy and procedures","type":"unified"},{"id":"uc:UC-GOV-36","rendered":true,"sources":["nis2","nist-800-53"],"title":"UC-GOV-36 — Maintain communications security and cryptography policies","type":"unified"},{"id":"uc:UC-GOV-37","rendered":true,"sources":["nist-800-53"],"title":"UC-GOV-37 — Operate insider-threat and threat-awareness programs","type":"unified"},{"id":"uc:UC-GOV-38","rendered":true,"sources":["iia-pos-2026-erm","iia-pos-2026-three-lines"],"title":"UC-GOV-38 — Assign and maintain Three Lines accountability by risk activity","type":"unified"},{"id":"uc:UC-HR-01","rendered":true,"sources":["hipaa","iso-27001","nist-800-53"],"title":"UC-HR-01 — Screen personnel commensurate with position risk","type":"unified"},{"id":"uc:UC-HR-02","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-HR-02 — Formalize security responsibilities in employment terms","type":"unified"},{"id":"uc:UC-HR-03","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-HR-03 — Secure termination and transfer of personnel","type":"unified"},{"id":"uc:UC-HR-04","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-HR-04 — Enforce a formal disciplinary process for violations","type":"unified"},{"id":"uc:UC-HR-05","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-HR-05 — Hold third-party personnel to equivalent security terms","type":"unified"},{"id":"uc:UC-HR-06","rendered":true,"sources":["nist-csf-2","soc2"],"title":"UC-HR-06 — Embed security and competence in HR practices","type":"unified"},{"id":"uc:UC-HR-07","rendered":true,"sources":["iso-27001"],"title":"UC-HR-07 — Secure remote working arrangements","type":"unified"},{"id":"uc:UC-IR-01","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-IR-01 — Maintain an approved incident response plan","type":"unified"},{"id":"uc:UC-IR-02","rendered":true,"sources":["nist-800-53"],"title":"UC-IR-02 — Train responders and test the incident response capability","type":"unified"},{"id":"uc:UC-IR-03","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-IR-03 — Provide channels to report events and obtain response help","type":"unified"},{"id":"uc:UC-IR-04","rendered":true,"sources":["iso-27001","nist-csf-2"],"title":"UC-IR-04 — Triage, categorize, and escalate reported security events","type":"unified"},{"id":"uc:UC-IR-05","rendered":true,"sources":["nist-csf-2"],"title":"UC-IR-05 — Assess and validate incident scope, impact, and magnitude","type":"unified"},{"id":"uc:UC-IR-06","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"UC-IR-06 — Respond to, contain, and eradicate declared incidents","type":"unified"},{"id":"uc:UC-IR-07","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2"],"title":"UC-IR-07 — Investigate incidents and preserve evidence and records","type":"unified"},{"id":"uc:UC-IR-08","rendered":true,"sources":["gdpr","hipaa","nist-800-53","nist-csf-2"],"title":"UC-IR-08 — Notify authorities and affected parties within deadlines","type":"unified"},{"id":"uc:UC-IR-09","rendered":true,"sources":["nist-csf-2","soc2"],"title":"UC-IR-09 — Recover from incidents using defined initiation criteria","type":"unified"},{"id":"uc:UC-IR-10","rendered":true,"sources":["coso-ic","iso-27001"],"title":"UC-IR-10 — Learn from incidents and communicate corrective actions","type":"unified"},{"id":"uc:UC-IR-11","rendered":true,"sources":["nist-800-53"],"title":"UC-IR-11 — Respond to information spillage with defined procedures","type":"unified"},{"id":"uc:UC-LOG-01","rendered":true,"sources":["hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","pci-dss"],"title":"UC-LOG-01 — Log security-relevant events across all systems","type":"unified"},{"id":"uc:UC-LOG-02","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-LOG-02 — Record complete audit content with synchronized clocks","type":"unified"},{"id":"uc:UC-LOG-03","rendered":true,"sources":["nist-800-53","nist-ai-agent-identity","nydfs-500"],"title":"UC-LOG-03 — Protect audit logs and retain them for required periods","type":"unified"},{"id":"uc:UC-LOG-04","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"UC-LOG-04 — Continuously monitor systems for anomalous activity","type":"unified"},{"id":"uc:UC-LOG-05","rendered":true,"sources":["nist-800-53","nist-csf-2"],"title":"UC-LOG-05 — Correlate and analyze events centrally with threat intel","type":"unified"},{"id":"uc:UC-LOG-06","rendered":true,"sources":["gdpr","nist-csf-2","soc2"],"title":"UC-LOG-06 — Evaluate events and declare incidents against defined criteria","type":"unified"},{"id":"uc:UC-LOG-07","rendered":true,"sources":["nist-800-53","nist-csf-2"],"title":"UC-LOG-07 — Monitor user sessions and personnel activity","type":"unified"},{"id":"uc:UC-LOG-08","rendered":true,"sources":["iso-27001"],"title":"UC-LOG-08 — Secure and monitor networks and network services","type":"unified"},{"id":"uc:UC-LOG-09","rendered":true,"sources":["aiuc-1","nist-800-53","nist-csf-2"],"title":"UC-LOG-09 — Monitor providers and exchange audit data across organizations","type":"unified"},{"id":"uc:UC-LOG-10","rendered":true,"sources":["nist-csf-2"],"title":"UC-LOG-10 — Monitor the physical environment for adverse events","type":"unified"},{"id":"uc:UC-LOG-11","rendered":true,"sources":["nist-800-53"],"title":"UC-LOG-11 — Monitor external sources for unauthorized information disclosure","type":"unified"},{"id":"uc:UC-NET-01","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","soc2"],"title":"UC-NET-01 — Segment networks and defend the external boundary","type":"unified"},{"id":"uc:UC-NET-02","rendered":true,"sources":["nist-800-53"],"title":"UC-NET-02 — Authorize and secure remote, wireless, and mobile access","type":"unified"},{"id":"uc:UC-NET-03","rendered":true,"sources":["nist-800-53"],"title":"UC-NET-03 — Provide trusted channels and control session lifecycle","type":"unified"},{"id":"uc:UC-NET-04","rendered":true,"sources":["nist-800-53"],"title":"UC-NET-04 — Isolate system, user, and security functions","type":"unified"},{"id":"uc:UC-NET-05","rendered":true,"sources":["nist-800-53"],"title":"UC-NET-05 — Prevent leakage via shared resources and covert channels","type":"unified"},{"id":"uc:UC-NET-06","rendered":true,"sources":["nist-800-53"],"title":"UC-NET-06 — Enforce separation with hardware and software mechanisms","type":"unified"},{"id":"uc:UC-NET-07","rendered":true,"sources":["nist-800-53"],"title":"UC-NET-07 — Secure name resolution and time services","type":"unified"},{"id":"uc:UC-NET-08","rendered":true,"sources":["nist-800-53"],"title":"UC-NET-08 — Maintain communications availability under attack and failure","type":"unified"},{"id":"uc:UC-NET-09","rendered":true,"sources":["nist-800-53"],"title":"UC-NET-09 — Reduce attack surface through resilient architecture","type":"unified"},{"id":"uc:UC-NET-10","rendered":true,"sources":["nist-800-53"],"title":"UC-NET-10 — Deploy deception and dynamic detection capabilities","type":"unified"},{"id":"uc:UC-NET-11","rendered":true,"sources":["nist-800-53"],"title":"UC-NET-11 — Conceal operational information from adversaries","type":"unified"},{"id":"uc:UC-NET-12","rendered":true,"sources":["nist-800-53"],"title":"UC-NET-12 — Restrict communication-capable devices, ports, and sensors","type":"unified"},{"id":"uc:UC-NET-13","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-NET-13 — Control mobile code and web content","type":"unified"},{"id":"uc:UC-NET-14","rendered":true,"sources":["nist-800-53"],"title":"UC-NET-14 — Enforce policy on cross-domain information exchange","type":"unified"},{"id":"uc:UC-PHYS-01","rendered":true,"sources":["hipaa","iso-27001","nist-800-53","soc2"],"title":"UC-PHYS-01 — Restrict physical access to facilities and secure areas","type":"unified"},{"id":"uc:UC-PHYS-02","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-PHYS-02 — Monitor physical access and retain visitor and entry records","type":"unified"},{"id":"uc:UC-PHYS-03","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2"],"title":"UC-PHYS-03 — Protect facilities against fire, water, and environmental hazards","type":"unified"},{"id":"uc:UC-PHYS-04","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-PHYS-04 — Site facilities and equipment to minimize hazards and exposure","type":"unified"},{"id":"uc:UC-PHYS-05","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-PHYS-05 — Provide emergency power, lighting, and resilient utilities","type":"unified"},{"id":"uc:UC-PHYS-06","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-PHYS-06 — Protect power and communications cabling from damage and taps","type":"unified"},{"id":"uc:UC-PHYS-07","rendered":true,"sources":["nist-800-53"],"title":"UC-PHYS-07 — Shield systems from electromagnetic leakage and pulse threats","type":"unified"},{"id":"uc:UC-PHYS-08","rendered":true,"sources":["iso-27001"],"title":"UC-PHYS-08 — Maintain equipment to preserve availability and integrity","type":"unified"},{"id":"uc:UC-PHYS-09","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-PHYS-09 — Prevent information exposure at desks, screens, and outputs","type":"unified"},{"id":"uc:UC-PHYS-10","rendered":true,"sources":["nist-800-53"],"title":"UC-PHYS-10 — Control and track asset delivery, removal, and movement","type":"unified"},{"id":"uc:UC-PHYS-11","rendered":true,"sources":["nist-800-53"],"title":"UC-PHYS-11 — Secure alternate work sites","type":"unified"},{"id":"uc:UC-PHYS-12","rendered":true,"sources":["nist-800-53"],"title":"UC-PHYS-12 — Mark hardware components with handling designations","type":"unified"},{"id":"uc:UC-RISK-01","rendered":true,"sources":["eu-ai-act","iso-31000"],"title":"UC-RISK-01 — Establish and maintain a tailored risk management framework","type":"unified"},{"id":"uc:UC-RISK-02","rendered":true,"sources":["iso-27001","iso-31000","nist-csf-2"],"title":"UC-RISK-02 — Integrate risk management into enterprise processes and projects","type":"unified"},{"id":"uc:UC-RISK-03","rendered":true,"sources":["iso-31000","nist-800-53","nist-csf-2"],"title":"UC-RISK-03 — Define risk appetite, tolerance, and risk assessment criteria","type":"unified"},{"id":"uc:UC-RISK-04","rendered":true,"sources":["coso-ic","nist-800-53","soc2"],"title":"UC-RISK-04 — Define objectives and business context for risk assessment","type":"unified"},{"id":"uc:UC-RISK-05","rendered":true,"sources":["iso-31000","nist-csf-2"],"title":"UC-RISK-05 — Communicate and consult with stakeholders on risk","type":"unified"},{"id":"uc:UC-RISK-06","rendered":true,"sources":["coso-ic","nist-800-53","nydfs-500","soc2","sox"],"title":"UC-RISK-06 — Perform periodic enterprise risk assessments","type":"unified"},{"id":"uc:UC-RISK-07","rendered":true,"sources":["coso-erm","iso-31000","nist-csf-2"],"title":"UC-RISK-07 — Identify and analyze risks and opportunities to objectives","type":"unified"},{"id":"uc:UC-RISK-08","rendered":true,"sources":["coso-erm","iso-31000","nist-csf-2"],"title":"UC-RISK-08 — Evaluate and prioritize risks against risk criteria","type":"unified"},{"id":"uc:UC-RISK-09","rendered":true,"sources":["coso-erm","iso-31000","nist-800-53","nist-csf-2"],"title":"UC-RISK-09 — Select, plan, and implement risk treatments","type":"unified"},{"id":"uc:UC-RISK-10","rendered":true,"sources":["coso-erm","iso-31000"],"title":"UC-RISK-10 — Maintain a risk register and report the portfolio view","type":"unified"},{"id":"uc:UC-RISK-11","rendered":true,"sources":["coso-erm","coso-ic","iso-31000","soc2"],"title":"UC-RISK-11 — Assess changes that could significantly affect risk and control","type":"unified"},{"id":"uc:UC-RISK-12","rendered":true,"sources":["coso-ic","soc2","sox"],"title":"UC-RISK-12 — Assess and mitigate fraud risk including management override","type":"unified"},{"id":"uc:UC-RISK-13","rendered":true,"sources":["coso-erm","iso-31000","soc2"],"title":"UC-RISK-13 — Monitor and review risk management performance","type":"unified"},{"id":"uc:UC-RISK-14","rendered":true,"sources":["nist-800-53","soc2"],"title":"UC-RISK-14 — Track deficiencies to closure with remediation action plans","type":"unified"},{"id":"uc:UC-RISK-15","rendered":true,"sources":["coso-erm","iso-31000","nist-csf-2"],"title":"UC-RISK-15 — Continually improve the risk management program","type":"unified"},{"id":"uc:UC-RISK-16","rendered":true,"sources":["gdpr","nist-800-53"],"title":"UC-RISK-16 — Conduct privacy impact assessments for high-risk processing","type":"unified"},{"id":"uc:UC-RISK-17","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-RISK-17 — Operate threat intelligence and threat hunting","type":"unified"},{"id":"uc:UC-RISK-18","rendered":true,"sources":["nist-800-53"],"title":"UC-RISK-18 — Categorize systems and components by impact and criticality","type":"unified"},{"id":"uc:UC-SDLC-01","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","sox"],"title":"UC-SDLC-01 — Follow a secure development lifecycle with approval gates","type":"unified"},{"id":"uc:UC-SDLC-02","rendered":true,"sources":["cobit-2019","nist-800-53"],"title":"UC-SDLC-02 — Plan and resource development programs and projects","type":"unified"},{"id":"uc:UC-SDLC-03","rendered":true,"sources":["cobit-2019","iso-27001"],"title":"UC-SDLC-03 — Define and approve security requirements for applications","type":"unified"},{"id":"uc:UC-SDLC-04","rendered":true,"sources":["aiuc-1","cobit-2019","eu-ai-act","iso-27001","nist-800-53"],"title":"UC-SDLC-04 — Engineer systems with secure architecture and design","type":"unified"},{"id":"uc:UC-SDLC-05","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-SDLC-05 — Enforce secure coding and input validation standards","type":"unified"},{"id":"uc:UC-SDLC-06","rendered":true,"sources":["cobit-2019","nist-800-53"],"title":"UC-SDLC-06 — Maintain configuration control over systems and code","type":"unified"},{"id":"uc:UC-SDLC-07","rendered":true,"sources":["cobit-2019"],"title":"UC-SDLC-07 — Approve, test, and accept changes before production release","type":"unified"},{"id":"uc:UC-SDLC-08","rendered":true,"sources":["cobit-2019","nist-800-53"],"title":"UC-SDLC-08 — Maintain current system documentation and knowledge","type":"unified"},{"id":"uc:UC-SDLC-09","rendered":true,"sources":["cobit-2019","nist-800-53"],"title":"UC-SDLC-09 — Prepare and train users for new and changed systems","type":"unified"},{"id":"uc:UC-SDLC-10","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-SDLC-10 — Oversee outsourced development and vet developers","type":"unified"},{"id":"uc:UC-SDLC-11","rendered":true,"sources":["nist-800-53"],"title":"UC-SDLC-11 — Apply specialized development to critical components","type":"unified"},{"id":"uc:UC-SDLC-12","rendered":true,"sources":["cobit-2019","nist-800-53"],"title":"UC-SDLC-12 — Manage solution assets and retire unsupported components","type":"unified"},{"id":"uc:UC-SDLC-13","rendered":true,"sources":["cobit-2019"],"title":"UC-SDLC-13 — Plan solution availability and capacity","type":"unified"},{"id":"uc:UC-SDLC-14","rendered":true,"sources":["iso-27001"],"title":"UC-SDLC-14 — Protect production systems during audit testing","type":"unified"},{"id":"uc:UC-TPRM-01","rendered":true,"sources":["cobit-2019","dora","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500"],"title":"UC-TPRM-01 — Operate a third-party security risk management program","type":"unified"},{"id":"uc:UC-TPRM-02","rendered":true,"sources":["nist-800-53","nist-csf-2","soc2"],"title":"UC-TPRM-02 — Perform risk-based due diligence before engaging vendors","type":"unified"},{"id":"uc:UC-TPRM-03","rendered":true,"sources":["ccpa","gdpr","hipaa","nist-800-53","nist-csf-2"],"title":"UC-TPRM-03 — Bind vendors to security and privacy terms by contract","type":"unified"},{"id":"uc:UC-TPRM-04","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2"],"title":"UC-TPRM-04 — Monitor vendor performance, services, and risk","type":"unified"},{"id":"uc:UC-TPRM-05","rendered":true,"sources":["nist-800-53","nist-csf-2"],"title":"UC-TPRM-05 — Include suppliers in incident notification and response","type":"unified"},{"id":"uc:UC-TPRM-06","rendered":true,"sources":["nist-800-53","nist-csf-2"],"title":"UC-TPRM-06 — Manage secure termination and disposal at relationship end","type":"unified"},{"id":"uc:UC-TPRM-07","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-TPRM-07 — Verify component authenticity, provenance, and integrity","type":"unified"},{"id":"uc:UC-TPRM-08","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-TPRM-08 — Govern security of external and cloud service use","type":"unified"},{"id":"uc:UC-TPRM-09","rendered":true,"sources":["nist-800-53"],"title":"UC-TPRM-09 — Protect supply chain information through OPSEC","type":"unified"},{"id":"uc:UC-TRAIN-01","rendered":true,"sources":["iso-27001","nist-800-53","nist-csf-2","nydfs-500"],"title":"UC-TRAIN-01 — Deliver security awareness training to all personnel","type":"unified"},{"id":"uc:UC-TRAIN-02","rendered":true,"sources":["nist-800-53","nist-csf-2"],"title":"UC-TRAIN-02 — Train personnel with specialized security roles and duties","type":"unified"},{"id":"uc:UC-TRAIN-03","rendered":true,"sources":["nist-800-53"],"title":"UC-TRAIN-03 — Record training completion and measure effectiveness","type":"unified"},{"id":"uc:UC-TRAIN-04","rendered":true,"sources":["sox"],"title":"UC-TRAIN-04 — Communicate control responsibilities and reporting channels","type":"unified"},{"id":"uc:UC-VULN-01","rendered":true,"sources":["nist-800-53","nist-csf-2","nydfs-500"],"title":"UC-VULN-01 — Scan for vulnerabilities and track advisories on a defined cadence","type":"unified"},{"id":"uc:UC-VULN-02","rendered":true,"sources":["nist-800-53","nist-ai-tevv-athlon","pci-dss"],"title":"UC-VULN-02 — Test security through independent penetration exercises","type":"unified"},{"id":"uc:UC-VULN-03","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-VULN-03 — Remediate identified flaws within defined timeframes","type":"unified"},{"id":"uc:UC-VULN-04","rendered":true,"sources":["iso-27001","nist-800-53"],"title":"UC-VULN-04 — Test software security during development and acceptance","type":"unified"},{"id":"uc:UC-VULN-05","rendered":true,"sources":["iso-27001","nist-800-53","pci-dss"],"title":"UC-VULN-05 — Block malware, spam, and phishing across all systems","type":"unified"},{"id":"uc:UC-VULN-06","rendered":true,"sources":["nist-800-53","nist-csf-2"],"title":"UC-VULN-06 — Verify software, firmware, and information integrity","type":"unified"},{"id":"uc:UC-VULN-07","rendered":true,"sources":["nist-800-53"],"title":"UC-VULN-07 — Harden runtime error handling, output filtering, and memory","type":"unified"},{"id":"uc:UC-VULN-08","rendered":true,"sources":["nist-800-53"],"title":"UC-VULN-08 — Engineer systems to fail predictably and safely","type":"unified"},{"id":"uc:UC-VULN-09","rendered":true,"sources":["nist-800-53"],"title":"UC-VULN-09 — Employ non-persistence and information-resilience techniques","type":"unified"},{"id":"uc:UC-VULN-11","rendered":true,"sources":["nist-800-53"],"title":"UC-VULN-11 — Embed taint mechanisms to detect data exfiltration","type":"unified"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-cybersecurity-assurance-review","capabilities":[],"department":"internal-audit","id":"wf:A1","mappingStatus":"mapped","releaseId":"sha256:b1b1849f755b1bd298e35c5fe4919ba4e021cf217f67943330cb40b47b726828","rendered":true,"slug":"audit-cybersecurity-assurance-review","sourceTemplateId":"workflow-library:audit-cybersecurity-assurance-review","sources":["ccpa","cobit-2019","hipaa","iia-2024","iia-pos-2026-three-lines","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc2"],"teams":["internal-audit","it"],"title":"Cybersecurity Assurance Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-internal-audit-ethics-objectivity-competency-program","capabilities":[],"department":"internal-audit","id":"wf:A10","mappingStatus":"mapped","releaseId":"sha256:12fca28d6d3a7fe7190b7ac924cfb3b588fd0ceaa1afc3769dc1f7303c2c1f8f","rendered":true,"slug":"audit-internal-audit-ethics-objectivity-competency-program","sourceTemplateId":"workflow-library:audit-internal-audit-ethics-objectivity-competency-program","sources":["iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"teams":["internal-audit"],"title":"Internal Audit Ethics, Objectivity & Competency Program","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-fraud-investigation","capabilities":[],"department":"internal-audit","id":"wf:A11","mappingStatus":"mapped","releaseId":"sha256:b5fe4ec3e78e34833795d4e184e8ffaddf20825dd6fd5fa09a4a661495cc0862","rendered":true,"slug":"audit-fraud-investigation","sourceTemplateId":"workflow-library:audit-fraud-investigation","sources":["coso-ic","iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-27001","nist-800-53","nist-csf-2"],"teams":["internal-audit","compliance-legal"],"title":"Fraud & Forensic Investigation Engagement","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-fieldwork-findings-reporting","capabilities":["audit-fieldwork-reporting"],"department":"internal-audit","id":"wf:A12","mappingStatus":"mapped","releaseId":"sha256:e8226351d0c903d5f102783016cee953a2a400641a2afd9c5108d074b6ace220","rendered":true,"slug":"audit-fieldwork-findings-reporting","sourceTemplateId":"workflow-library:audit-fieldwork-findings-reporting","sources":["iia-2024"],"teams":["internal-audit"],"title":"Audit Fieldwork, Findings & Reporting","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-iso27001-certification-readiness","capabilities":["iso27001-certification-readiness"],"department":"internal-audit","id":"wf:A13","mappingStatus":"mapped","releaseId":"sha256:a8f5c42a865b29fd211a9798d94cde470f226c702287bd2a970df0597fb6a334","rendered":true,"slug":"audit-iso27001-certification-readiness","sourceTemplateId":"workflow-library:audit-iso27001-certification-readiness","sources":["iia-2024"],"teams":["internal-audit"],"title":"ISO 27001 Certification Readiness","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-process-narrative-walkthrough","capabilities":["process-narrative-walkthrough"],"department":"internal-audit","id":"wf:A14","mappingStatus":"mapped","releaseId":"sha256:dd7c7cd48647b1aa9ec8eab1dc90ae1f0e9d77bbd6621271642583eb984d926b","rendered":true,"slug":"audit-process-narrative-walkthrough","sourceTemplateId":"workflow-library:audit-process-narrative-walkthrough","sources":["iia-2024"],"teams":["internal-audit"],"title":"Process Narrative & Walkthrough","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-soc2-readiness-disposition","capabilities":["soc2-readiness"],"department":"internal-audit","id":"wf:A15","mappingStatus":"mapped","releaseId":"sha256:14f2f6568cafdb682d7dafdf0ff401fe56649c1307c627ad67aa0c432bf095ed","rendered":true,"slug":"audit-soc2-readiness-disposition","sourceTemplateId":"workflow-library:audit-soc2-readiness-disposition","sources":["aiuc-1","cobit-2019","coso-erm","coso-ic","gdpr","hipaa","iia-2024","iso-27001","iso-31000","nis2","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"teams":["internal-audit"],"title":"SOC 2 Trust Services Readiness","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=continuous-monitoring-agent-evaluation","capabilities":["audit-quality-assurance"],"department":"internal-audit","id":"wf:A16","mappingStatus":"mapped","releaseId":"sha256:aa97fa663a87d2d432e798ca69889efe76c8e286707cc566a6cca8235a2a6715","rendered":true,"slug":"continuous-monitoring-agent-evaluation","sourceTemplateId":"workflow-library:continuous-monitoring-agent-evaluation","sources":["iia-2024"],"teams":["internal-audit"],"title":"Continuous Monitoring & Agent Evaluation","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=fraud-risk-je-testing","capabilities":["audit-testing"],"department":"internal-audit","id":"wf:A17","mappingStatus":"mapped","releaseId":"sha256:79c63b355999a79e044c279a7bd312e4a60f76cfc83b7c13d70a490b0b253a56","rendered":true,"slug":"fraud-risk-je-testing","sourceTemplateId":"workflow-library:fraud-risk-je-testing","sources":["iia-2024"],"teams":["internal-audit"],"title":"Fraud Risk Assessment & JE Testing","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=itgc-change-provisioning-testing","capabilities":["audit-testing"],"department":"internal-audit","id":"wf:A18","mappingStatus":"mapped","releaseId":"sha256:568bf412eaf4229147a7556e111d5bda5641422d9748cdb97eb66cf112123da4","rendered":true,"slug":"itgc-change-provisioning-testing","sourceTemplateId":"workflow-library:itgc-change-provisioning-testing","sources":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2","sox"],"teams":["internal-audit"],"title":"ITGC Change & Provisioning Testing","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=substantive-testing-data-analytics","capabilities":["audit-testing"],"department":"internal-audit","id":"wf:A19","mappingStatus":"mapped","releaseId":"sha256:f305df7947a3a4ed799b3666887edd77425586ee8543d0b2be515df6e862b700","rendered":true,"slug":"substantive-testing-data-analytics","sourceTemplateId":"workflow-library:substantive-testing-data-analytics","sources":["iia-2024"],"teams":["internal-audit"],"title":"Substantive Testing & Data Analytics","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-engagement-lifecycle","capabilities":[],"department":"internal-audit","id":"wf:A2","mappingStatus":"mapped","releaseId":"sha256:060ee0bf2ae9cb1b2cc942c83283a92b1205066b5af558c8b6652048467de14e","rendered":true,"slug":"audit-engagement-lifecycle","sourceTemplateId":"workflow-library:audit-engagement-lifecycle","sources":["iia-2024","nist-csf-2"],"teams":["internal-audit"],"title":"Internal Audit Engagement Lifecycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-engagement-planning","capabilities":[],"department":"internal-audit","id":"wf:A3","mappingStatus":"mapped","releaseId":"sha256:b6b8606898fa799c22cc7aaa3d1d036828b9ec97873cdb397ca4ce75e4f0089a","rendered":true,"slug":"audit-engagement-planning","sourceTemplateId":"workflow-library:audit-engagement-planning","sources":["iia-2024"],"teams":["internal-audit"],"title":"Audit Engagement Planning","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-finding-remediation-monitoring","capabilities":[],"department":"internal-audit","id":"wf:A4","mappingStatus":"mapped","releaseId":"sha256:3f25c4f56f6bd3454122d83cee380036bbb55544d974354073ba34475463976d","rendered":true,"slug":"audit-finding-remediation-monitoring","sourceTemplateId":"workflow-library:audit-finding-remediation-monitoring","sources":["coso-ic","iia-2024","nist-800-53","nist-csf-2","soc2"],"teams":["internal-audit"],"title":"Finding Remediation & Action-Plan Monitoring","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-qaip-cycle","capabilities":[],"department":"internal-audit","id":"wf:A5","mappingStatus":"mapped","releaseId":"sha256:a154310aaad6e60914859edbbf54493e6a822745667977c77e5400e90fa4a26a","rendered":true,"slug":"audit-qaip-cycle","sourceTemplateId":"workflow-library:audit-qaip-cycle","sources":["iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"teams":["internal-audit"],"title":"Quality Assurance & Improvement Program Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-report-drafting","capabilities":[],"department":"internal-audit","id":"wf:A6","mappingStatus":"mapped","releaseId":"sha256:3cbf5a0ef0478f6bd8be09a582416a5e7eb002647bd276ff4f2fbe762d8e397f","rendered":true,"slug":"audit-report-drafting","sourceTemplateId":"workflow-library:audit-report-drafting","sources":["iia-2024"],"teams":["internal-audit"],"title":"Audit Report Drafting","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-third-party-assurance-engagement","capabilities":[],"department":"internal-audit","id":"wf:A7","mappingStatus":"mapped","releaseId":"sha256:559830dd60ca4ef7406b72e8d19e4c47cc75cede6d875886681f1bf77abddf64","rendered":true,"slug":"audit-third-party-assurance-engagement","sourceTemplateId":"workflow-library:audit-third-party-assurance-engagement","sources":["cobit-2019","dora","iia-2024","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2"],"teams":["internal-audit","procurement"],"title":"Third-Party Vendor Assurance Engagement","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-internal-audit-charter-independence-board-governance","capabilities":[],"department":"internal-audit","id":"wf:A8","mappingStatus":"mapped","releaseId":"sha256:d0ac12a0fd4a357279d21a76e1ed578eebdbb7f2fbf7bdc0dc9bdb8487e44c53","rendered":true,"slug":"audit-internal-audit-charter-independence-board-governance","sourceTemplateId":"workflow-library:audit-internal-audit-charter-independence-board-governance","sources":["coso-ic","iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"teams":["internal-audit","executive"],"title":"Internal Audit Charter, Independence & Board Governance Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-annual-internal-audit-planning-resource-management","capabilities":[],"department":"internal-audit","id":"wf:A9","mappingStatus":"mapped","releaseId":"sha256:2e25e6b33c874dbffd18cd204117039793dba7390af3d1956eb91cbbd82141f7","rendered":true,"slug":"audit-annual-internal-audit-planning-resource-management","sourceTemplateId":"workflow-library:audit-annual-internal-audit-planning-resource-management","sources":["iia-2024","iia-pos-2026-erm"],"teams":["internal-audit"],"title":"Annual Internal Audit Planning & Resource Management","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=finance-monthly-close","capabilities":["monthly-close","account-reconciliation","journal-approval","period-close"],"department":"finance","id":"wf:B1","mappingStatus":"not-applicable","releaseId":"sha256:1655c7627589506aa64bef85c8cb138a11a3eafa551f5e00415924b6b117b4ae","rendered":true,"slug":"finance-monthly-close","sourceTemplateId":"workflow-library:finance-monthly-close","sources":[],"teams":["finance"],"title":"Monthly Financial Close","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=hr-recruiting","capabilities":["recruiting","hiring-decision"],"department":"hr","id":"wf:B2","mappingStatus":"not-applicable","releaseId":"sha256:d23870fb0f4655038442bf0576170617288c9d3daefe5ebf646a4a13d9985823","rendered":true,"slug":"hr-recruiting","sourceTemplateId":"workflow-library:hr-recruiting","sources":[],"teams":["hr"],"title":"Recruiting and Hiring Decision","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-continuous-controls-monitoring-iscm","capabilities":[],"department":"it","id":"wf:C1","mappingStatus":"mapped","releaseId":"sha256:c1eba4819d732a63c86422514455ba1cffacc57cfca35373d63457d0e5694c14","rendered":true,"slug":"controls-continuous-controls-monitoring-iscm","sourceTemplateId":"workflow-library:controls-continuous-controls-monitoring-iscm","sources":["cobit-2019","coso-erm","coso-ic","iso-27001","iso-31000","nist-800-53","nist-csf-2","soc2","sox"],"teams":["it","risk-management"],"title":"Continuous Controls Monitoring (ISCM) Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-technical-security-testing-pentest","capabilities":[],"department":"it","id":"wf:C10","mappingStatus":"mapped","releaseId":"sha256:c28fb0e08623dc507cf60fcdf8730d6f0b13de3d95018f9692f7c72965a24317","rendered":true,"slug":"controls-technical-security-testing-pentest","sourceTemplateId":"workflow-library:controls-technical-security-testing-pentest","sources":["aiuc-1","cobit-2019","eu-ai-act","gdpr","iso-27001","nist-800-53","nist-ai-tevv-athlon","nist-csf-2","pci-dss","soc2"],"teams":["it"],"title":"Technical Security Testing & Pentest Engagement","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-vendor-soc-cuec-review","capabilities":[],"department":"procurement","id":"wf:C11","mappingStatus":"mapped","releaseId":"sha256:31af594ee8aeb5af01927dcc0e95bf6ea9f05a8d45fd1524d012709768b688e0","rendered":true,"slug":"controls-vendor-soc-cuec-review","sourceTemplateId":"workflow-library:controls-vendor-soc-cuec-review","sources":["iso-27001","nist-800-53","nist-csf-2","soc1"],"teams":["procurement","it"],"title":"Vendor SOC 1/SOC 2 Report Review & CUEC Mapping","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-user-access-review","capabilities":[],"department":"it","id":"wf:C12","mappingStatus":"mapped","releaseId":"sha256:a7af16f97073e073ad464ca1ec5c0736dae8db8ef2ccdbccf8da2c2700053e2d","rendered":true,"slug":"controls-user-access-review","sourceTemplateId":"workflow-library:controls-user-access-review","sources":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc2"],"teams":["it","finance"],"title":"User Access Review & Recertification","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-vulnerability-patch-management","capabilities":[],"department":"it","id":"wf:C13","mappingStatus":"mapped","releaseId":"sha256:9774074d4b29f254001fafd22efa7e724864084b0d28613d5fb5bbb8791a8dc4","rendered":true,"slug":"controls-vulnerability-patch-management","sourceTemplateId":"workflow-library:controls-vulnerability-patch-management","sources":["iso-27001","nist-800-53","nist-csf-2","nydfs-500"],"teams":["it"],"title":"Vulnerability & Patch Management Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-bcdr-test-exercise","capabilities":[],"department":"operations","id":"wf:C14","mappingStatus":"mapped","releaseId":"sha256:a8327d73b34cf64076fa4977e8aedb36e95121d78b859e40ddbc05bbbf6079a0","rendered":true,"slug":"controls-bcdr-test-exercise","sourceTemplateId":"workflow-library:controls-bcdr-test-exercise","sources":["cobit-2019","dora","iso-27001","nist-800-53","nist-csf-2","nydfs-500","soc2"],"teams":["operations","it"],"title":"Business Continuity & DR Test Exercise","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-security-awareness-training","capabilities":[],"department":"it","id":"wf:C15","mappingStatus":"mapped","releaseId":"sha256:5676177ad081fc5c8472ca1056e07b505068d5a347b8365199c5a60b5bd0944a","rendered":true,"slug":"controls-security-awareness-training","sourceTemplateId":"workflow-library:controls-security-awareness-training","sources":["iso-27001","nist-800-53","nist-csf-2","nydfs-500"],"teams":["it","hr"],"title":"Security Awareness Training Campaign","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-isms-internal-audit-management-review","capabilities":[],"department":"internal-audit","id":"wf:C16","mappingStatus":"mapped","releaseId":"sha256:742d77471fcfb9e129cd8c2c7bf4a77d76efc0dc9e0982900aaa8c182a577076","rendered":true,"slug":"controls-isms-internal-audit-management-review","sourceTemplateId":"workflow-library:controls-isms-internal-audit-management-review","sources":["ccpa","cobit-2019","iia-2024","iia-pos-2026-three-lines","iso-27001","nist-800-53","nist-csf-2","nydfs-500"],"teams":["internal-audit","it","executive"],"title":"ISMS Internal Audit & Management Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-soc2-readiness-evidence-cycle","capabilities":[],"department":"it","id":"wf:C17","mappingStatus":"mapped","releaseId":"sha256:a75a8829641f824e14de4a3ac834eb857327b7536a5954b8f5b887df61305df4","rendered":true,"slug":"controls-soc2-readiness-evidence-cycle","sourceTemplateId":"workflow-library:controls-soc2-readiness-evidence-cycle","sources":["ccpa","cobit-2019","coso-ic","iia-2024","iia-pos-2026-three-lines","iso-27001","nist-800-53","soc2","sox"],"teams":["it","compliance-legal"],"title":"SOC 2 Readiness & Evidence Collection","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-key-management-crypto-review","capabilities":[],"department":"it","id":"wf:C18","mappingStatus":"mapped","releaseId":"sha256:e11d0a422f1a884d2c193a96e85fc415f71a9fe2547b9f12a600420e0b162bdb","rendered":true,"slug":"controls-key-management-crypto-review","sourceTemplateId":"workflow-library:controls-key-management-crypto-review","sources":["iso-27001","nist-800-53"],"teams":["it"],"title":"Cryptographic Key Management Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-joiner-mover-leaver","capabilities":[],"department":"it","id":"wf:C19","mappingStatus":"mapped","releaseId":"sha256:16938047ff0802214480433fbaa4f58aa66b270ca388b9d30d02736ad190c4c1","rendered":true,"slug":"controls-joiner-mover-leaver","sourceTemplateId":"workflow-library:controls-joiner-mover-leaver","sources":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2","sox"],"teams":["it","hr"],"title":"Joiner-Mover-Leaver Access Lifecycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-csf-profile-maturity-assessment","capabilities":[],"department":"it","id":"wf:C2","mappingStatus":"mapped","releaseId":"sha256:27c45a606d72b2ab411434c5a4c54d39fbe813777b3075321f79ec72cf5de5a8","rendered":true,"slug":"controls-csf-profile-maturity-assessment","sourceTemplateId":"workflow-library:controls-csf-profile-maturity-assessment","sources":["cobit-2019","coso-erm","coso-ic","dora","iso-27001","iso-31000","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2","sox"],"teams":["it","executive"],"title":"CSF 2.0 Profile & Maturity Assessment","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-threat-intelligence-program","capabilities":[],"department":"it","id":"wf:C20","mappingStatus":"mapped","releaseId":"sha256:9e50ff9e802446081a3b33b6195cb72fc672500d02b83389a22727d7e12d9ece","rendered":true,"slug":"controls-threat-intelligence-program","sourceTemplateId":"workflow-library:controls-threat-intelligence-program","sources":["dora","iso-27001","nist-800-53"],"teams":["it"],"title":"Threat Intelligence & Insider Threat Program","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-data-retention-disposal","capabilities":[],"department":"it","id":"wf:C21","mappingStatus":"mapped","releaseId":"sha256:f6701b905bc9cb9478c91fc668ae944d10bfa6a8ab6b18eb919a0be2ef47fa5e","rendered":true,"slug":"controls-data-retention-disposal","sourceTemplateId":"workflow-library:controls-data-retention-disposal","sources":["iso-27001","nist-800-53","soc2"],"teams":["it","privacy"],"title":"Data Retention & Secure Disposal","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-incident-reporting-spillage-response","capabilities":[],"department":"it","id":"wf:C23","mappingStatus":"mapped","releaseId":"sha256:801f657afd613afa2d6a34b2a9198219da7d8f5923ef91d765537765855606a8","rendered":true,"slug":"controls-incident-reporting-spillage-response","sourceTemplateId":"workflow-library:controls-incident-reporting-spillage-response","sources":["iso-27001","nist-800-53"],"teams":["it","compliance-legal"],"title":"Incident Reporting Channels & Spillage Response","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-categorization-planning-authorization","capabilities":[],"department":"it","id":"wf:C24","mappingStatus":"mapped","releaseId":"sha256:8a94d321110b8bcc3298d0e3c8954403fa30e2ef9c4f66f96c2d4a62effbe3ec","rendered":true,"slug":"controls-system-categorization-planning-authorization","sourceTemplateId":"workflow-library:controls-system-categorization-planning-authorization","sources":["nist-800-53"],"teams":["it","compliance-legal"],"title":"System Categorization, Security Planning & Authorization","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-information-security-program-governance-review","capabilities":[],"department":"it","id":"wf:C25","mappingStatus":"mapped","releaseId":"sha256:7bfa6143ae99e0af99e205c327c02861bf5a3a398c178c92b28e94cdf2ce5f82","rendered":true,"slug":"controls-information-security-program-governance-review","sourceTemplateId":"workflow-library:controls-information-security-program-governance-review","sources":["cobit-2019","coso-erm","coso-ic","iso-27001","nist-800-53","nist-csf-2","nydfs-500","soc2"],"teams":["it","executive"],"title":"Information Security Program Governance Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-security-policy-suite-review-protection-domains","capabilities":[],"department":"it","id":"wf:C26","mappingStatus":"mapped","releaseId":"sha256:035bb7044a1c5349f8206936ed2e8f6fedb3a7c54c1dafc75a1679e666df9f4c","rendered":true,"slug":"controls-security-policy-suite-review-protection-domains","sourceTemplateId":"workflow-library:controls-security-policy-suite-review-protection-domains","sources":["nis2","nist-800-53","nydfs-500","soc2"],"teams":["it","compliance-legal"],"title":"Security Policy Suite Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-security-privacy-architecture-review-board","capabilities":[],"department":"it","id":"wf:C28","mappingStatus":"mapped","releaseId":"sha256:f4fe8ecd7ca5d670f071656992621a3ae28d900aec23d4843962eac9e65866ac","rendered":true,"slug":"controls-security-privacy-architecture-review-board","sourceTemplateId":"workflow-library:controls-security-privacy-architecture-review-board","sources":["cobit-2019","nist-800-53"],"teams":["it","privacy"],"title":"Security & Privacy Architecture Review Board","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-privileged-access-authorization-model-management","capabilities":[],"department":"it","id":"wf:C29","mappingStatus":"mapped","releaseId":"sha256:929cca1040eecb0875f57a15e62e68431ed65478947bd97305d9eb7d9d79544f","rendered":true,"slug":"controls-privileged-access-authorization-model-management","sourceTemplateId":"workflow-library:controls-privileged-access-authorization-model-management","sources":["aiuc-1","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2"],"teams":["it"],"title":"Privileged Access & Authorization Model Management","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-cybersecurity-incident-response","capabilities":[],"department":"it","id":"wf:C3","mappingStatus":"mapped","releaseId":"sha256:24f03436d3713f92be067a14847e35f7b71d0b34c3bab5fe0e06bcc04156c45f","rendered":true,"slug":"controls-cybersecurity-incident-response","sourceTemplateId":"workflow-library:controls-cybersecurity-incident-response","sources":["cobit-2019","coso-ic","dora","gdpr","iso-27001","nist-800-53","nist-csf-2","soc2"],"teams":["it"],"title":"Cybersecurity Incident Response","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-identity-authenticator-lifecycle-administration","capabilities":[],"department":"it","id":"wf:C30","mappingStatus":"mapped","releaseId":"sha256:f80ac3091ec1ebb2c841e32384473adbffab3d5b1bc43189934663886e04428b","rendered":true,"slug":"controls-identity-authenticator-lifecycle-administration","sourceTemplateId":"workflow-library:controls-identity-authenticator-lifecycle-administration","sources":["iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2"],"teams":["it"],"title":"Identity & Authenticator Lifecycle Administration","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-authentication-platform-session-policy-operations","capabilities":[],"department":"it","id":"wf:C31","mappingStatus":"mapped","releaseId":"sha256:a423b169a8e3d6d6864e185744540fef3107b5e5c468eb937fccef9fff160210","rendered":true,"slug":"controls-authentication-platform-session-policy-operations","sourceTemplateId":"workflow-library:controls-authentication-platform-session-policy-operations","sources":["hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss"],"teams":["it"],"title":"Authentication Platform & Session Policy Operations","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-public-content-external-sharing-authorization","capabilities":[],"department":"it","id":"wf:C32","mappingStatus":"mapped","releaseId":"sha256:920c97d575af92eedda7f4b4e83b78d86377f2c1f6eba6645f8542651b6ba7c0","rendered":true,"slug":"controls-public-content-external-sharing-authorization","sourceTemplateId":"workflow-library:controls-public-content-external-sharing-authorization","sources":["aiuc-1","nist-800-53"],"teams":["it","compliance-legal"],"title":"Public Content & External Sharing Authorization","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-data-encryption-in-use-protection-operations","capabilities":[],"department":"it","id":"wf:C33","mappingStatus":"mapped","releaseId":"sha256:2803b29ce9c1d03798d270f0824b32255b3f51d13b0c68c093d012b9ee7c90ae","rendered":true,"slug":"controls-data-encryption-in-use-protection-operations","sourceTemplateId":"workflow-library:controls-data-encryption-in-use-protection-operations","sources":["aiuc-1","hipaa","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"teams":["it"],"title":"Data Encryption & In-Use Protection Operations","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-workplace-remote-work-security-cycle","capabilities":[],"department":"it","id":"wf:C34","mappingStatus":"mapped","releaseId":"sha256:9aef76dcd829f33f6e986e62c6a33afd2447bd2084e460e520eb5386cd30eae6","rendered":true,"slug":"controls-workplace-remote-work-security-cycle","sourceTemplateId":"workflow-library:controls-workplace-remote-work-security-cycle","sources":["iso-27001","nist-800-53"],"teams":["it","hr","facilities"],"title":"Workplace & Remote Work Security Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-facility-access-administration-monitoring","capabilities":[],"department":"facilities","id":"wf:C35","mappingStatus":"mapped","releaseId":"sha256:6a3c818bee6b517fa47e0ccd1ea9f1bd11cd4954c08acda6202b41e564c7ff5e","rendered":true,"slug":"controls-facility-access-administration-monitoring","sourceTemplateId":"workflow-library:controls-facility-access-administration-monitoring","sources":["hipaa","iso-27001","nist-800-53","nist-csf-2","soc1","soc2"],"teams":["facilities","it"],"title":"Facility Access Administration & Monitoring","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-environmental-utility-systems-maintenance","capabilities":[],"department":"facilities","id":"wf:C36","mappingStatus":"mapped","releaseId":"sha256:21904d7b642920d0441d7813b4bf123b80990fcbd1dcd9f0f17bdc6b0d556fa6","rendered":true,"slug":"controls-environmental-utility-systems-maintenance","sourceTemplateId":"workflow-library:controls-environmental-utility-systems-maintenance","sources":["iso-27001","nist-800-53","nist-csf-2"],"teams":["facilities","it"],"title":"Environmental & Utility Systems Maintenance","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-equipment-maintenance-movement-marking-control","capabilities":[],"department":"facilities","id":"wf:C37","mappingStatus":"mapped","releaseId":"sha256:2362fbaa4e911d96dfff4c6484601e29fb0f960818ff589bde290703aa0a85d3","rendered":true,"slug":"controls-equipment-maintenance-movement-marking-control","sourceTemplateId":"workflow-library:controls-equipment-maintenance-movement-marking-control","sources":["iso-27001","nist-800-53"],"teams":["facilities","it"],"title":"Equipment Maintenance, Movement & Marking Control","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-it-asset-inventory-classification-upkeep","capabilities":[],"department":"it","id":"wf:C38","mappingStatus":"mapped","releaseId":"sha256:2cd86cbfcb83530b6da3ecc02e70ac2401a88e640f6f935ee49a6a938e2b709d","rendered":true,"slug":"controls-it-asset-inventory-classification-upkeep","sourceTemplateId":"workflow-library:controls-it-asset-inventory-classification-upkeep","sources":["aiuc-1","coso-ic","gdpr","iso-27001","nist-800-53","nist-csf-2","soc2"],"teams":["it"],"title":"IT Asset Inventory & Classification Upkeep","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-endpoint-media-information-handling-custody","capabilities":[],"department":"it","id":"wf:C39","mappingStatus":"mapped","releaseId":"sha256:6760c558247bda73e71ef40ac389982bfefd5310b84ef599ffff4896bbdac37f","rendered":true,"slug":"controls-endpoint-media-information-handling-custody","sourceTemplateId":"workflow-library:controls-endpoint-media-information-handling-custody","sources":["iso-27001","nist-800-53","pci-dss","soc2"],"teams":["it"],"title":"Endpoint, Media & Information Handling Custody","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-design","capabilities":[],"department":"operations","id":"wf:C4","mappingStatus":"mapped","releaseId":"sha256:362c8362a87fd9c6ed9bbc66ac1f6bf55e7701d605a4f7fce99f08d6b1c1206f","rendered":true,"slug":"controls-design","sourceTemplateId":"workflow-library:controls-design","sources":["coso-ic"],"teams":["operations","risk-management"],"title":"Control Design","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-it-availability-resilient-failure-operations","capabilities":[],"department":"it","id":"wf:C40","mappingStatus":"mapped","releaseId":"sha256:4c158ff94db3daeacbef5d536ca11ed76c08fa3eb7514bebaf1b0847e4d071bc","rendered":true,"slug":"controls-it-availability-resilient-failure-operations","sourceTemplateId":"workflow-library:controls-it-availability-resilient-failure-operations","sources":["nist-800-53","sox"],"teams":["it"],"title":"IT Availability & Resilient Failure Operations","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-change-release-management-operation","capabilities":[],"department":"it","id":"wf:C41","mappingStatus":"mapped","releaseId":"sha256:bff91696eb5798d65dae1ed4785cae7e0def347c88e46ca51aa4faed126fbe9b","rendered":true,"slug":"controls-change-release-management-operation","sourceTemplateId":"workflow-library:controls-change-release-management-operation","sources":["cobit-2019","iso-27001","nist-800-53","soc1","soc2","sox"],"teams":["it","finance"],"title":"Change & Release Management (CAB)","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-secure-baseline-integrity-drift-management","capabilities":[],"department":"it","id":"wf:C42","mappingStatus":"mapped","releaseId":"sha256:0af32625b7fb0bd5d59150bc4d02bc9e6a537d1997191911212275676a044f27","rendered":true,"slug":"controls-secure-baseline-integrity-drift-management","sourceTemplateId":"workflow-library:controls-secure-baseline-integrity-drift-management","sources":["coso-ic","iso-27001","nist-800-53","nist-csf-2","pci-dss","soc2"],"teams":["it"],"title":"Secure Baseline & Integrity Drift Management","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-authorized-software-component-integrity-control","capabilities":[],"department":"it","id":"wf:C43","mappingStatus":"mapped","releaseId":"sha256:b53f505729c73529b0c617f56c09fe8bc6d9c256b403c66b164c684e8fed5372","rendered":true,"slug":"controls-authorized-software-component-integrity-control","sourceTemplateId":"workflow-library:controls-authorized-software-component-integrity-control","sources":["iso-27001","nist-800-53","nist-csf-2","soc2"],"teams":["it"],"title":"Authorized Software & Component Integrity Control","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-malware-email-web-content-defense-operations","capabilities":[],"department":"it","id":"wf:C44","mappingStatus":"mapped","releaseId":"sha256:3d55f54b2fcd9c02bbcb99373843a2c850f589f699300583fd65d4ccef633e0e","rendered":true,"slug":"controls-malware-email-web-content-defense-operations","sourceTemplateId":"workflow-library:controls-malware-email-web-content-defense-operations","sources":["iso-27001","nist-800-53","pci-dss"],"teams":["it"],"title":"Malware, Email & Web Content Defense Operations","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-deception-honeytoken-opsec-concealment-operations","capabilities":[],"department":"it","id":"wf:C45","mappingStatus":"mapped","releaseId":"sha256:6f0b367a6b42ff061615e403c2c5ce39ef09a5ec054aa932d43c8b74d4d220e6","rendered":true,"slug":"controls-deception-honeytoken-opsec-concealment-operations","sourceTemplateId":"workflow-library:controls-deception-honeytoken-opsec-concealment-operations","sources":["nist-800-53"],"teams":["it"],"title":"Deception, Honeytoken & OPSEC Concealment Operations","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-secure-development-release-security-gate","capabilities":[],"department":"it","id":"wf:C46","mappingStatus":"mapped","releaseId":"sha256:97dde0cbe2525c8b4665900d4ab33c1d99daacd4ad3a2b8cf27e14ff86954a66","rendered":true,"slug":"controls-secure-development-release-security-gate","sourceTemplateId":"workflow-library:controls-secure-development-release-security-gate","sources":["gdpr","iso-27001","nist-800-53","nist-csf-2","pci-dss"],"teams":["it"],"title":"Secure Development & Release Security Gate","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-controlled-hardware-system-maintenance","capabilities":[],"department":"it","id":"wf:C47","mappingStatus":"mapped","releaseId":"sha256:4ab7949ada41be689fc596040ac532f7fecc93bb91772f5a347654ffd5afcf03","rendered":true,"slug":"controls-controlled-hardware-system-maintenance","sourceTemplateId":"workflow-library:controls-controlled-hardware-system-maintenance","sources":["nist-800-53","nist-csf-2"],"teams":["it","facilities"],"title":"Controlled Hardware & System Maintenance","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-network-segmentation-boundary-rule-management","capabilities":[],"department":"it","id":"wf:C48","mappingStatus":"mapped","releaseId":"sha256:b3e7dfe095f4f6ac9eb3dee98f171c19585678c068d46b38bb7e5a009a0c80d3","rendered":true,"slug":"controls-network-segmentation-boundary-rule-management","sourceTemplateId":"workflow-library:controls-network-segmentation-boundary-rule-management","sources":["aiuc-1","gdpr","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","soc2"],"teams":["it"],"title":"Network Segmentation & Boundary Rule Management","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-secure-connectivity-network-trust-services","capabilities":[],"department":"it","id":"wf:C49","mappingStatus":"mapped","releaseId":"sha256:2f2c8b341180d218856634cd273ef87ef09f1ea90339826604d82d8fe83d1704","rendered":true,"slug":"controls-secure-connectivity-network-trust-services","sourceTemplateId":"workflow-library:controls-secure-connectivity-network-trust-services","sources":["nist-800-53","nist-ai-agent-identity"],"teams":["it"],"title":"Secure Connectivity & Network Trust Services Operation","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-identity-assurance-review","capabilities":[],"department":"it","id":"wf:C5","mappingStatus":"mapped","releaseId":"sha256:356c43deb1a22a13525cc411a881fc72d7a28eff0443a514ded9c6c5444bd201","rendered":true,"slug":"controls-identity-assurance-review","sourceTemplateId":"workflow-library:controls-identity-assurance-review","sources":["hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss"],"teams":["it"],"title":"Identity Assurance Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-platform-isolation-separation-enforcement","capabilities":[],"department":"it","id":"wf:C50","mappingStatus":"mapped","releaseId":"sha256:87d7ec847bc369edee212ee417702566be5995820fc364469fa7dab1fbcc5c9a","rendered":true,"slug":"controls-platform-isolation-separation-enforcement","sourceTemplateId":"workflow-library:controls-platform-isolation-separation-enforcement","sources":["nist-800-53"],"teams":["it"],"title":"Platform Isolation & Separation Enforcement","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-resilient-architecture-non-persistence-operations","capabilities":[],"department":"it","id":"wf:C51","mappingStatus":"mapped","releaseId":"sha256:31d5fcdf98f9720cc534b5692dc1003e851c430b4ab0c1e777006600f1e535e1","rendered":true,"slug":"controls-resilient-architecture-non-persistence-operations","sourceTemplateId":"workflow-library:controls-resilient-architecture-non-persistence-operations","sources":["nist-800-53"],"teams":["it"],"title":"Resilient Architecture & Non-Persistence Operations","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-audit-logging-coverage-integrity-operations","capabilities":[],"department":"it","id":"wf:C52","mappingStatus":"mapped","releaseId":"sha256:4b7fee34ffe97fe67233456545758640c8491dfcb20c1331eb266b66f96734b4","rendered":true,"slug":"controls-audit-logging-coverage-integrity-operations","sourceTemplateId":"workflow-library:controls-audit-logging-coverage-integrity-operations","sources":["hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nydfs-500","pci-dss"],"teams":["it"],"title":"Audit Logging Coverage & Integrity Operations","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-security-monitoring-detection-operations","capabilities":[],"department":"it","id":"wf:C53","mappingStatus":"mapped","releaseId":"sha256:2264ccb2a62c35b5cd25519eb830d768654f8034602856c3d593927ef0ebf28c","rendered":true,"slug":"controls-security-monitoring-detection-operations","sourceTemplateId":"workflow-library:controls-security-monitoring-detection-operations","sources":["cobit-2019","iso-27001","nist-800-53","nist-csf-2","soc2"],"teams":["it"],"title":"Security Monitoring & Detection Operations","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-user-activity-external-exposure-monitoring","capabilities":[],"department":"it","id":"wf:C54","mappingStatus":"mapped","releaseId":"sha256:507a4a5bfc78815b47c68f319b5e08063e17570820c2df86cc5c083de3191bce","rendered":true,"slug":"controls-user-activity-external-exposure-monitoring","sourceTemplateId":"workflow-library:controls-user-activity-external-exposure-monitoring","sources":["nist-800-53","nist-csf-2"],"teams":["it","hr"],"title":"User Activity & External Exposure Monitoring","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-network-provider-service-monitoring","capabilities":[],"department":"it","id":"wf:C55","mappingStatus":"mapped","releaseId":"sha256:214e4d9ded1ce0a8d5e2e038114d15720fb5a06388182a17d44245436b674619","rendered":true,"slug":"controls-network-provider-service-monitoring","sourceTemplateId":"workflow-library:controls-network-provider-service-monitoring","sources":["aiuc-1","iso-27001","nist-800-53","nist-csf-2"],"teams":["it","procurement"],"title":"Network & Provider Service Monitoring","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-physical-environment-monitoring-review","capabilities":[],"department":"facilities","id":"wf:C56","mappingStatus":"mapped","releaseId":"sha256:4b89a8b465f2b6a9ee4a463d60e2f2df35290fe8f9422bf73f3bb5d3f69e4b29","rendered":true,"slug":"controls-physical-environment-monitoring-review","sourceTemplateId":"workflow-library:controls-physical-environment-monitoring-review","sources":["nist-csf-2"],"teams":["facilities"],"title":"Physical Environment Monitoring Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-incident-response-readiness-program","capabilities":[],"department":"it","id":"wf:C57","mappingStatus":"mapped","releaseId":"sha256:61fcfac851cd742968ad73ecf3783140c0be3de3489b3de2ac17e3c00cba230d","rendered":true,"slug":"controls-incident-response-readiness-program","sourceTemplateId":"workflow-library:controls-incident-response-readiness-program","sources":["iso-27001","nist-800-53"],"teams":["it"],"title":"Incident Response Readiness Program","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-resilience-failover-readiness-verification","capabilities":[],"department":"it","id":"wf:C58","mappingStatus":"mapped","releaseId":"sha256:f38e4776db3dc7198958fcc6b8b422244265219259df3fd62ccf20545bd3db9b","rendered":true,"slug":"controls-resilience-failover-readiness-verification","sourceTemplateId":"workflow-library:controls-resilience-failover-readiness-verification","sources":["iso-27001","nist-800-53","nist-csf-2"],"teams":["it"],"title":"Resilience & Failover Readiness Verification","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-it-operations-capacity-management-cycle","capabilities":[],"department":"it","id":"wf:C59","mappingStatus":"mapped","releaseId":"sha256:6c08d1ef2edeb59f2859ef25dc798d5e8c3d049174647623a14d5ae0d013b541","rendered":true,"slug":"controls-it-operations-capacity-management-cycle","sourceTemplateId":"workflow-library:controls-it-operations-capacity-management-cycle","sources":["cobit-2019","nist-800-53","nist-csf-2","soc2"],"teams":["it"],"title":"IT Operations & Capacity Management Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-isms-risk-assessment-treatment","capabilities":[],"department":"it","id":"wf:C6","mappingStatus":"mapped","releaseId":"sha256:d28392c2f1ee0bffec0f16bf8935ffe4a883954a3dbec02d0f981ced07f5dcee","rendered":true,"slug":"controls-isms-risk-assessment-treatment","sourceTemplateId":"workflow-library:controls-isms-risk-assessment-treatment","sources":["coso-erm","coso-ic","iso-31000","nist-800-53","nist-csf-2","nydfs-500","soc2","sox"],"teams":["it","risk-management"],"title":"ISMS Risk Assessment & Treatment Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-supply-chain-integrity-opsec-operations","capabilities":[],"department":"it","id":"wf:C60","mappingStatus":"mapped","releaseId":"sha256:6accc3950adde35373ca06d8c364cbd98d3206abe88ce5a64ae5d541ac074b30","rendered":true,"slug":"controls-supply-chain-integrity-opsec-operations","sourceTemplateId":"workflow-library:controls-supply-chain-integrity-opsec-operations","sources":["iso-27001","nist-800-53"],"teams":["it","procurement"],"title":"Supply-Chain Integrity & OPSEC Operations","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-secure-sdlc-phase-gate-program","capabilities":[],"department":"it","id":"wf:C61","mappingStatus":"mapped","releaseId":"sha256:72fbb361652e21aa8489b2417f6663964be17b14d016ab666d678b92e457f419","rendered":true,"slug":"controls-secure-sdlc-phase-gate-program","sourceTemplateId":"workflow-library:controls-secure-sdlc-phase-gate-program","sources":["aiuc-1","cobit-2019","eu-ai-act","iso-27001","nist-800-53","nist-csf-2","sox"],"teams":["it"],"title":"Secure SDLC Phase-Gate Program","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-outsourced-critical-component-development-oversight","capabilities":[],"department":"procurement","id":"wf:C63","mappingStatus":"mapped","releaseId":"sha256:f420cdf1d70a9a9222512c83f000ea88e6d3b4be6315825595c9cbb43247ea6b","rendered":true,"slug":"controls-outsourced-critical-component-development-oversight","sourceTemplateId":"workflow-library:controls-outsourced-critical-component-development-oversight","sources":["iso-27001","nist-800-53"],"teams":["procurement","it"],"title":"Outsourced & Critical-Component Development Oversight","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-technology-lifecycle-capacity-review","capabilities":[],"department":"it","id":"wf:C64","mappingStatus":"mapped","releaseId":"sha256:bcb5dc6468aa8860bf2b008384f0dc30e2671f493be419239493ce585c592345","rendered":true,"slug":"controls-technology-lifecycle-capacity-review","sourceTemplateId":"workflow-library:controls-technology-lifecycle-capacity-review","sources":["cobit-2019","nist-800-53"],"teams":["it"],"title":"Technology Lifecycle & Capacity Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-ai-operations-monitoring-incident-response","capabilities":[],"department":"ai-governance","id":"wf:C65","mappingStatus":"mapped","releaseId":"sha256:b67b3ae208b8909971dcc618da590b99838d3fe95a94a69d43f8f9e802e71adb","rendered":true,"slug":"controls-ai-operations-monitoring-incident-response","sourceTemplateId":"workflow-library:controls-ai-operations-monitoring-incident-response","sources":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"teams":["ai-governance","it"],"title":"AI Operations Monitoring & Incident Response","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-ai-guardrail-configuration-agent-permission-review","capabilities":[],"department":"ai-governance","id":"wf:C66","mappingStatus":"mapped","releaseId":"sha256:b02741cf77f111c9d5a16e847a45acf672e5b25cbe8a0511ebdabe8a4cf69f61","rendered":true,"slug":"controls-ai-guardrail-configuration-agent-permission-review","sourceTemplateId":"workflow-library:controls-ai-guardrail-configuration-agent-permission-review","sources":["aiuc-1","nist-ai-agent-identity","nist-ai-tevv-athlon"],"teams":["ai-governance","it"],"title":"AI Guardrail Configuration & Agent Permission Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-quarterly-third-party-ai-evaluation-cycle","capabilities":[],"department":"ai-governance","id":"wf:C67","mappingStatus":"mapped","releaseId":"sha256:e542a1851c8c176ba2d527bcdd1e574e8c9b9b5ee51fbbb9ca5a86307c7b2d84","rendered":true,"slug":"controls-quarterly-third-party-ai-evaluation-cycle","sourceTemplateId":"workflow-library:controls-quarterly-third-party-ai-evaluation-cycle","sources":["aiuc-1","nist-ai-agent-identity","nist-ai-tevv-athlon"],"teams":["ai-governance","procurement"],"title":"Quarterly Third-Party AI Evaluation Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-personnel-offboarding-access","capabilities":["offboarding-access-revocation"],"department":"it","id":"wf:C68","mappingStatus":"mapped","releaseId":"sha256:caafde58d223a05539df8c7f542b5c52d75a17bde58042450b390792a9c7b218","rendered":true,"slug":"controls-personnel-offboarding-access","sourceTemplateId":"workflow-library:controls-personnel-offboarding-access","sources":["nist-800-53","soc1","soc2","sox"],"teams":["it"],"title":"Offboarding & Access Revocation","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-personnel-onboarding-access","capabilities":["onboarding-access-provisioning"],"department":"it","id":"wf:C69","mappingStatus":"mapped","releaseId":"sha256:1262db80aa606cf208fe178068d49691732d4cc91a175ece393ef3af9293f373","rendered":true,"slug":"controls-personnel-onboarding-access","sourceTemplateId":"workflow-library:controls-personnel-onboarding-access","sources":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2","sox"],"teams":["it"],"title":"Onboarding & Access Provisioning","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-iso27001-soa-review","capabilities":[],"department":"it","id":"wf:C7","mappingStatus":"mapped","releaseId":"sha256:8131d31962a4d6bfc7156742399d4a2f6ed9ee12af11daec6dfe1648c3a575d8","rendered":true,"slug":"controls-iso27001-soa-review","sourceTemplateId":"workflow-library:controls-iso27001-soa-review","sources":["cobit-2019","coso-erm","coso-ic","gdpr","hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"teams":["it","compliance-legal"],"title":"ISO 27001 SoA Review & Controls Assessment","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-personnel-transfer-access","capabilities":["transfer-access-modification"],"department":"it","id":"wf:C70","mappingStatus":"mapped","releaseId":"sha256:dc992c20b421860c0a318eb76700110f4fc752b38e83243bcc216325ced3047c","rendered":true,"slug":"controls-personnel-transfer-access","sourceTemplateId":"workflow-library:controls-personnel-transfer-access","sources":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2","sox"],"teams":["it"],"title":"Transfer & Access Modification","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-remediation-delivery-validation","capabilities":["remediation-delivery-validation"],"department":"operations","id":"wf:C71","mappingStatus":"mapped","releaseId":"sha256:1d968c8acfc2bd6f39974fb0b8bf73fbe438470b6211d849af0502405e11076d","rendered":true,"slug":"controls-remediation-delivery-validation","sourceTemplateId":"workflow-library:controls-remediation-delivery-validation","sources":["nist-800-53","soc2"],"teams":["operations"],"title":"Remediation Delivery & Validation","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-access-recertification","capabilities":["periodic-user-access-review"],"department":"it","id":"wf:C72","mappingStatus":"mapped","releaseId":"sha256:e4c82920fd5501605623b273d6814f3976845ff2c498c45f5e88bfaf47aed9ae","rendered":true,"slug":"controls-system-access-recertification","sourceTemplateId":"workflow-library:controls-system-access-recertification","sources":["iso-27001","nydfs-500"],"teams":["it"],"title":"Periodic User Access Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-backup-restoration-test","capabilities":["backup-recovery-testing"],"department":"it","id":"wf:C73","mappingStatus":"mapped","releaseId":"sha256:daf5fa339d6abca65f52e24586c6311d2d88cfb5fed227d441397871bd4e2bec","rendered":true,"slug":"controls-system-backup-restoration-test","sourceTemplateId":"workflow-library:controls-system-backup-restoration-test","sources":["iso-27001","nist-800-53","nist-csf-2","soc2"],"teams":["it"],"title":"Backup & Recovery Testing","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-batch-processing-review","capabilities":["job-scheduling-batch-monitoring"],"department":"it","id":"wf:C74","mappingStatus":"mapped","releaseId":"sha256:bedd1ab9491ab9bc1750397e6669e1d8de35062dce88fbe992cde579fdd4363b","rendered":true,"slug":"controls-system-batch-processing-review","sourceTemplateId":"workflow-library:controls-system-batch-processing-review","sources":["soc1"],"teams":["it"],"title":"Job Scheduling & Batch Monitoring","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-change-approval-migration","capabilities":["change-request-approval-migration"],"department":"it","id":"wf:C75","mappingStatus":"mapped","releaseId":"sha256:b7a02e83141c52306773f1ca95808c5b085b6bed12cb7151e0542d7b204bf9b2","rendered":true,"slug":"controls-system-change-approval-migration","sourceTemplateId":"workflow-library:controls-system-change-approval-migration","sources":["cobit-2019"],"teams":["it"],"title":"Change Request, Approval & Migration","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-data-conversion-validation","capabilities":["data-conversion-migration"],"department":"it","id":"wf:C76","mappingStatus":"mapped","releaseId":"sha256:1afd9a665fecc025c52c0c60726c3bcd4eb1306ccb79aee21936b21824d4f9d7","rendered":true,"slug":"controls-system-data-conversion-validation","sourceTemplateId":"workflow-library:controls-system-data-conversion-validation","sources":["soc1"],"teams":["it"],"title":"Data Conversion & Migration","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-emergency-change","capabilities":["emergency-change"],"department":"it","id":"wf:C77","mappingStatus":"mapped","releaseId":"sha256:1e33df05e7ecbc3cc43cd5aca7ad1e022ffb1238e7f44143982f46a51eea4a33","rendered":true,"slug":"controls-system-emergency-change","sourceTemplateId":"workflow-library:controls-system-emergency-change","sources":["cobit-2019"],"teams":["it"],"title":"Emergency Change","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-euc-validation","capabilities":["euc-inventory-validation"],"department":"it","id":"wf:C78","mappingStatus":"mapped","releaseId":"sha256:7d6a110101d46d36ef6125f2bb1ed4f193f88c88ef5753f5275ab3560291b33c","rendered":true,"slug":"controls-system-euc-validation","sourceTemplateId":"workflow-library:controls-system-euc-validation","sources":["soc1"],"teams":["it"],"title":"End-User Computing Inventory & Validation","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-implementation-readiness","capabilities":["new-system-implementation"],"department":"it","id":"wf:C79","mappingStatus":"mapped","releaseId":"sha256:a7d51eb909a2f68f80eba7d33675cadeb83b680914bed3337c87482c46f9ea0c","rendered":true,"slug":"controls-system-implementation-readiness","sourceTemplateId":"workflow-library:controls-system-implementation-readiness","sources":["cobit-2019","iso-27001"],"teams":["it"],"title":"New System Implementation (SDLC)","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-rmf-system-authorization-ato","capabilities":[],"department":"it","id":"wf:C8","mappingStatus":"mapped","releaseId":"sha256:fb1370c15e42a8a84603dd92914c3f91d5edd898296476d2cafb967d88ebb215","rendered":true,"slug":"controls-rmf-system-authorization-ato","sourceTemplateId":"workflow-library:controls-rmf-system-authorization-ato","sources":["cobit-2019","coso-ic","nist-800-53","soc2","sox"],"teams":["it","compliance-legal"],"title":"NIST RMF System Authorization (ATO) Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-incident-problem-review","capabilities":["incident-problem-management"],"department":"it","id":"wf:C80","mappingStatus":"mapped","releaseId":"sha256:93d0aa5a409d203e64d1562914362cc6b67fd832883fe53c57410d39b3caa247","rendered":true,"slug":"controls-system-incident-problem-review","sourceTemplateId":"workflow-library:controls-system-incident-problem-review","sources":["cobit-2019","dora"],"teams":["it"],"title":"Incident & Problem Management","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-privileged-access-review","capabilities":["privileged-access-review"],"department":"it","id":"wf:C81","mappingStatus":"mapped","releaseId":"sha256:e3ac108af9cd689c1f752de579c7b9a732023b919cd218d036e128b47a82b175","rendered":true,"slug":"controls-system-privileged-access-review","sourceTemplateId":"workflow-library:controls-system-privileged-access-review","sources":["iso-27001","nist-csf-2"],"teams":["it"],"title":"Privileged Access Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-security-assessment-poam-remediation","capabilities":[],"department":"it","id":"wf:C9","mappingStatus":"mapped","releaseId":"sha256:513af45d886c143c166f32c84f2080655a9a78f1376bd2613ac47d412d1bb6c8","rendered":true,"slug":"controls-security-assessment-poam-remediation","sourceTemplateId":"workflow-library:controls-security-assessment-poam-remediation","sources":["aiuc-1","cobit-2019","coso-ic","gdpr","hipaa","iia-2024","iso-27001","nis2","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"teams":["it","compliance-legal"],"title":"Security Control Assessment & POA&M Remediation","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-control-design-assessment","capabilities":["control-design-assessment"],"department":"internal-audit","id":"wf:D01","mappingStatus":"mapped","releaseId":"sha256:19ed451f8831aa644571f5f565bd060230005406569c794b1ae5b463984f10c6","rendered":true,"slug":"audit-control-design-assessment","sourceTemplateId":"workflow-library:audit-control-design-assessment","sources":["cobit-2019","coso-ic","iia-2024","nist-800-53","sox"],"teams":["internal-audit"],"title":"Control Design Assessment","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-control-exception-evaluation-remediation","capabilities":["control-exception-evaluation-remediation"],"department":"internal-audit","id":"wf:D02","mappingStatus":"mapped","releaseId":"sha256:79e9e68b50d4d7b1170a8c79e2027f1ccd9f12defc3ac6c7b9940811542f9065","rendered":true,"slug":"audit-control-exception-evaluation-remediation","sourceTemplateId":"workflow-library:audit-control-exception-evaluation-remediation","sources":["iia-2024","nist-800-53","soc2"],"teams":["internal-audit","risk-management"],"title":"Control Exception Evaluation and Remediation","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-control-remediation-retest-closure","capabilities":["control-remediation-retest-closure"],"department":"internal-audit","id":"wf:D03","mappingStatus":"mapped","releaseId":"sha256:6748ff523340814f9924c86d601621610bb452a0adc63aa26212687870a3208d","rendered":true,"slug":"audit-control-remediation-retest-closure","sourceTemplateId":"workflow-library:audit-control-remediation-retest-closure","sources":["cobit-2019","coso-ic","iia-2024","nist-800-53","nist-csf-2","sox"],"teams":["internal-audit"],"title":"Control Remediation Retest and Closure","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-control-walkthrough","capabilities":["control-walkthrough"],"department":"internal-audit","id":"wf:D04","mappingStatus":"mapped","releaseId":"sha256:aad79d3a209a28e35932add90167fe72340b4e937a9b43d97d71a986d998cd4f","rendered":true,"slug":"audit-control-walkthrough","sourceTemplateId":"workflow-library:audit-control-walkthrough","sources":["cobit-2019","coso-ic","iia-2024","nist-800-53","sox"],"teams":["internal-audit"],"title":"Control Walkthrough","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-iso27001-stage1-documentation-review","capabilities":[],"department":"internal-audit","id":"wf:D05","mappingStatus":"mapped","releaseId":"sha256:943b404cc0e12e6e267dfbc1f1d00c7877ba4169de0de517c4d7fb5e13899775","rendered":true,"slug":"audit-iso27001-stage1-documentation-review","sourceTemplateId":"workflow-library:audit-iso27001-stage1-documentation-review","sources":["ccpa","cobit-2019","coso-erm","coso-ic","hipaa","iia-2024","iia-pos-2026-three-lines","iso-27001","iso-31000","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2","sox"],"teams":["internal-audit"],"title":"ISO 27001 Stage 1 ISMS Documentation Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-iso27001-stage2-controls-audit","capabilities":[],"department":"internal-audit","id":"wf:D06","mappingStatus":"mapped","releaseId":"sha256:b684ea2e0d1a9c1dea7abe73d94ca5e187127e4e8497cd066aaf3917023996ae","rendered":true,"slug":"audit-iso27001-stage2-controls-audit","sourceTemplateId":"workflow-library:audit-iso27001-stage2-controls-audit","sources":["aiuc-1","ccpa","cobit-2019","coso-erm","coso-ic","dora","eu-ai-act","gdpr","hipaa","iia-2024","iia-pos-2026-three-lines","iso-27001","iso-31000","nis2","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"teams":["internal-audit"],"title":"ISO 27001 Stage 2 Annex A Controls Audit","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-planning-scoping","capabilities":["audit-planning-scoping"],"department":"internal-audit","id":"wf:D10","mappingStatus":"mapped","releaseId":"sha256:b129f9b9eac5c2e11573cd10f14c1314472067164b8f97a66dcff8c708730543","rendered":true,"slug":"audit-planning-scoping","sourceTemplateId":"workflow-library:audit-planning-scoping","sources":["iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines"],"teams":["internal-audit"],"title":"Audit Planning and Scoping","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-soc2-availability-assessment","capabilities":[],"department":"internal-audit","id":"wf:D11","mappingStatus":"mapped","releaseId":"sha256:7983431d7321b998260992c652b92d70e13509f7bf8e704d755e882efb2c9f77","rendered":true,"slug":"audit-soc2-availability-assessment","sourceTemplateId":"workflow-library:audit-soc2-availability-assessment","sources":["dora","iso-27001","nist-800-53","nist-csf-2","soc2"],"teams":["internal-audit"],"title":"SOC 2 Availability Assessment","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-soc2-confidentiality-assessment","capabilities":[],"department":"internal-audit","id":"wf:D21","mappingStatus":"mapped","releaseId":"sha256:2b53c083aeda413a08ab84f0003e32b08689327edd594b9f442805aae092b899","rendered":true,"slug":"audit-soc2-confidentiality-assessment","sourceTemplateId":"workflow-library:audit-soc2-confidentiality-assessment","sources":["iso-27001","nist-800-53","nist-csf-2","soc2"],"teams":["internal-audit"],"title":"SOC 2 Confidentiality Assessment","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-soc2-privacy-criteria-assessment","capabilities":[],"department":"internal-audit","id":"wf:D22","mappingStatus":"mapped","releaseId":"sha256:e6d523b7976d80d05bd077cdc53c1be7c8205d77d0da9569a624c7dca13e8a2f","rendered":true,"slug":"audit-soc2-privacy-criteria-assessment","sourceTemplateId":"workflow-library:audit-soc2-privacy-criteria-assessment","sources":["ccpa","gdpr","hipaa","iso-27001","nist-800-53","soc2"],"teams":["internal-audit"],"title":"SOC 2 Privacy Criteria Assessment","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-soc2-processing-integrity-assessment","capabilities":[],"department":"internal-audit","id":"wf:D23","mappingStatus":"mapped","releaseId":"sha256:57d4dce4e6d411751ff2482a79f9545f465586d447cab37498bd8d777237d19d","rendered":true,"slug":"audit-soc2-processing-integrity-assessment","sourceTemplateId":"workflow-library:audit-soc2-processing-integrity-assessment","sources":["soc2","sox"],"teams":["internal-audit"],"title":"SOC 2 Processing Integrity Assessment","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-soc2-type2-interim-testing","capabilities":[],"department":"internal-audit","id":"wf:D24","mappingStatus":"mapped","releaseId":"sha256:26d1ded689c4f18e7d13568fab54fde2e1caa585cc01e7820226c793cfd2b175","rendered":true,"slug":"audit-soc2-type2-interim-testing","sourceTemplateId":"workflow-library:audit-soc2-type2-interim-testing","sources":["aiuc-1","cobit-2019","coso-erm","coso-ic","dora","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"teams":["internal-audit"],"title":"SOC 2 Type II Interim Testing","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-employee-offboarding","capabilities":["employee-offboarding","access-revocation"],"department":"hr","id":"wf:D30","mappingStatus":"mapped","releaseId":"sha256:68d2f74392f49dc7f6fe33168ecb26fff8f603027c0745299ef3cb2c1ba77321","rendered":true,"slug":"controls-employee-offboarding","sourceTemplateId":"workflow-library:controls-employee-offboarding","sources":["iso-27001","nist-800-53","soc1","soc2","sox"],"teams":["hr","it"],"title":"Employee Offboarding","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-employee-onboarding","capabilities":["employee-onboarding","access-provisioning"],"department":"hr","id":"wf:D31","mappingStatus":"mapped","releaseId":"sha256:ecd83603cb9d5ba1cf47ac8c3d5a980d850a4edfec45dd1bb52098ba3cfeda98","rendered":true,"slug":"controls-employee-onboarding","sourceTemplateId":"workflow-library:controls-employee-onboarding","sources":["hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"teams":["hr","it"],"title":"Employee Onboarding","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-gcp-physical-environmental-subservice-reliance","capabilities":[],"department":"it","id":"wf:D32","mappingStatus":"mapped","releaseId":"sha256:5af35ab842eb7c5b52ca2e9bcd4fd14f41d4c89299b5264a6dfb7250fcd2600c","rendered":true,"slug":"controls-gcp-physical-environmental-subservice-reliance","sourceTemplateId":"workflow-library:controls-gcp-physical-environmental-subservice-reliance","sources":["iso-27001","nist-800-53","nist-csf-2","soc1","soc2"],"teams":["it","risk-management"],"title":"GCP Physical and Environmental Subservice Reliance","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-remediation-delivery","capabilities":[],"department":"operations","id":"wf:D37","mappingStatus":"mapped","releaseId":"sha256:4d8c5f2ce3e264ed1116540f0195c8bad3d0b12f1d421e2ff3e6930cf127b3bc","rendered":true,"slug":"controls-remediation-delivery","sourceTemplateId":"workflow-library:controls-remediation-delivery","sources":["nist-800-53","soc2"],"teams":["operations"],"title":"Remediation Delivery","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-itgc-operation","capabilities":[],"department":"it","id":"wf:D40","mappingStatus":"mapped","releaseId":"sha256:ee939e9afca588e18417cd888bbf38732d528c8799f482833f36f760385ed30b","rendered":true,"slug":"controls-system-itgc-operation","sourceTemplateId":"workflow-library:controls-system-itgc-operation","sources":["hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"teams":["it"],"title":"System ITGC Operation","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-annual-policy-review","capabilities":["policy-annual-review"],"department":"compliance-legal","id":"wf:D49","mappingStatus":"mapped","releaseId":"sha256:ccc74893e9e25bfb5a02f79364bdc1997c132196bc534949164c09e48738a227","rendered":true,"slug":"grc-annual-policy-review","sourceTemplateId":"workflow-library:grc-annual-policy-review","sources":["hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"teams":["compliance-legal"],"title":"Annual Policy Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-domain-oversight-management-review","capabilities":[],"department":"risk-management","id":"wf:D50","mappingStatus":"mapped","releaseId":"sha256:d61ea8f4d4988817a3771d780f21c98336cf07ac4f1b9cb318e7913dd738d1fa","rendered":true,"slug":"grc-domain-oversight-management-review","sourceTemplateId":"workflow-library:grc-domain-oversight-management-review","sources":["cobit-2019","coso-erm","coso-ic","iso-31000","nist-800-53","soc2"],"teams":["risk-management","executive"],"title":"Domain Oversight and Management Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-issue-remediation-verification","capabilities":[],"department":"risk-management","id":"wf:D51","mappingStatus":"mapped","releaseId":"sha256:eb09ca81ac511655754f2d0a447ea40841ae72efcf42e3bfb39ce73400e26a0c","rendered":true,"slug":"grc-issue-remediation-verification","sourceTemplateId":"workflow-library:grc-issue-remediation-verification","sources":["nist-800-53","soc2"],"teams":["risk-management","operations"],"title":"Issue Remediation and Verification","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-policy-change","capabilities":["policy-change"],"department":"compliance-legal","id":"wf:D52","mappingStatus":"mapped","releaseId":"sha256:4d0bf9ff2cf1ce535e30fcc8df2604156764659d95839402041eaabec9ee0917","rendered":true,"slug":"grc-policy-change","sourceTemplateId":"workflow-library:grc-policy-change","sources":["hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"teams":["compliance-legal"],"title":"Policy Change","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-risk-assessment-treatment-review","capabilities":["risk-assessment-treatment-review"],"department":"risk-management","id":"wf:D53","mappingStatus":"mapped","releaseId":"sha256:be78b032b9dd7a006f5dcc70e2dfb3e6acad595c02e4813e28601c1b350ed90c","rendered":true,"slug":"grc-risk-assessment-treatment-review","sourceTemplateId":"workflow-library:grc-risk-assessment-treatment-review","sources":["coso-erm","coso-ic","iso-31000","nist-800-53","nist-csf-2","soc2"],"teams":["risk-management"],"title":"Risk Assessment and Treatment Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-soc2-reporting-management-assertion","capabilities":[],"department":"compliance-legal","id":"wf:D54","mappingStatus":"mapped","releaseId":"sha256:3674467114ba7d272775885cfbb2dc7591c579950a0bdad5f8e7d49a90cba04e","rendered":true,"slug":"grc-soc2-reporting-management-assertion","sourceTemplateId":"workflow-library:grc-soc2-reporting-management-assertion","sources":["cobit-2019","coso-erm","coso-ic","iso-27001","nist-800-53","nist-csf-2","soc2"],"teams":["compliance-legal","executive"],"title":"SOC 2 Reporting and Management Assertion","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-system-third-party-risk-review","capabilities":["system-third-party-risk-review"],"department":"risk-management","id":"wf:D55","mappingStatus":"mapped","releaseId":"sha256:d9186ad1dc8351f49127ab6e35603aab14ffd8eae0f6994ca6e3b52ac74bd3d1","rendered":true,"slug":"grc-system-third-party-risk-review","sourceTemplateId":"workflow-library:grc-system-third-party-risk-review","sources":["aiuc-1","iso-27001","nist-800-53","nist-csf-2","soc2"],"teams":["risk-management","it","procurement"],"title":"System and Third-Party Risk Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-vendor-risk-assessment-disposition","capabilities":[],"department":"procurement","id":"wf:D56","mappingStatus":"mapped","releaseId":"sha256:0e1b87c81c6df3a7731724450a4addf288b73a1af31f910c346d83d2618b16a5","rendered":true,"slug":"grc-vendor-risk-assessment-disposition","sourceTemplateId":"workflow-library:grc-vendor-risk-assessment-disposition","sources":["ccpa","gdpr","hipaa","iso-27001","nist-800-53","nist-csf-2","soc1","soc2"],"teams":["procurement","risk-management","it"],"title":"Vendor Risk Assessment and Disposition","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-interim-operating-effectiveness-testing","capabilities":[],"department":"internal-audit","id":"wf:D57","mappingStatus":"mapped","releaseId":"sha256:5bd155c018ab3cb785e6499512fb5c53848286349c16be8d9ce1b3a52651c824","rendered":true,"slug":"sox-interim-operating-effectiveness-testing","sourceTemplateId":"workflow-library:sox-interim-operating-effectiveness-testing","sources":["cobit-2019","coso-ic","iia-2024","iso-27001","nist-800-53","soc2","sox"],"teams":["internal-audit","finance"],"title":"Interim Operating Effectiveness Testing","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-period-end-roll-forward-testing","capabilities":[],"department":"internal-audit","id":"wf:D58","mappingStatus":"mapped","releaseId":"sha256:4d21a6f09c45e2990d073d8fbadc984b694d6579c9740ac5880b6ef21da577d2","rendered":true,"slug":"sox-period-end-roll-forward-testing","sourceTemplateId":"workflow-library:sox-period-end-roll-forward-testing","sources":["cobit-2019","coso-ic","iso-27001","nist-800-53","soc2","sox"],"teams":["internal-audit","finance"],"title":"Period-End Roll-Forward Testing","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=audit-iso42001-aims-internal-audit","capabilities":[],"department":"internal-audit","id":"wf:D59","mappingStatus":"mapped","releaseId":"sha256:15ecca1696f441388036dd0925f0e6d73e923ea467770f5f0b411263de489779","rendered":true,"slug":"audit-iso42001-aims-internal-audit","sourceTemplateId":"workflow-library:audit-iso42001-aims-internal-audit","sources":["aiuc-1","cobit-2019","coso-ic","eu-ai-act","iso-42001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","sox"],"teams":["internal-audit","ai-governance"],"title":"ISO/IEC 42001 AI Management System Internal Audit","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-ai-governance-aims-assessment","capabilities":[],"department":"ai-governance","id":"wf:G1","mappingStatus":"mapped","releaseId":"sha256:f13547ad64a1e7ed0822c6ec471aea724ebac5e7e5bcc6629ee6c8c40aca16dc","rendered":true,"slug":"grc-ai-governance-aims-assessment","sourceTemplateId":"workflow-library:grc-ai-governance-aims-assessment","sources":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"teams":["ai-governance"],"title":"AI Governance & Risk/Impact Assessment","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-quarterly-board-audit-committee-reporting","capabilities":[],"department":"risk-management","id":"wf:G10","mappingStatus":"mapped","releaseId":"sha256:6d75ecb22ff2f49635ee533d71e7f61e415ea80adf9c9b1366b87543baf635a9","rendered":true,"slug":"grc-quarterly-board-audit-committee-reporting","sourceTemplateId":"workflow-library:grc-quarterly-board-audit-committee-reporting","sources":["cobit-2019","coso-erm","coso-ic","iia-2024","iso-31000","nis2","nist-800-53","nist-csf-2","soc2"],"teams":["risk-management","internal-audit","executive"],"title":"Quarterly Board & Audit-Committee GRC Reporting","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-risk-appetite-board-reporting","capabilities":[],"department":"executive","id":"wf:G11","mappingStatus":"mapped","releaseId":"sha256:723ab74c727b8838bd39308f2744973e46edacb63b7c2394677b5adc452c10ed","rendered":true,"slug":"grc-risk-appetite-board-reporting","sourceTemplateId":"workflow-library:grc-risk-appetite-board-reporting","sources":["cobit-2019","coso-erm","coso-ic","iso-31000","nis2","nist-800-53","nist-csf-2","soc2"],"teams":["executive","risk-management"],"title":"Risk Appetite Definition & Board Reporting","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-risk-register-intake","capabilities":[],"department":"risk-management","id":"wf:G12","mappingStatus":"mapped","releaseId":"sha256:75e01ddd883d1cf48630fce5879880b334cfdd9af7e2aec3111be8842be42114","rendered":true,"slug":"grc-risk-register-intake","sourceTemplateId":"workflow-library:grc-risk-register-intake","sources":["coso-erm","iso-31000","nist-csf-2"],"teams":["risk-management"],"title":"Risk Register Intake","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-third-party-vendor-risk-lifecycle","capabilities":[],"department":"procurement","id":"wf:G13","mappingStatus":"mapped","releaseId":"sha256:96f9e2a2333ab1b869a093e9ffa77920c2a18e3719304346f9daebe8bc6ce5fa","rendered":true,"slug":"grc-third-party-vendor-risk-lifecycle","sourceTemplateId":"workflow-library:grc-third-party-vendor-risk-lifecycle","sources":["aiuc-1","ccpa","cobit-2019","dora","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2"],"teams":["procurement"],"title":"Third-Party Vendor Risk Lifecycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-policy-exception-risk-acceptance","capabilities":[],"department":"risk-management","id":"wf:G14","mappingStatus":"mapped","releaseId":"sha256:4cf2f22767e9a99b893684ffb6e0d1fa7238fa4bcafda89190b6a2052a31b0ef","rendered":true,"slug":"grc-policy-exception-risk-acceptance","sourceTemplateId":"workflow-library:grc-policy-exception-risk-acceptance","sources":["coso-erm","iia-2024","iso-31000","nist-800-53","nist-csf-2"],"teams":["risk-management","compliance-legal"],"title":"Policy Exception & Risk Acceptance","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-it-governance-cobit-review","capabilities":[],"department":"executive","id":"wf:G15","mappingStatus":"mapped","releaseId":"sha256:10127d5f20ad531fc57130095f92fb97dcdcf60abc15a77096891474c8966351","rendered":true,"slug":"grc-it-governance-cobit-review","sourceTemplateId":"workflow-library:grc-it-governance-cobit-review","sources":["cobit-2019","coso-erm","coso-ic","nist-800-53","nist-csf-2","nydfs-500","soc2"],"teams":["executive","it"],"title":"IT Governance Objective Review (COBIT)","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-risk-resilience-framework-governance","capabilities":[],"department":"risk-management","id":"wf:G16","mappingStatus":"mapped","releaseId":"sha256:2eaeb9c8bb2b20a89e69ff15a7f08852a99129d1bad280b4e70a722a18fef665","rendered":true,"slug":"grc-risk-resilience-framework-governance","sourceTemplateId":"workflow-library:grc-risk-resilience-framework-governance","sources":["cobit-2019","coso-erm","dora","eu-ai-act","iso-31000","nist-800-53","nist-csf-2"],"teams":["risk-management","executive"],"title":"Risk & Resilience Framework Governance","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-board-risk-internal-control-oversight-cycle","capabilities":[],"department":"executive","id":"wf:G17","mappingStatus":"mapped","releaseId":"sha256:699bb8f921e61282509d797631e22c865a0c1b254195bbc6798e50947f563a0f","rendered":true,"slug":"grc-board-risk-internal-control-oversight-cycle","sourceTemplateId":"workflow-library:grc-board-risk-internal-control-oversight-cycle","sources":["cobit-2019","coso-erm","coso-ic","nis2","nist-csf-2","soc2"],"teams":["executive","risk-management"],"title":"Board Risk & Internal Control Oversight Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-code-of-conduct-workforce-accountability-cycle","capabilities":[],"department":"hr","id":"wf:G18","mappingStatus":"mapped","releaseId":"sha256:297e477eb945b39af22edd0a8fe11617b292c0bd8882d2eaaa9eeb9d06a03f41","rendered":true,"slug":"grc-code-of-conduct-workforce-accountability-cycle","sourceTemplateId":"workflow-library:grc-code-of-conduct-workforce-accountability-cycle","sources":["coso-erm","coso-ic","iso-27001","nist-800-53","nist-csf-2","soc2","sox"],"teams":["hr","compliance-legal"],"title":"Code of Conduct & Workforce Accountability Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-technology-investment-project-risk-governance","capabilities":[],"department":"executive","id":"wf:G19","mappingStatus":"mapped","releaseId":"sha256:bce9657225cd01598d10e901416f1aedcc06fe22a5b2aa418dc3d393cc8c3dfd","rendered":true,"slug":"grc-technology-investment-project-risk-governance","sourceTemplateId":"workflow-library:grc-technology-investment-project-risk-governance","sources":["cobit-2019","iso-27001","iso-31000","nist-800-53","nist-csf-2"],"teams":["executive","it"],"title":"Technology Investment & Project Risk Governance","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-combined-assurance-mapping","capabilities":[],"department":"internal-audit","id":"wf:G2","mappingStatus":"mapped","releaseId":"sha256:f0ae775a3a86f082f6bcc1a2383a15f8e0219c50577d82600fbd8fa89c947e8e","rendered":true,"slug":"grc-combined-assurance-mapping","sourceTemplateId":"workflow-library:grc-combined-assurance-mapping","sources":["ccpa","cobit-2019","coso-ic","iia-2024","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-27001"],"teams":["internal-audit","risk-management"],"title":"Combined Assurance Mapping","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-strategic-context-objectives-alignment-cycle","capabilities":[],"department":"executive","id":"wf:G20","mappingStatus":"mapped","releaseId":"sha256:ef223302fc7834d5c7acb69246e0932c83b66fb891910b7b9da62b7615e9ec4f","rendered":true,"slug":"grc-strategic-context-objectives-alignment-cycle","sourceTemplateId":"workflow-library:grc-strategic-context-objectives-alignment-cycle","sources":["cobit-2019","coso-erm","coso-ic","nist-800-53","nist-csf-2","soc2"],"teams":["executive","risk-management"],"title":"Strategic Context & Objectives Alignment Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-data-governance-council-operations","capabilities":[],"department":"operations","id":"wf:G21","mappingStatus":"mapped","releaseId":"sha256:2c5564bd2edf274e1a4337ed6524ca7a882fedcab9c7b1f2d5715bae74dfca70","rendered":true,"slug":"grc-data-governance-council-operations","sourceTemplateId":"workflow-library:grc-data-governance-council-operations","sources":["cobit-2019","nist-800-53"],"teams":["operations","privacy","it"],"title":"Data Governance Council Operations","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-enterprise-risk-assessment-treatment-cycle","capabilities":[],"department":"operations","id":"wf:G22","mappingStatus":"mapped","releaseId":"sha256:bbc320670d4d8c85ce55c4b291867eb62b89ddc4c7b8c7aacd8355d71a632125","rendered":true,"slug":"grc-enterprise-risk-assessment-treatment-cycle","sourceTemplateId":"workflow-library:grc-enterprise-risk-assessment-treatment-cycle","sources":["coso-erm","coso-ic","iso-31000","nist-800-53","nist-csf-2","nydfs-500","soc2","sox"],"teams":["operations","risk-management"],"title":"Enterprise Risk Treatment Operations Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-risk-communication-reporting-performance-review","capabilities":[],"department":"risk-management","id":"wf:G23","mappingStatus":"mapped","releaseId":"sha256:a9b7771d4a349b09631c9de418215f6f44afa4c44bd3c01f6e11d5431aa862d8","rendered":true,"slug":"grc-risk-communication-reporting-performance-review","sourceTemplateId":"workflow-library:grc-risk-communication-reporting-performance-review","sources":["cobit-2019","coso-erm","coso-ic","iso-31000","nist-csf-2","soc2"],"teams":["risk-management"],"title":"Risk Communication, Reporting & Performance Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-subservice-organization-third-party-personnel-oversight","capabilities":[],"department":"procurement","id":"wf:G24","mappingStatus":"mapped","releaseId":"sha256:f363048ac9ad6bf8d1664397cb2ca7ee815450822567ec5ffd7c1027bf080c2c","rendered":true,"slug":"grc-subservice-organization-third-party-personnel-oversight","sourceTemplateId":"workflow-library:grc-subservice-organization-third-party-personnel-oversight","sources":["iso-27001","nist-800-53","soc1"],"teams":["procurement","hr"],"title":"Subservice Organization & Third-Party Personnel Oversight","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-personnel-screening-agreements-sanctions-administration","capabilities":[],"department":"hr","id":"wf:G25","mappingStatus":"mapped","releaseId":"sha256:d2e485a453e0634692cb0eeb10d2b2baf6047d54c4c8148e28914b9b78f59cd9","rendered":true,"slug":"grc-personnel-screening-agreements-sanctions-administration","sourceTemplateId":"workflow-library:grc-personnel-screening-agreements-sanctions-administration","sources":["hipaa","iso-27001","nist-800-53"],"teams":["hr"],"title":"Personnel Screening, Agreements & Sanctions Administration","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-supplier-service-registry-critical-supplier-assessment","capabilities":[],"department":"procurement","id":"wf:G26","mappingStatus":"mapped","releaseId":"sha256:bf161dec8217bd83b608ffa897e2f2b7bb5cd7ca553873b4a43fc32b3d54a617","rendered":true,"slug":"grc-supplier-service-registry-critical-supplier-assessment","sourceTemplateId":"workflow-library:grc-supplier-service-registry-critical-supplier-assessment","sources":["nist-csf-2"],"teams":["procurement"],"title":"Supplier Service Registry & Critical Supplier Assessment","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-control-responsibility-communications-ethics-hotline","capabilities":[],"department":"compliance-legal","id":"wf:G27","mappingStatus":"mapped","releaseId":"sha256:46c33e7957451f219f05cbf24352132b607a2602b1935d359cd89256b4630baa","rendered":true,"slug":"grc-control-responsibility-communications-ethics-hotline","sourceTemplateId":"workflow-library:grc-control-responsibility-communications-ethics-hotline","sources":["sox"],"teams":["compliance-legal","hr"],"title":"Control Responsibility Communications & Ethics Hotline","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-vendor-due-diligence-contracting-gate","capabilities":[],"department":"procurement","id":"wf:G28","mappingStatus":"mapped","releaseId":"sha256:5119b29be115a4aef6f49bee55dd7116b088d3345b47938ce2a9e3dd6fa846dc","rendered":true,"slug":"grc-vendor-due-diligence-contracting-gate","sourceTemplateId":"workflow-library:grc-vendor-due-diligence-contracting-gate","sources":["ccpa","gdpr","hipaa","nist-800-53","nist-csf-2","soc2"],"teams":["procurement","privacy"],"title":"Vendor Due Diligence & Contracting Gate","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-third-party-risk-program-vendor-oversight-cycle","capabilities":[],"department":"procurement","id":"wf:G29","mappingStatus":"mapped","releaseId":"sha256:a897ce21c38e200ae7741ba040630159a3e639a9f926f61653e2dc07ba3c28f6","rendered":true,"slug":"grc-third-party-risk-program-vendor-oversight-cycle","sourceTemplateId":"workflow-library:grc-third-party-risk-program-vendor-oversight-cycle","sources":["cobit-2019","dora","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500"],"teams":["procurement","executive"],"title":"Third-Party Risk Program & Vendor Oversight Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-enterprise-risk-assessment-cycle","capabilities":[],"department":"risk-management","id":"wf:G3","mappingStatus":"mapped","releaseId":"sha256:c0b55c9a7fc920d14f3d9ae8b3d77d431a7fa57d1bdb0cd025c63ae86e94f2e9","rendered":true,"slug":"grc-enterprise-risk-assessment-cycle","sourceTemplateId":"workflow-library:grc-enterprise-risk-assessment-cycle","sources":["coso-erm","coso-ic","iso-31000","nist-800-53","nist-csf-2","nydfs-500","soc2","sox"],"teams":["risk-management"],"title":"Enterprise Risk Assessment & Portfolio Oversight Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-vendor-offboarding-secure-termination","capabilities":[],"department":"procurement","id":"wf:G30","mappingStatus":"mapped","releaseId":"sha256:68ba255991c944b50697cf043f9bc7fbde7ecf065f42ccb12f684c5a448b351c","rendered":true,"slug":"grc-vendor-offboarding-secure-termination","sourceTemplateId":"workflow-library:grc-vendor-offboarding-secure-termination","sources":["nist-800-53","nist-csf-2"],"teams":["procurement","it"],"title":"Vendor Offboarding & Secure Termination","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-ai-governance-framework-roles-obligations-review","capabilities":[],"department":"ai-governance","id":"wf:G31","mappingStatus":"mapped","releaseId":"sha256:aab1bde82a904f5eba9b2ae83229f011b64af87ef752b3180189fa1124799384","rendered":true,"slug":"grc-ai-governance-framework-roles-obligations-review","sourceTemplateId":"workflow-library:grc-ai-governance-framework-roles-obligations-review","sources":["aiuc-1","eu-ai-act","iso-42001"],"teams":["ai-governance","executive"],"title":"AI Governance Framework, Roles & Obligations Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-rcsa-program","capabilities":[],"department":"operations","id":"wf:G32","mappingStatus":"mapped","releaseId":"sha256:4a08a203b0f96f2087dae903e17246c4717f06bcf1767da2153cf0f3c9dcb894","rendered":true,"slug":"grc-rcsa-program","sourceTemplateId":"workflow-library:grc-rcsa-program","sources":["cobit-2019","coso-erm","coso-ic","iso-31000","nist-800-53","nist-csf-2","soc2"],"teams":["operations","risk-management"],"title":"Risk & Control Self-Assessment (RCSA) Program","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-regulatory-exam-management","capabilities":[],"department":"compliance-legal","id":"wf:G33","mappingStatus":"mapped","releaseId":"sha256:f6435e4199020b25d9143bcab2ab97b3aebb9f4c636df19a252b35f46f085c74","rendered":true,"slug":"grc-regulatory-exam-management","sourceTemplateId":"workflow-library:grc-regulatory-exam-management","sources":["aiuc-1","ccpa","cobit-2019","iia-2024","iia-pos-2026-three-lines","iso-27001","nist-800-53","nist-csf-2"],"teams":["compliance-legal"],"title":"Regulatory Exam & External Audit Management","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-control-library-lifecycle","capabilities":[],"department":"risk-management","id":"wf:G34","mappingStatus":"mapped","releaseId":"sha256:a76117c6573b51cec4f270fddb377e68b43540928702251450b81533f50ac57a","rendered":true,"slug":"grc-control-library-lifecycle","sourceTemplateId":"workflow-library:grc-control-library-lifecycle","sources":["cobit-2019","coso-ic","iso-27001","nist-800-53","soc2","sox"],"teams":["risk-management","finance"],"title":"Control Library Lifecycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-ai-service-data-policy-quality-management-cycle","capabilities":[],"department":"ai-governance","id":"wf:G35","mappingStatus":"mapped","releaseId":"sha256:578fedbe1717a4988fcc601d5f7881a77f1b6cc72e5f5e4f7e3f93d854941781","rendered":true,"slug":"grc-ai-service-data-policy-quality-management-cycle","sourceTemplateId":"workflow-library:grc-ai-service-data-policy-quality-management-cycle","sources":["aiuc-1","eu-ai-act","iso-42001"],"teams":["ai-governance","privacy"],"title":"AI Service Data Policy & Quality Management Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-emerging-risk-horizon-scan","capabilities":["emerging-risk-horizon-scan"],"department":"risk-management","id":"wf:G36","mappingStatus":"mapped","releaseId":"sha256:83efcfa5d3fb60eaa22ea6b249b2a86fe028af2f318a41e7613ed1982c4db22a","rendered":true,"slug":"grc-emerging-risk-horizon-scan","sourceTemplateId":"workflow-library:grc-emerging-risk-horizon-scan","sources":["coso-erm","coso-ic","iso-31000","nist-csf-2","soc2"],"teams":["risk-management"],"title":"Emerging Risk & Horizon Scan","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-issue-triage-disposition","capabilities":["issue-triage-disposition"],"department":"risk-management","id":"wf:G37","mappingStatus":"mapped","releaseId":"sha256:d9b811ef61181c1a3b0c6d4394b65b28259bc28a00192820c9502c0d2ffb73b7","rendered":true,"slug":"grc-issue-triage-disposition","sourceTemplateId":"workflow-library:grc-issue-triage-disposition","sources":["nist-800-53","soc2"],"teams":["risk-management"],"title":"Issue Triage & Disposition","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-risk-appetite-tolerance-calibration","capabilities":["risk-appetite-tolerance-calibration"],"department":"risk-management","id":"wf:G38","mappingStatus":"mapped","releaseId":"sha256:ef1f3206472603b0255f897b5c9116be6a0e6aa07910eba61064f586d24e13fb","rendered":true,"slug":"grc-risk-appetite-tolerance-calibration","sourceTemplateId":"workflow-library:grc-risk-appetite-tolerance-calibration","sources":["iso-31000","nist-800-53","nist-csf-2"],"teams":["risk-management"],"title":"Risk Appetite & Tolerance Calibration","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-risk-register-refresh","capabilities":["erm-risk-identification-register-refresh"],"department":"risk-management","id":"wf:G39","mappingStatus":"mapped","releaseId":"sha256:7833e463a292cf29cc68a8f0103621a5c7a32a0716bc1f98312c1724e186475d","rendered":true,"slug":"grc-risk-register-refresh","sourceTemplateId":"workflow-library:grc-risk-register-refresh","sources":["coso-erm","iso-31000","nist-csf-2"],"teams":["risk-management"],"title":"ERM Risk Identification & Register Refresh","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-enterprise-risk-register-lifecycle","capabilities":[],"department":"risk-management","id":"wf:G4","mappingStatus":"mapped","releaseId":"sha256:c93ca4af1ef0fb0829dc57626fed632b72751eed20f08bb8b59f66e7fa0ac457","rendered":true,"slug":"grc-enterprise-risk-register-lifecycle","sourceTemplateId":"workflow-library:grc-enterprise-risk-register-lifecycle","sources":["coso-erm","iia-pos-2026-erm","iia-pos-2026-three-lines","iso-31000","nist-800-53","nist-csf-2","soc2"],"teams":["risk-management"],"title":"Enterprise Risk Register Lifecycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-system-soc-cuec-review","capabilities":["system-soc-report-cuec-review"],"department":"risk-management","id":"wf:G40","mappingStatus":"mapped","releaseId":"sha256:df3671c86f949c17c967daba333b4b646ed00fc63fc113d19f8a950279dbbfe6","rendered":true,"slug":"grc-system-soc-cuec-review","sourceTemplateId":"workflow-library:grc-system-soc-cuec-review","sources":["soc1"],"teams":["risk-management"],"title":"SOC Report, Subservice & CUEC Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-esg-risk-materiality-integration","capabilities":[],"department":"risk-management","id":"wf:G5","mappingStatus":"mapped","releaseId":"sha256:31ccdbcde94fb4d63b0cdda9a37195c04fe27dc6b59391d2db4d785f34b57409","rendered":true,"slug":"grc-esg-risk-materiality-integration","sourceTemplateId":"workflow-library:grc-esg-risk-materiality-integration","sources":["cobit-2019","coso-erm","coso-ic","iso-27001","iso-31000","nist-800-53","nist-csf-2","soc2"],"teams":["risk-management","executive"],"title":"ESG-Related Risk Materiality & Integration","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-framework-adoption-cross-mapping","capabilities":[],"department":"compliance-legal","id":"wf:G6","mappingStatus":"mapped","releaseId":"sha256:1a62dedf9c3fd637b88064ca3f0909b6746b8c23914c060731d9c9c4acef0250","rendered":true,"slug":"grc-framework-adoption-cross-mapping","sourceTemplateId":"workflow-library:grc-framework-adoption-cross-mapping","sources":["nist-800-53","soc2"],"teams":["compliance-legal","risk-management"],"title":"Framework Adoption & Cross-Mapping","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-incident-management-lifecycle","capabilities":[],"department":"operations","id":"wf:G7","mappingStatus":"mapped","releaseId":"sha256:77c1602449f9eb3f1137db475d9bf0562db8468f039c984fdbba64e37e5a422a","rendered":true,"slug":"grc-incident-management-lifecycle","sourceTemplateId":"workflow-library:grc-incident-management-lifecycle","sources":["cobit-2019","coso-ic","dora","gdpr","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","soc2"],"teams":["operations","it","compliance-legal"],"title":"Incident Management Lifecycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-platform-integration-bridge","capabilities":[],"department":"it","id":"wf:G8","mappingStatus":"mapped","releaseId":"sha256:9d6ffd17fc78a11ed47618dee3281cc83e9d627ec2d01d83b80fbe712a6b007b","rendered":true,"slug":"grc-platform-integration-bridge","sourceTemplateId":"workflow-library:grc-platform-integration-bridge","sources":["iso-27001","soc1","soc2"],"teams":["it","risk-management"],"title":"Enterprise GRC Platform Integration Bridge","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=grc-policy-lifecycle-management","capabilities":[],"department":"compliance-legal","id":"wf:G9","mappingStatus":"mapped","releaseId":"sha256:07f7c6423331d5325e268383c0375b4be4b9e74de04d1df3c1d3bb5ecf4dbbaa","rendered":true,"slug":"grc-policy-lifecycle-management","sourceTemplateId":"workflow-library:grc-policy-lifecycle-management","sources":["coso-ic","hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2","sox"],"teams":["compliance-legal","executive"],"title":"Policy Lifecycle Management","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-compliance-attestation-cycle","capabilities":[],"department":"compliance-legal","id":"wf:R1","mappingStatus":"mapped","releaseId":"sha256:ec89107ef3b241534c7ed1153a3b71287baa28fce8a8fba6b41647569cd08291","rendered":true,"slug":"reg-compliance-attestation-cycle","sourceTemplateId":"workflow-library:reg-compliance-attestation-cycle","sources":["cobit-2019","iso-27001","nis2","nydfs-500","soc2"],"teams":["compliance-legal","executive"],"title":"Regulatory Compliance Attestation Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-personal-data-quality-deidentification","capabilities":[],"department":"privacy","id":"wf:R10","mappingStatus":"mapped","releaseId":"sha256:41e943265957da605901310ca4952729a53a437e317359b1b0dc2c0788e1783a","rendered":true,"slug":"reg-personal-data-quality-deidentification","sourceTemplateId":"workflow-library:reg-personal-data-quality-deidentification","sources":["aiuc-1","ccpa","hipaa","iso-27001","nist-800-53","soc2"],"teams":["privacy"],"title":"Personal Data Quality & De-identification","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-privacy-safeguards-notice-management","capabilities":[],"department":"privacy","id":"wf:R11","mappingStatus":"mapped","releaseId":"sha256:9fc1ed573a4e68d5331016375524eaf9c4bcf19c6c6de67ae968a3a474effd42","rendered":true,"slug":"reg-privacy-safeguards-notice-management","sourceTemplateId":"workflow-library:reg-privacy-safeguards-notice-management","sources":["ccpa","gdpr","hipaa","iso-27001","nist-800-53","soc2"],"teams":["privacy"],"title":"Privacy Safeguards & Notice Management","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-legal-regulatory-compliance-register-evaluation","capabilities":[],"department":"compliance-legal","id":"wf:R12","mappingStatus":"mapped","releaseId":"sha256:f66b649a8d2dd843ce3e4056421808ddaf88d95e9299e98194e32b19a040db10","rendered":true,"slug":"reg-legal-regulatory-compliance-register-evaluation","sourceTemplateId":"workflow-library:reg-legal-regulatory-compliance-register-evaluation","sources":["cobit-2019","iso-27001"],"teams":["compliance-legal"],"title":"Legal & Regulatory Compliance Register Evaluation","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-ai-system-development-data-deployment-gate","capabilities":[],"department":"ai-governance","id":"wf:R13","mappingStatus":"mapped","releaseId":"sha256:5491251bf79dd811f94ee4d46bbb88850559c225c54b7beb93a0921b3b428275","rendered":true,"slug":"reg-ai-system-development-data-deployment-gate","sourceTemplateId":"workflow-library:reg-ai-system-development-data-deployment-gate","sources":["aiuc-1","eu-ai-act","iso-42001","nist-ai-agent-identity","nist-ai-tevv-athlon"],"teams":["ai-governance","it"],"title":"AI System Development, Data & Deployment Gate","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-ai-transparency-value-chain-communications","capabilities":[],"department":"ai-governance","id":"wf:R14","mappingStatus":"mapped","releaseId":"sha256:60cc1c01c83f6e87a9af1c1e666feb0df4473bd01115003eb5d049b0381808b9","rendered":true,"slug":"reg-ai-transparency-value-chain-communications","sourceTemplateId":"workflow-library:reg-ai-transparency-value-chain-communications","sources":["aiuc-1","eu-ai-act","iso-42001"],"teams":["ai-governance","compliance-legal"],"title":"AI Transparency & Value-Chain Communications","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-gpai-model-provider-compliance-cycle","capabilities":[],"department":"ai-governance","id":"wf:R15","mappingStatus":"mapped","releaseId":"sha256:7e427a460ababb62b9c8cfd5ce27abc223cd59cabef347babf2696300e458859","rendered":true,"slug":"reg-gpai-model-provider-compliance-cycle","sourceTemplateId":"workflow-library:reg-gpai-model-provider-compliance-cycle","sources":["eu-ai-act"],"teams":["ai-governance","compliance-legal"],"title":"GPAI Model Provider Compliance Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-privacy-breach-notification","capabilities":[],"department":"privacy","id":"wf:R16","mappingStatus":"mapped","releaseId":"sha256:b6d82ac360dbc52b9d28da072da02bf71b207adfa96d8d8119353ae4692a80e4","rendered":true,"slug":"reg-privacy-breach-notification","sourceTemplateId":"workflow-library:reg-privacy-breach-notification","sources":["coso-ic","gdpr","hipaa","iso-27001","nist-800-53","nist-csf-2","soc2"],"teams":["privacy","it"],"title":"Privacy Breach Assessment & Notification","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-requirement-applicability-mapping","capabilities":["requirement-applicability-control-mapping"],"department":"compliance-legal","id":"wf:R17","mappingStatus":"mapped","releaseId":"sha256:c6a77fafa7954fc1ced64cfa665002a87a264cdd3a24bdbbee9800443523ec9a","rendered":true,"slug":"reg-requirement-applicability-mapping","sourceTemplateId":"workflow-library:reg-requirement-applicability-mapping","sources":["iso-27001","nist-csf-2","nydfs-500"],"teams":["compliance-legal"],"title":"Requirement Applicability & Control Mapping","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-requirement-change-impact","capabilities":["regulatory-change-intake-impact"],"department":"compliance-legal","id":"wf:R18","mappingStatus":"mapped","releaseId":"sha256:f9d7dd896fe1b8d970e7a18a1a27353bda68aa7f6f78f2a54e9194dd7a7c021a","rendered":true,"slug":"reg-requirement-change-impact","sourceTemplateId":"workflow-library:reg-requirement-change-impact","sources":["coso-erm","coso-ic","iso-27001","iso-31000","nist-csf-2","nydfs-500","soc2"],"teams":["compliance-legal"],"title":"Regulatory Change Intake & Impact Assessment","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-requirement-implementation-adoption","capabilities":["obligation-implementation-adoption"],"department":"compliance-legal","id":"wf:R19","mappingStatus":"mapped","releaseId":"sha256:f22940cd7b33f0b669501991899fdb2549bcd7b42a044b520bde26f1c98fd3b9","rendered":true,"slug":"reg-requirement-implementation-adoption","sourceTemplateId":"workflow-library:reg-requirement-implementation-adoption","sources":["iso-27001","nist-csf-2","nydfs-500"],"teams":["compliance-legal"],"title":"Obligation Implementation & Adoption","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-eu-ai-act-impact-analysis","capabilities":[],"department":"ai-governance","id":"wf:R2","mappingStatus":"mapped","releaseId":"sha256:ebe3ad0a90ce6e3b0b4f990739127367ed0dc83b3beaa4ee49d421d7b8f9c3db","rendered":true,"slug":"reg-eu-ai-act-impact-analysis","sourceTemplateId":"workflow-library:reg-eu-ai-act-impact-analysis","sources":["aiuc-1","cobit-2019","coso-erm","coso-ic","eu-ai-act","iso-27001","iso-31000","iso-42001","nist-csf-2","nydfs-500","soc2"],"teams":["ai-governance","compliance-legal"],"title":"EU AI Act Obligation Impact Analysis","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-requirement-monitoring-attestation","capabilities":["compliance-monitoring-attestation"],"department":"compliance-legal","id":"wf:R20","mappingStatus":"mapped","releaseId":"sha256:ad7012c05025dde69c0c869deeeb3928f0ec6ddd9a4919c58063fc8613b0ebbf","rendered":true,"slug":"reg-requirement-monitoring-attestation","sourceTemplateId":"workflow-library:reg-requirement-monitoring-attestation","sources":["iso-27001","nist-csf-2","nydfs-500"],"teams":["compliance-legal"],"title":"Compliance Monitoring & Attestation","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-horizon-scanning-triage","capabilities":[],"department":"compliance-legal","id":"wf:R3","mappingStatus":"mapped","releaseId":"sha256:6a8bf27bfdcd86939da101dae84bfe0394c1e12c5cda148d1d9fc22333700325","rendered":true,"slug":"reg-horizon-scanning-triage","sourceTemplateId":"workflow-library:reg-horizon-scanning-triage","sources":["coso-erm","coso-ic","iso-27001","iso-31000","nist-csf-2","nydfs-500","soc2"],"teams":["compliance-legal"],"title":"Regulatory Horizon Scanning & Triage","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-impact-analysis-obligation-mapping","capabilities":[],"department":"compliance-legal","id":"wf:R4","mappingStatus":"mapped","releaseId":"sha256:552a35d2fabdfd04f46b566e106b4bccaca279a4e3155caf4d281b04b8db71b4","rendered":true,"slug":"reg-impact-analysis-obligation-mapping","sourceTemplateId":"workflow-library:reg-impact-analysis-obligation-mapping","sources":["cobit-2019","coso-erm","coso-ic","iso-27001","iso-31000","nist-800-53","nist-csf-2","nydfs-500","soc2"],"teams":["compliance-legal"],"title":"Regulatory Impact Analysis & Obligation Mapping","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-obligation-implementation","capabilities":[],"department":"compliance-legal","id":"wf:R5","mappingStatus":"mapped","releaseId":"sha256:1d07282aea30741e1be3a50057f444f6ebc5e5cadefc69e1e45d54f762f47f4b","rendered":true,"slug":"reg-obligation-implementation","sourceTemplateId":"workflow-library:reg-obligation-implementation","sources":["hipaa","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc2"],"teams":["compliance-legal"],"title":"Regulatory Obligation Implementation","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-third-party-ict-vendor-assurance","capabilities":[],"department":"procurement","id":"wf:R6","mappingStatus":"mapped","releaseId":"sha256:b4c06cb6a2ba39ca07accbded09c9f8aedbc921ced294ee70b6041ac580956fa","rendered":true,"slug":"reg-third-party-ict-vendor-assurance","sourceTemplateId":"workflow-library:reg-third-party-ict-vendor-assurance","sources":["aiuc-1","cobit-2019","dora","iso-27001","nis2","nist-800-53","nist-csf-2","nydfs-500"],"teams":["procurement","compliance-legal"],"title":"Third-Party ICT Vendor Regulatory Assurance","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-dsar-fulfillment","capabilities":[],"department":"privacy","id":"wf:R7","mappingStatus":"mapped","releaseId":"sha256:8226ebb5176ad52f52c7a5ab46e65466771eac32bed5bc7d88069b47d6aaef39","rendered":true,"slug":"reg-dsar-fulfillment","sourceTemplateId":"workflow-library:reg-dsar-fulfillment","sources":["ccpa","gdpr","hipaa","soc2"],"teams":["privacy"],"title":"DSAR Fulfillment (Access & Deletion Requests)","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-dpia-privacy-impact-assessment","capabilities":[],"department":"privacy","id":"wf:R8","mappingStatus":"mapped","releaseId":"sha256:067c568dd4441d2e2af151c0e54d600bf0756560cae3f64ccce9b450523a9e04","rendered":true,"slug":"reg-dpia-privacy-impact-assessment","sourceTemplateId":"workflow-library:reg-dpia-privacy-impact-assessment","sources":["gdpr","nist-800-53"],"teams":["privacy"],"title":"DPIA / Privacy Impact Assessment","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=reg-privacy-program-operations","capabilities":[],"department":"privacy","id":"wf:R9","mappingStatus":"mapped","releaseId":"sha256:be27ffe0107fb0639209e9259a92dea5e56078e5fa8f797d331def91854a81fa","rendered":true,"slug":"reg-privacy-program-operations","sourceTemplateId":"workflow-library:reg-privacy-program-operations","sources":["ccpa","gdpr","hipaa","nist-800-53","soc2"],"teams":["privacy"],"title":"Privacy Program Operations (Consent, Complaints & Sharing)","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-annual-icfr-scoping-risk-assessment","capabilities":[],"department":"finance","id":"wf:S1","mappingStatus":"mapped","releaseId":"sha256:720fdf4885654c51fb5721af67579fe7802d3bcf7a01e685870295affd52d58e","rendered":true,"slug":"sox-annual-icfr-scoping-risk-assessment","sourceTemplateId":"workflow-library:sox-annual-icfr-scoping-risk-assessment","sources":["coso-erm","coso-ic","iso-31000","nist-800-53","nist-csf-2","nydfs-500","soc2","sox"],"teams":["finance"],"title":"Annual ICFR Scoping & Risk Assessment","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-fraud-risk-assessment-anti-override-control-review","capabilities":[],"department":"finance","id":"wf:S10","mappingStatus":"mapped","releaseId":"sha256:daf2307624b2d1e52a35c50bcb6da717b62f88d54bb41beff571bb9a29757587","rendered":true,"slug":"sox-fraud-risk-assessment-anti-override-control-review","sourceTemplateId":"workflow-library:sox-fraud-risk-assessment-anti-override-control-review","sources":["coso-ic","soc2","sox"],"teams":["finance","executive"],"title":"Fraud Risk Assessment & Anti-Override Control Review","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-financial-controls-policy-segregation-of-duties","capabilities":[],"department":"finance","id":"wf:S11","mappingStatus":"mapped","releaseId":"sha256:6b32637212d2ff1458758420c2f6d3363003ac55edee441699e1cb6d539f45c3","rendered":true,"slug":"sox-financial-controls-policy-segregation-of-duties","sourceTemplateId":"workflow-library:sox-financial-controls-policy-segregation-of-duties","sources":["sox"],"teams":["finance"],"title":"Financial Controls Policy & Segregation-of-Duties Governance","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-financial-systems-transaction-integrity-monitoring","capabilities":[],"department":"finance","id":"wf:S12","mappingStatus":"mapped","releaseId":"sha256:8bb0b7cccad61b8cb4ef25c21e62649e2f2dc93983cdd11756dcf9ef0fdbd10a","rendered":true,"slug":"sox-financial-systems-transaction-integrity-monitoring","sourceTemplateId":"workflow-library:sox-financial-systems-transaction-integrity-monitoring","sources":["soc2","sox"],"teams":["finance","it"],"title":"Financial Systems Transaction Integrity Monitoring","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-physical-asset-custody-count-program","capabilities":[],"department":"finance","id":"wf:S13","mappingStatus":"mapped","releaseId":"sha256:726b59341fce0a43fd2afaf59a183ec7403481ce70c1016f6e16704fa5e7efe6","rendered":true,"slug":"sox-physical-asset-custody-count-program","sourceTemplateId":"workflow-library:sox-physical-asset-custody-count-program","sources":["soc2","sox"],"teams":["finance","facilities"],"title":"Physical Asset Custody & Count Program","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-production-operations-processing-integrity-cycle","capabilities":[],"department":"it","id":"wf:S15","mappingStatus":"mapped","releaseId":"sha256:8dd7743ee60dc1390b3fc9610358d4d11a39542f3ef83c52bf6892a9312df2f3","rendered":true,"slug":"sox-production-operations-processing-integrity-cycle","sourceTemplateId":"workflow-library:sox-production-operations-processing-integrity-cycle","sources":["iso-27001","nist-csf-2","soc1"],"teams":["it","finance"],"title":"Production Operations & Processing Integrity Cycle","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-deficiency-aggregation-evaluation","capabilities":[],"department":"finance","id":"wf:S16","mappingStatus":"mapped","releaseId":"sha256:e44e2152e93d96eb220e7ce001a04754f0a770e2bac48d1e711e634c9ff66c45","rendered":true,"slug":"sox-deficiency-aggregation-evaluation","sourceTemplateId":"workflow-library:sox-deficiency-aggregation-evaluation","sources":["cobit-2019","coso-erm","coso-ic","iia-2024","nist-800-53","nist-csf-2","soc2","sox"],"teams":["finance"],"title":"Year-End Deficiency Aggregation & Severity Evaluation","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-subcertification-cascade","capabilities":[],"department":"finance","id":"wf:S17","mappingStatus":"mapped","releaseId":"sha256:76943fa4fdeeb5deb71fbefc885cc9ef49c56ea1487e95d3fa44d89f1c8b0bd4","rendered":true,"slug":"sox-subcertification-cascade","sourceTemplateId":"workflow-library:sox-subcertification-cascade","sources":["cobit-2019","coso-erm","coso-ic","iso-27001","nist-800-53","soc2"],"teams":["finance","executive"],"title":"Quarterly 302/906 Sub-Certification Cascade","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-annual-program-planning","capabilities":["sox-annual-planning"],"department":"finance","id":"wf:S18","mappingStatus":"mapped","releaseId":"sha256:b75bd14e0152fe649923987ad463dcbb0ac52c7904f707221db82b724a0b7c21","rendered":true,"slug":"sox-annual-program-planning","sourceTemplateId":"workflow-library:sox-annual-program-planning","sources":["iia-2024"],"teams":["finance"],"title":"SOX Annual Planning & Risk Assessment","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-control-interim-testing-record","capabilities":["control-interim-operating-effectiveness"],"department":"internal-audit","id":"wf:S19","mappingStatus":"mapped","releaseId":"sha256:cb4c34235cdea8a9a40278dfe2430ef89c9e9a0ba0f2f90559e966b70cd69962","rendered":true,"slug":"sox-control-interim-testing-record","sourceTemplateId":"workflow-library:sox-control-interim-testing-record","sources":["cobit-2019","coso-ic","nist-800-53","sox"],"teams":["internal-audit"],"title":"Control Interim Testing Record","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-control-roll-forward-record","capabilities":["control-period-end-roll-forward"],"department":"internal-audit","id":"wf:S20","mappingStatus":"mapped","releaseId":"sha256:4629f99823a0eccb411bc98fe622012736cabfee5444dfafba974e39a27e1a57","rendered":true,"slug":"sox-control-roll-forward-record","sourceTemplateId":"workflow-library:sox-control-roll-forward-record","sources":["cobit-2019","coso-ic","nist-800-53","sox"],"teams":["internal-audit"],"title":"Period-End Roll-Forward / Rollover Testing","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-control-testing-publication","capabilities":["sox-control-testing","audit-testing"],"department":"internal-audit","id":"wf:S21","mappingStatus":"mapped","releaseId":"sha256:6a9a2b6740664366edac822192a3264e04a764e662b3a0277aba2229cc0360af","rendered":true,"slug":"sox-control-testing-publication","sourceTemplateId":"workflow-library:sox-control-testing-publication","sources":["cobit-2019","coso-ic","nist-800-53","sox"],"teams":["internal-audit"],"title":"SOX Control Testing","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-external-audit-pbc-request","capabilities":["sox-pbc"],"department":"finance","id":"wf:S22","mappingStatus":"mapped","releaseId":"sha256:6d0a661e3761f8a35e5eabfafee0b91603106a4739bfef76aa1f1ece69e90de4","rendered":true,"slug":"sox-external-audit-pbc-request","sourceTemplateId":"workflow-library:sox-external-audit-pbc-request","sources":["iso-27001","soc2"],"teams":["finance"],"title":"External Audit Support & PBC","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-fsli-significance-assessment","capabilities":["fsli-significance-assessment"],"department":"finance","id":"wf:S23","mappingStatus":"mapped","releaseId":"sha256:5f78d183e1b302ffe31fc7b71d24dc5da14a19bbfd72cfd6548b24048722489a","rendered":true,"slug":"sox-fsli-significance-assessment","sourceTemplateId":"workflow-library:sox-fsli-significance-assessment","sources":["coso-erm","iso-31000","nist-csf-2"],"teams":["finance"],"title":"FSLI Significance Assessment","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-management-assessment-assertion","capabilities":["sox-mgmt-assessment"],"department":"finance","id":"wf:S24","mappingStatus":"mapped","releaseId":"sha256:32b1feec1a1316d8be4799202977bff12a5ed7f20f205ae62f4abe2a98b6d6fd","rendered":true,"slug":"sox-management-assessment-assertion","sourceTemplateId":"workflow-library:sox-management-assessment-assertion","sources":["cobit-2019","coso-erm","coso-ic","soc2"],"teams":["finance"],"title":"Management Assessment & Assertion","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-process-walkthrough-record","capabilities":["sox-walkthrough"],"department":"internal-audit","id":"wf:S25","mappingStatus":"mapped","releaseId":"sha256:621ef23bd7c6a261cfd5298e9c12006351f094d749127f381b1dffd5e363d644","rendered":true,"slug":"sox-process-walkthrough-record","sourceTemplateId":"workflow-library:sox-process-walkthrough-record","sources":["cobit-2019","coso-ic","nist-800-53","sox"],"teams":["internal-audit"],"title":"Process Walkthrough & Design Assessment","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-program-deficiency-committee-review","capabilities":["sox-deficiency-eval"],"department":"finance","id":"wf:S26","mappingStatus":"mapped","releaseId":"sha256:20b0f1a39cb19973e76827f07005d4b06432a3f32ff85b840339bcdbe906b7d9","rendered":true,"slug":"sox-program-deficiency-committee-review","sourceTemplateId":"workflow-library:sox-program-deficiency-committee-review","sources":["cobit-2019","coso-erm","coso-ic","nist-800-53","soc2"],"teams":["finance"],"title":"Deficiency Evaluation & Committee","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-year-end-program-planning","capabilities":["sox-ye-planning"],"department":"finance","id":"wf:S27","mappingStatus":"mapped","releaseId":"sha256:eb8302bd744d5bb8ac6bbf9ebe917b0f55eb636ee043e4f26a82ba412c63ae59","rendered":true,"slug":"sox-year-end-program-planning","sourceTemplateId":"workflow-library:sox-year-end-program-planning","sources":["iia-2024"],"teams":["finance"],"title":"Year-End Planning & Roll-Forward","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-deficiency-remediation","capabilities":[],"department":"finance","id":"wf:S3","mappingStatus":"mapped","releaseId":"sha256:8b3fcc0e9ec08f3b44dfc9cfbb44cf2d57ce6a0729c257e1de8142822e4212df","rendered":true,"slug":"sox-deficiency-remediation","sourceTemplateId":"workflow-library:sox-deficiency-remediation","sources":["iia-2024","nist-800-53","nist-csf-2","soc2"],"teams":["finance"],"title":"SOX Deficiency Remediation","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-ipe-validation","capabilities":[],"department":"internal-audit","id":"wf:S4","mappingStatus":"mapped","releaseId":"sha256:51cfc7bd7a4f244e2478b5c44f256f648735995ccef48c11995f306b73e6e40f","rendered":true,"slug":"sox-ipe-validation","sourceTemplateId":"workflow-library:sox-ipe-validation","sources":["iia-2024","soc2","sox"],"teams":["internal-audit","finance"],"title":"SOX IPE Validation","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-itgc-testing","capabilities":[],"department":"internal-audit","id":"wf:S5","mappingStatus":"mapped","releaseId":"sha256:eaebf4d5b6fbbc31ce2e6cc4908a6af39aeb6d2a3e5494135f364962e96fd19a","rendered":true,"slug":"sox-itgc-testing","sourceTemplateId":"workflow-library:sox-itgc-testing","sources":["aiuc-1","cobit-2019","coso-ic","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","soc1","soc2","sox"],"teams":["internal-audit","it","finance"],"title":"SOX ITGC Testing","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-key-control-tod-toe-test","capabilities":[],"department":"internal-audit","id":"wf:S6","mappingStatus":"mapped","releaseId":"sha256:8f06171750e61dd0269bfcc6968910fe46768d003ca2c581fc617c39ef1fff42","rendered":true,"slug":"sox-key-control-tod-toe-test","sourceTemplateId":"workflow-library:sox-key-control-tod-toe-test","sources":["cobit-2019","coso-ic","nist-800-53","soc2","sox"],"teams":["internal-audit","finance"],"title":"SOX Key Control TOD/TOE Test","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-scoping-decision","capabilities":[],"department":"finance","id":"wf:S7","mappingStatus":"mapped","releaseId":"sha256:998fa0fa624dc515ce92355a407983ccc609a84b1a5d73bfdd40f6d63f6db11f","rendered":true,"slug":"sox-scoping-decision","sourceTemplateId":"workflow-library:sox-scoping-decision","sources":["coso-erm","coso-ic","iso-31000","nist-csf-2","soc2"],"teams":["finance"],"title":"SOX Scoping Decision","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-walkthrough","capabilities":[],"department":"finance","id":"wf:S8","mappingStatus":"mapped","releaseId":"sha256:4101b1b96bb5de07faf7ed2dca53bb57b8bb08318564ae7f48a0d60671344586","rendered":true,"slug":"sox-walkthrough","sourceTemplateId":"workflow-library:sox-walkthrough","sources":["cobit-2019","coso-ic","iia-2024","nist-800-53","sox"],"teams":["finance","internal-audit"],"title":"SOX Process Walkthrough","type":"workflow"},{"canonicalUrl":"https://workflow-library.com/all/?w=sox-key-control-operation","capabilities":[],"department":"finance","id":"wf:S9","mappingStatus":"mapped","releaseId":"sha256:679d0d95a23910b4e09daa881a7f83c38e65960524b8db9d9adbae2eb08348f6","rendered":true,"slug":"sox-key-control-operation","sourceTemplateId":"workflow-library:sox-key-control-operation","sources":["cobit-2019","iso-27001","nist-800-53","soc2","sox"],"teams":["finance"],"title":"SOX Key Control Operation (Close Cycle)","type":"workflow"}],"revision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","version":1}