unified
UC-GOV-24 — Notify regulators of incidents and file required certifications
Maintain documented procedures to notify supervisory and regulatory bodies of reportable cybersecurity events within mandated regulatory timelines, including any staged early-warning, detailed-notification, and final-report deadlines, and to submit required periodic compliance certifications and filings. Handle regulatory submissions and related materials confidentially, and retain evidence of all notifications, certifications, and supporting records.
In catalog since 2026-09-17T22:28:00Z · Last changed 2026-09-17T22:28:00Z (f368a6cce277)
Record JSON · Open in map · Data retrieval guide
Catalog revision: 791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- corrective
- category
- administrative
Details
- unified_id
- UC-GOV-24
- title
- Notify regulators of incidents and file required certifications
- statement
- Maintain documented procedures to notify supervisory and regulatory bodies of reportable cybersecurity events within mandated regulatory timelines, including any staged early-warning, detailed-notification, and final-report deadlines, and to submit required periodic compliance certifications and filings. Handle regulatory submissions and related materials confidentially, and retain evidence of all notifications, certifications, and supporting records.
- domain
- Governance, Policy & Oversight
- control_type
- corrective
- control_category
- administrative
- members
- framework
- nydfs-500
- control_id
- 500.17
- coverage
- full
- relationship
- superset_of
- framework
- nis2
- control_id
- NIS2-Art23
- coverage
- partial
- delta
- staged deadlines (early warning 24h, notification 72h, final report within one month); Art 23 also requires notifying service recipients of significant incidents and threat remedies
- relationship
- intersects_with
- framework
- nydfs-500
- control_id
- 500.18
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-GOV-24 — Notify regulators of incidents and file required certifications mitigates Litigation, investigation and enforcement exposure
- strength
- primary
- rationale
- Notifying regulators within mandated timelines and filing required certifications avoids penalties for late or missing regulatory reporting.
- UC-GOV-24 — Notify regulators of incidents and file required certifications mitigates Brand and reputational crisis
- strength
- related
- rationale
- Timely, proper incident notification limits the reputational fallout of mishandled disclosure.
- UC-GOV-24 — Notify regulators of incidents and file required certifications maps_to 500.17 — Notices to superintendent (incident notification and annual certification)
- framework
- nydfs-500
- control_id
- 500.17
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-24 — Notify regulators of incidents and file required certifications maps_to NIS2-Art23 — Reporting obligations (early warning 24h, incident notification 72h, final report 1 month)
- framework
- nis2
- control_id
- NIS2-Art23
- coverage
- partial
- delta
- staged deadlines (early warning 24h, notification 72h, final report within one month); Art 23 also requires notifying service recipients of significant incidents and threat remedies
- relationship
- intersects_with
- source_version
- Directive (EU) 2022/2555
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-24 — Notify regulators of incidents and file required certifications maps_to 500.18 — Confidentiality
- framework
- nydfs-500
- control_id
- 500.18
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 23 NYCRR 500, Second Amendment
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Incident Management Lifecycle operates UC-GOV-24 — Notify regulators of incidents and file required certifications
- Regulatory Compliance Attestation Cycle oversees UC-GOV-24 — Notify regulators of incidents and file required certifications