{"catalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","contextIds":[],"directIds":["ctrl:nist-csf-2:DE.AE-02","ctrl:nist-csf-2:DE.AE-03","ctrl:nist-csf-2:DE.AE-04","ctrl:nist-csf-2:DE.AE-06","ctrl:nist-csf-2:DE.AE-07","ctrl:nist-csf-2:DE.AE-08","ctrl:nist-csf-2:DE.CM-01","ctrl:nist-csf-2:DE.CM-02","ctrl:nist-csf-2:DE.CM-03","ctrl:nist-csf-2:DE.CM-06","ctrl:nist-csf-2:DE.CM-09","ctrl:nist-csf-2:GV.OC-01","ctrl:nist-csf-2:GV.OC-02","ctrl:nist-csf-2:GV.OC-03","ctrl:nist-csf-2:GV.OC-04","ctrl:nist-csf-2:GV.OC-05","ctrl:nist-csf-2:GV.OV-01","ctrl:nist-csf-2:GV.OV-02","ctrl:nist-csf-2:GV.OV-03","ctrl:nist-csf-2:GV.PO-01","ctrl:nist-csf-2:GV.PO-02","ctrl:nist-csf-2:GV.RM-01","ctrl:nist-csf-2:GV.RM-02","ctrl:nist-csf-2:GV.RM-03","ctrl:nist-csf-2:GV.RM-04","ctrl:nist-csf-2:GV.RM-05","ctrl:nist-csf-2:GV.RM-06","ctrl:nist-csf-2:GV.RM-07","ctrl:nist-csf-2:GV.RR-01","ctrl:nist-csf-2:GV.RR-02","ctrl:nist-csf-2:GV.RR-03","ctrl:nist-csf-2:GV.RR-04","ctrl:nist-csf-2:GV.SC-01","ctrl:nist-csf-2:GV.SC-02","ctrl:nist-csf-2:GV.SC-03","ctrl:nist-csf-2:GV.SC-04","ctrl:nist-csf-2:GV.SC-05","ctrl:nist-csf-2:GV.SC-06","ctrl:nist-csf-2:GV.SC-07","ctrl:nist-csf-2:GV.SC-08"],"kind":"bundle","metadata":"/assets/agent_metadata.84eaa456936e4fa1.json","name":"NIST CSF 2.0","next":"/assets/agent_sources-nist-csf-2-2.677f1cad6980d20a.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"technical","framework":"nist-csf-2","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Adverse Event Analysis: Potentially adverse events are analyzed to better understand associated activities","details":{"automation":"hybrid","control_category":"technical","control_id":"DE.AE-02","control_type":"detective","domains":["Logging, Monitoring & Detection"],"framework":"nist-csf-2","group":"Detect","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"03b2cb5784552edc7fdc79ba5ce4de83bcb40482e87cd797ff39151e0ac67b9d","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-de-ae-02-1f4071e1.html","id":"ctrl:nist-csf-2:DE.AE-02","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3ADE.AE-02","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"DE.AE-02 — Adverse Event Analysis: Potentially adverse events are analyzed to better understand associated activities","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-de-ae-02-1f4071e1.05549c5a2a1fee38.json"},{"attributes":{"category":"technical","framework":"nist-csf-2","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Adverse Event Analysis: Information is correlated from multiple sources","details":{"automation":"automated","control_category":"technical","control_id":"DE.AE-03","control_type":"detective","domains":["Logging, Monitoring & Detection"],"framework":"nist-csf-2","group":"Detect","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"5d8a746dc446a9e20742774dda0712a58f18eca7e33c666c691db78e6b9ca252","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-de-ae-03-f45e152f.html","id":"ctrl:nist-csf-2:DE.AE-03","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3ADE.AE-03","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"DE.AE-03 — Adverse Event Analysis: Information is correlated from multiple sources","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-de-ae-03-f45e152f.8b18646eaf49d2e2.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Adverse Event Analysis: The estimated impact and scope of adverse events are understood","details":{"automation":"manual","control_category":"administrative","control_id":"DE.AE-04","control_type":"detective","domains":["Incident Management & Response"],"framework":"nist-csf-2","group":"Detect","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"ccc4bf558849606a97bcb34c3e1d5f52014d38fd82352de9d9ad4ed115b30b3a","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-de-ae-04-186bb6c1.html","id":"ctrl:nist-csf-2:DE.AE-04","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3ADE.AE-04","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"DE.AE-04 — Adverse Event Analysis: The estimated impact and scope of adverse events are understood","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-de-ae-04-186bb6c1.0fcab38514ca41a7.json"},{"attributes":{"category":"technical","framework":"nist-csf-2","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Adverse Event Analysis: Information on adverse events is provided to authorized staff and tools","details":{"automation":"automated","control_category":"technical","control_id":"DE.AE-06","control_type":"detective","domains":["Logging, Monitoring & Detection"],"framework":"nist-csf-2","group":"Detect","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"aa9f26568f906e4c100476461078218b6cdc8a29b1dd26c74c4ad6bde2a42d24","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-de-ae-06-88d06373.html","id":"ctrl:nist-csf-2:DE.AE-06","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3ADE.AE-06","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"DE.AE-06 — Adverse Event Analysis: Information on adverse events is provided to authorized staff and tools","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-de-ae-06-88d06373.4eec8c6ebbcc2321.json"},{"attributes":{"category":"technical","framework":"nist-csf-2","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Adverse Event Analysis: Cyber threat intelligence and other contextual information are integrated into the analysis","details":{"automation":"hybrid","control_category":"technical","control_id":"DE.AE-07","control_type":"detective","domains":["Logging, Monitoring & Detection","Incident Management & Response"],"framework":"nist-csf-2","group":"Detect","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"1b7ef62e6456bb0f7adcdd373e0d764914698bfb5d236a1d291fb73db10f382d","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-de-ae-07-a597b302.html","id":"ctrl:nist-csf-2:DE.AE-07","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3ADE.AE-07","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"DE.AE-07 — Adverse Event Analysis: Cyber threat intelligence and other contextual information are integrated into the analysis","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-de-ae-07-a597b302.8b5ee86cb7bb4e52.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Adverse Event Analysis: Incidents are declared when adverse events meet the defined incident criteria","details":{"automation":"manual","control_category":"administrative","control_id":"DE.AE-08","control_type":"detective","domains":["Logging, Monitoring & Detection"],"framework":"nist-csf-2","group":"Detect","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"009ad2f181ecfa517f1d40d2471724f8431eb082df637cde61d37d61ee559155","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-de-ae-08-67efb705.html","id":"ctrl:nist-csf-2:DE.AE-08","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3ADE.AE-08","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"DE.AE-08 — Adverse Event Analysis: Incidents are declared when adverse events meet the defined incident criteria","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-de-ae-08-67efb705.da64bc106780967e.json"},{"attributes":{"category":"technical","framework":"nist-csf-2","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Continuous Monitoring: Networks and network services are monitored to find potentially adverse events","details":{"automation":"automated","control_category":"technical","control_id":"DE.CM-01","control_type":"detective","domains":["Logging, Monitoring & Detection","Network & Communications Security"],"framework":"nist-csf-2","group":"Detect","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"8dff46c1ff1d48e8504d48659414f56f538bfd1929ccb08fe19b9ad6927f4297","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-de-cm-01-5a17881e.html","id":"ctrl:nist-csf-2:DE.CM-01","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3ADE.CM-01","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"DE.CM-01 — Continuous Monitoring: Networks and network services are monitored to find potentially adverse events","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-de-cm-01-5a17881e.1dadaf2df7c73dbe.json"},{"attributes":{"category":"physical","framework":"nist-csf-2","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Continuous Monitoring: The physical environment is monitored to find potentially adverse events","details":{"automation":"hybrid","control_category":"physical","control_id":"DE.CM-02","control_type":"detective","domains":["Logging, Monitoring & Detection"],"framework":"nist-csf-2","group":"Detect","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"b45ca7ea814aaea4ec3d635c875fdca9f6c4899fbd01d12499193cf658731b62","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-de-cm-02-96e890cb.html","id":"ctrl:nist-csf-2:DE.CM-02","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3ADE.CM-02","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"DE.CM-02 — Continuous Monitoring: The physical environment is monitored to find potentially adverse events","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-de-cm-02-96e890cb.3e6d0fd7980769e8.json"},{"attributes":{"category":"technical","framework":"nist-csf-2","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Continuous Monitoring: Personnel activity and technology usage are monitored to find potentially adverse events","details":{"automation":"automated","control_category":"technical","control_id":"DE.CM-03","control_type":"detective","domains":["Logging, Monitoring & Detection"],"framework":"nist-csf-2","group":"Detect","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"f47a5bcc135319858f8fba5808aebe3c2c67b2c241ae6cf275719ae61125fceb","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-de-cm-03-9f258e61.html","id":"ctrl:nist-csf-2:DE.CM-03","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3ADE.CM-03","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"DE.CM-03 — Continuous Monitoring: Personnel activity and technology usage are monitored to find potentially adverse events","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-de-cm-03-9f258e61.04705b2dcf2f97d4.json"},{"attributes":{"category":"technical","framework":"nist-csf-2","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Continuous Monitoring: External service provider activities and services are monitored to find potentially adverse events","details":{"automation":"hybrid","control_category":"technical","control_id":"DE.CM-06","control_type":"detective","domains":["Logging, Monitoring & Detection"],"framework":"nist-csf-2","group":"Detect","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"a229810482b6ff67494b93d8384b94bd4427ec36700066f44b5ca29fe6dfb101","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-de-cm-06-241a1dc5.html","id":"ctrl:nist-csf-2:DE.CM-06","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3ADE.CM-06","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"DE.CM-06 — Continuous Monitoring: External service provider activities and services are monitored to find potentially adverse events","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-de-cm-06-241a1dc5.99bf2d31d1754a9f.json"},{"attributes":{"category":"technical","framework":"nist-csf-2","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Continuous Monitoring: Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events","details":{"automation":"automated","control_category":"technical","control_id":"DE.CM-09","control_type":"detective","domains":["Logging, Monitoring & Detection","Vulnerability & Patch Management"],"framework":"nist-csf-2","group":"Detect","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"af04bd5deedb2e5b3e5bdb3272cc584aea85c780bbab2433498d69fca972ed50","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-de-cm-09-e2e2548a.html","id":"ctrl:nist-csf-2:DE.CM-09","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3ADE.CM-09","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"DE.CM-09 — Continuous Monitoring: Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-de-cm-09-e2e2548a.ca83f1fbea46b834.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Organizational Context: The organizational mission is understood and informs cybersecurity risk management","details":{"automation":"manual","control_category":"administrative","control_id":"GV.OC-01","control_type":"preventive","domains":["Governance, Policy & Oversight"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"35388ee26b35c3a1a87038135045ed543d3748d64e3ca9f8c780cb8a30fc1717","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-oc-01-e996c461.html","id":"ctrl:nist-csf-2:GV.OC-01","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.OC-01","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.OC-01 — Organizational Context: The organizational mission is understood and informs cybersecurity risk management","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-oc-01-e996c461.57b138336e3f7ad3.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Organizational Context: Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered","details":{"automation":"manual","control_category":"administrative","control_id":"GV.OC-02","control_type":"preventive","domains":["Governance, Policy & Oversight"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"ef4e1eaea14737e33441c687a21bcf9c82854d34a723e634b7c21cb0e9960b47","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-oc-02-84d81944.html","id":"ctrl:nist-csf-2:GV.OC-02","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.OC-02","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.OC-02 — Organizational Context: Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-oc-02-84d81944.3fccef6199d4db07.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Organizational Context: Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed","details":{"automation":"manual","control_category":"administrative","control_id":"GV.OC-03","control_type":"preventive","domains":["AI Governance","Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"2c9bc9b307fbe5a6b7a75cf2191e6ab06ea3d6b5f9b3c3aaaaaf7132f7295d75","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-oc-03-325aeeeb.html","id":"ctrl:nist-csf-2:GV.OC-03","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.OC-03","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.OC-03 — Organizational Context: Legal, regulatory, and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-oc-03-325aeeeb.36d2308f5275f54e.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Organizational Context: Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated","details":{"automation":"manual","control_category":"administrative","control_id":"GV.OC-04","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Third-Party / Supply-Chain Risk","Compliance, Audit & Assurance"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"7d396205882052bdd8c02375d146d451f5a591c3407992ec20fe5b4c9335406f","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-oc-04-da71308a.html","id":"ctrl:nist-csf-2:GV.OC-04","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.OC-04","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.OC-04 — Organizational Context: Critical objectives, capabilities, and services that external stakeholders depend on or expect from the organization are understood and communicated","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-oc-04-da71308a.25727338fb81dfb9.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Organizational Context: Outcomes, capabilities, and services that the organization depends on are understood and communicated","details":{"automation":"manual","control_category":"administrative","control_id":"GV.OC-05","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Third-Party / Supply-Chain Risk","Compliance, Audit & Assurance"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"5e6721767a2116c94b7cf8e3cb063420a462df75c11f3afd3b2667df5831c75e","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-oc-05-abe265e5.html","id":"ctrl:nist-csf-2:GV.OC-05","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.OC-05","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.OC-05 — Organizational Context: Outcomes, capabilities, and services that the organization depends on are understood and communicated","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-oc-05-abe265e5.db4c03497e2c62f9.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Oversight: Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction","details":{"automation":"manual","control_category":"administrative","control_id":"GV.OV-01","control_type":"detective","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"809173c72700c976a588442e9947974320191da8ed5bf1dce7d335f1f1b26548","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-ov-01-19ee87a8.html","id":"ctrl:nist-csf-2:GV.OV-01","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.OV-01","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.OV-01 — Oversight: Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-ov-01-19ee87a8.30540ef97877ad19.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Oversight: The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks","details":{"automation":"manual","control_category":"administrative","control_id":"GV.OV-02","control_type":"detective","domains":["Compliance, Audit & Assurance"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"946f251cd0ff93780254e44d44ba93a02f7def73c43e29a0bab35cd0050f263f","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-ov-02-d7467a40.html","id":"ctrl:nist-csf-2:GV.OV-02","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.OV-02","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.OV-02 — Oversight: The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-ov-02-d7467a40.512c81bed19e59d5.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Oversight: Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed","details":{"automation":"manual","control_category":"administrative","control_id":"GV.OV-03","control_type":"detective","domains":["Compliance, Audit & Assurance"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"cc8219ffe2106627a229e1b9a8ea5c23b55d5472d9ec5e450300aafc9fd1d913","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-ov-03-fc445da9.html","id":"ctrl:nist-csf-2:GV.OV-03","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.OV-03","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.OV-03 — Oversight: Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-ov-03-fc445da9.572afa0fb58b831f.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Policy: Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced","details":{"automation":"manual","control_category":"administrative","control_id":"GV.PO-01","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"5392bda6a24510ce188ce3296371a2a2d850bacfb5968d41de82df0b1c7caee9","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-po-01-e8b931a8.html","id":"ctrl:nist-csf-2:GV.PO-01","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.PO-01","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.PO-01 — Policy: Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy, and priorities and is communicated and enforced","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-po-01-e8b931a8.13b58a36e83502a5.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Policy: Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission","details":{"automation":"manual","control_category":"administrative","control_id":"GV.PO-02","control_type":"preventive","domains":["Governance, Policy & Oversight"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"9390f714fea0542346c7aac76174f2b02a4fa930c370ce0dc89cfd24a93177ed","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-po-02-4745ed81.html","id":"ctrl:nist-csf-2:GV.PO-02","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.PO-02","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.PO-02 — Policy: Policy for managing cybersecurity risks is reviewed, updated, communicated, and enforced to reflect changes in requirements, threats, technology, and organizational mission","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-po-02-4745ed81.af666395898ac249.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Risk Management Strategy: Risk management objectives are established and agreed to by organizational stakeholders","details":{"automation":"manual","control_category":"administrative","control_id":"GV.RM-01","control_type":"preventive","domains":["AI Governance","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"adc74c94ca753aefad0a5b6ac0cf4775f693692b862f4adb7708521b18c5a5ff","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-rm-01-a04dd496.html","id":"ctrl:nist-csf-2:GV.RM-01","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.RM-01","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.RM-01 — Risk Management Strategy: Risk management objectives are established and agreed to by organizational stakeholders","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-rm-01-a04dd496.4e8c209b6fdf2df0.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Risk Management Strategy: Risk appetite and risk tolerance statements are established, communicated, and maintained","details":{"automation":"manual","control_category":"administrative","control_id":"GV.RM-02","control_type":"preventive","domains":["Risk Assessment & Management"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"4f325686285f5331be7ebfed5653bed2aa38aed5096aa85826b302e819196958","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-rm-02-5a997df0.html","id":"ctrl:nist-csf-2:GV.RM-02","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.RM-02","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.RM-02 — Risk Management Strategy: Risk appetite and risk tolerance statements are established, communicated, and maintained","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-rm-02-5a997df0.86e1f0d7f7a68905.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Risk Management Strategy: Cybersecurity risk management activities and outcomes are included in enterprise risk management processes","details":{"automation":"manual","control_category":"administrative","control_id":"GV.RM-03","control_type":"preventive","domains":["Risk Assessment & Management"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"cc5a91ef76184aa994f1469deb30627086d4375b0620bb559547a1360d759594","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-rm-03-4891faf8.html","id":"ctrl:nist-csf-2:GV.RM-03","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.RM-03","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.RM-03 — Risk Management Strategy: Cybersecurity risk management activities and outcomes are included in enterprise risk management processes","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-rm-03-4891faf8.0cf07b92195d494e.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Risk Management Strategy: Strategic direction that describes appropriate risk response options is established and communicated","details":{"automation":"manual","control_category":"administrative","control_id":"GV.RM-04","control_type":"preventive","domains":["Risk Assessment & Management"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"96e17df7b7ecd3678c1e59c89dc6d377f8976aec4fdfee0672db5e6ca2732976","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-rm-04-a64cbb61.html","id":"ctrl:nist-csf-2:GV.RM-04","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.RM-04","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.RM-04 — Risk Management Strategy: Strategic direction that describes appropriate risk response options is established and communicated","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-rm-04-a64cbb61.c732a246d7318757.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Risk Management Strategy: Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties","details":{"automation":"manual","control_category":"administrative","control_id":"GV.RM-05","control_type":"preventive","domains":["Risk Assessment & Management"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"1919f505186498d28694b96628d08736da80b595f3093a0f2126076793ef6422","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-rm-05-d4ec8a45.html","id":"ctrl:nist-csf-2:GV.RM-05","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.RM-05","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.RM-05 — Risk Management Strategy: Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-rm-05-d4ec8a45.0227d53ce7848c39.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Risk Management Strategy: A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated","details":{"automation":"manual","control_category":"administrative","control_id":"GV.RM-06","control_type":"preventive","domains":["Risk Assessment & Management"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"7f2cb5361681459b5e09a7b05de3cc02b6f4e92c4642c2d4325f0d1fc6948a4c","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-rm-06-aa913e7b.html","id":"ctrl:nist-csf-2:GV.RM-06","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.RM-06","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.RM-06 — Risk Management Strategy: A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-rm-06-aa913e7b.eac7b06e56e2aaba.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Risk Management Strategy: Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions","details":{"automation":"manual","control_category":"administrative","control_id":"GV.RM-07","control_type":"preventive","domains":["Risk Assessment & Management"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"365f85b885765b6e2efebef1cd21a49c0bc4aac7f28482fb7ced611eb4d7dc1d","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-rm-07-715f6bd4.html","id":"ctrl:nist-csf-2:GV.RM-07","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.RM-07","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.RM-07 — Risk Management Strategy: Strategic opportunities (i.e., positive risks) are characterized and are included in organizational cybersecurity risk discussions","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-rm-07-715f6bd4.e75067ee7918334e.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Roles, Responsibilities, and Authorities: Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving","details":{"automation":"manual","control_category":"administrative","control_id":"GV.RR-01","control_type":"preventive","domains":["Governance, Policy & Oversight"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"2c10ca9c97e1e5cbaf300361ffa4427c516ba15920ee048d8bd2510e03d8d7b1","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-rr-01-011a9146.html","id":"ctrl:nist-csf-2:GV.RR-01","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.RR-01","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.RR-01 — Roles, Responsibilities, and Authorities: Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-rr-01-011a9146.fe854a432c9bfdc2.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Roles, Responsibilities, and Authorities: Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced","details":{"automation":"manual","control_category":"administrative","control_id":"GV.RR-02","control_type":"preventive","domains":["Financial Reporting Controls (SOX)","Governance, Policy & Oversight"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"3347b9c417c58f0bdf702b394d4dac998e156571f5330f0d82d1b435b82a564f","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-rr-02-fa51dc97.html","id":"ctrl:nist-csf-2:GV.RR-02","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.RR-02","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.RR-02 — Roles, Responsibilities, and Authorities: Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-rr-02-fa51dc97.399c342a7c589b67.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Roles, Responsibilities, and Authorities: Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies","details":{"automation":"manual","control_category":"administrative","control_id":"GV.RR-03","control_type":"preventive","domains":["Governance, Policy & Oversight"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"4812b8f7062bc4cf418c7a51dcdbe484ac701ea8393887e2516b212bbfa09829","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-rr-03-f8d87e54.html","id":"ctrl:nist-csf-2:GV.RR-03","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.RR-03","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.RR-03 — Roles, Responsibilities, and Authorities: Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities, and policies","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-rr-03-f8d87e54.3608973c9d9ebf54.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Roles, Responsibilities, and Authorities: Cybersecurity is included in human resources practices","details":{"automation":"manual","control_category":"administrative","control_id":"GV.RR-04","control_type":"preventive","domains":["Awareness & Training","Human Resources / Personnel Security"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"dd10c7875d1d32ccc1f60073391a3f1f6c1e6d4ca793231139e1c4b0275e3105","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-rr-04-defc7f20.html","id":"ctrl:nist-csf-2:GV.RR-04","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.RR-04","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.RR-04 — Roles, Responsibilities, and Authorities: Cybersecurity is included in human resources practices","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-rr-04-defc7f20.48dcca381d850077.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Cybersecurity Supply Chain Risk Management: A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders","details":{"automation":"manual","control_category":"administrative","control_id":"GV.SC-01","control_type":"preventive","domains":["Third-Party / Supply-Chain Risk"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"556bd3d7f191a550a5b426e34dfb032f4be0723ad8a6519d6c7feca41e08564e","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-sc-01-a154a187.html","id":"ctrl:nist-csf-2:GV.SC-01","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.SC-01","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.SC-01 — Cybersecurity Supply Chain Risk Management: A cybersecurity supply chain risk management program, strategy, objectives, policies, and processes are established and agreed to by organizational stakeholders","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-sc-01-a154a187.dd492461ea7ecd10.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Cybersecurity Supply Chain Risk Management: Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally","details":{"automation":"manual","control_category":"administrative","control_id":"GV.SC-02","control_type":"preventive","domains":["Third-Party / Supply-Chain Risk"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"15723986279f57046010fb13123586089d03328284e0450fa4d0adccc69b2738","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-sc-02-03d3af49.html","id":"ctrl:nist-csf-2:GV.SC-02","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.SC-02","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.SC-02 — Cybersecurity Supply Chain Risk Management: Cybersecurity roles and responsibilities for suppliers, customers, and partners are established, communicated, and coordinated internally and externally","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-sc-02-03d3af49.bacc1a848c5fc117.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Cybersecurity Supply Chain Risk Management: Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes","details":{"automation":"manual","control_category":"administrative","control_id":"GV.SC-03","control_type":"preventive","domains":["Third-Party / Supply-Chain Risk"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"c9d203a85624588826dce852839e61bc56cf00c742595c48ee7563b9f56585e8","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-sc-03-92c70175.html","id":"ctrl:nist-csf-2:GV.SC-03","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.SC-03","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.SC-03 — Cybersecurity Supply Chain Risk Management: Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment, and improvement processes","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-sc-03-92c70175.6bbe420bfde5bc4c.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Cybersecurity Supply Chain Risk Management: Suppliers are known and prioritized by criticality","details":{"automation":"manual","control_category":"administrative","control_id":"GV.SC-04","control_type":"preventive","domains":["Third-Party / Supply-Chain Risk"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":8,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"0fcf72276239bbee420fd26160f122c97911775d8fd9029890292fe3dbb06195","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-sc-04-ccaf1868.html","id":"ctrl:nist-csf-2:GV.SC-04","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.SC-04","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.SC-04 — Cybersecurity Supply Chain Risk Management: Suppliers are known and prioritized by criticality","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-sc-04-ccaf1868.4f443417745e44c1.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Cybersecurity Supply Chain Risk Management: Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties","details":{"automation":"manual","control_category":"administrative","control_id":"GV.SC-05","control_type":"preventive","domains":["Third-Party / Supply-Chain Risk"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"674d73e5334b7aaba80550063b239bc11d8f96a8695d3cafa4818e99479cdb10","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-sc-05-27e42222.html","id":"ctrl:nist-csf-2:GV.SC-05","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.SC-05","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.SC-05 — Cybersecurity Supply Chain Risk Management: Requirements to address cybersecurity risks in supply chains are established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-sc-05-27e42222.8d4e3b77fb448e4c.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Cybersecurity Supply Chain Risk Management: Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships","details":{"automation":"manual","control_category":"administrative","control_id":"GV.SC-06","control_type":"preventive","domains":["Third-Party / Supply-Chain Risk"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":7,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"c9666acaccc827c33322337f927e759617fa58b1fb5f78d8c2012f5ff9ebba1f","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-sc-06-7725080e.html","id":"ctrl:nist-csf-2:GV.SC-06","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.SC-06","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.SC-06 — Cybersecurity Supply Chain Risk Management: Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-sc-06-7725080e.94baa8c03fb173ce.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Cybersecurity Supply Chain Risk Management: The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship","details":{"automation":"manual","control_category":"administrative","control_id":"GV.SC-07","control_type":"preventive","domains":["Third-Party / Supply-Chain Risk"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"c2285b631d7cd73f00fc7cb20b2df0dcba216d4fc0aac20c644ca67832bff812","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-sc-07-640ab80f.html","id":"ctrl:nist-csf-2:GV.SC-07","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.SC-07","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.SC-07 — Cybersecurity Supply Chain Risk Management: The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-sc-07-640ab80f.c715c3485145f6b0.json"},{"attributes":{"category":"administrative","framework":"nist-csf-2","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-csf-2/","description":"Cybersecurity Supply Chain Risk Management: Relevant suppliers and other third parties are included in incident planning, response, and recovery activities","details":{"automation":"manual","control_category":"administrative","control_id":"GV.SC-08","control_type":"preventive","domains":["Third-Party / Supply-Chain Risk"],"framework":"nist-csf-2","group":"Govern","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"f44b856fff7878ab998df129f9b8882091a65bbc713b0c97c0fd7c6aeb3152bf","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-csf-2-gv-sc-08-0bb8f74f.html","id":"ctrl:nist-csf-2:GV.SC-08","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-csf-2%3AGV.SC-08","sourceIds":["nist-csf-2"],"sourceUrl":null,"title":"GV.SC-08 — Cybersecurity Supply Chain Risk Management: Relevant suppliers and other third parties are included in incident planning, response, and recovery activities","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-csf-2-gv-sc-08-0bb8f74f.afe863a7658a1cc6.json"}],"relationships":[{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:03e990ef1d32ef898869078a3d5cc8e35e040894e29f8a665eee7e5c4cfd8bf8","properties":{"control_id":"GV.SC-03","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-03-92c70175.json","targetId":"ctrl:nist-csf-2:GV.SC-03","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:09046b78e703928f7e6bd7986b9980c61414d2ef2bacd9552d9c9edd27af6d62","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-01-a154a187.json","sourceId":"ctrl:nist-csf-2:GV.SC-01","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:0a6815d4d2c7fcb794bc4733f671d8728f13f59a6ad60498562e6827050dfe0a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-06-88d06373.json","sourceId":"ctrl:nist-csf-2:DE.AE-06","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:0a8199196c4291ea6edaa6f71c20b57557eb0d812000df7d9001fba469503aad","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-02-5a997df0.json","sourceId":"ctrl:nist-csf-2:GV.RM-02","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:100540596138cdf338bbb60b9e8ac90ea72bcf84924273e18908a7571db29247","properties":{"control_id":"DE.AE-08","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-log-06-735bbc3e.json","sourceId":"uc:UC-LOG-06","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-08-67efb705.json","targetId":"ctrl:nist-csf-2:DE.AE-08","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:160fcd5222abfd3f9a3f9e456c860aee846204a60b0d21f4915ca733c617bcaf","properties":{"control_id":"GV.RM-05","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-05-e2fc10a6.json","sourceId":"uc:UC-RISK-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-05-d4ec8a45.json","targetId":"ctrl:nist-csf-2:GV.RM-05","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:21f10052b8690e16fbe2c599fc6c8f20a3f20b649c0f33b700b905d7a7585a34","properties":{"control_id":"GV.PO-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-po-01-e8b931a8.json","targetId":"ctrl:nist-csf-2:GV.PO-01","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:2204b0bfc2fa263d6c0925a25a5e2d6db0f58faaf78aff7f33eb96fb786733d0","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-po-01-e8b931a8.json","sourceId":"ctrl:nist-csf-2:GV.PO-01","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:25f30af0e793f3cd4f7c65333b5752ccba89f268b0ceecec685873b653a2fc22","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-07-715f6bd4.json","sourceId":"ctrl:nist-csf-2:GV.RM-07","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:26ab45627440071e57e3737038b50fa6aabc730e4396a7e303860dfcfcd4cd5d","properties":{"control_id":"GV.SC-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-01-a154a187.json","targetId":"ctrl:nist-csf-2:GV.SC-01","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:2905c9102d7f60835925234e8fe78fadda8822b460a58c99e9c1f866c3fcc551","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rr-02-fa51dc97.json","sourceId":"ctrl:nist-csf-2:GV.RR-02","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:2db1cd2e188bd07014c41290d1c86b6d415e5dd02dd64cc29ca945a78c5f4d1b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-06-7725080e.json","sourceId":"ctrl:nist-csf-2:GV.SC-06","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:2fa1511c42bf90a866b7f517aadddec597be27b9303d0438a307f2e9a1abda3b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rr-01-011a9146.json","sourceId":"ctrl:nist-csf-2:GV.RR-01","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:38e3addcb080438a0d59869bee6a0d0ffe17eba7d3cc2f1119b00a783c7aab48","properties":{"control_id":"GV.RR-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-06-f1eb1346.json","sourceId":"uc:UC-GOV-06","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rr-02-fa51dc97.json","targetId":"ctrl:nist-csf-2:GV.RR-02","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:3dd0f026b9e73e30ed95401e40fd9da5033166912a83962a39930877c47d6436","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-03-f45e152f.json","sourceId":"ctrl:nist-csf-2:DE.AE-03","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:462219a874a6608fe81b0ae59581c0b14e9119a9c40e490889ce78f95dbcc90e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-05-d4ec8a45.json","sourceId":"ctrl:nist-csf-2:GV.RM-05","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:466881084924711c224c130dbd78c778beee07325c720698c26bbc01d223f61f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-08-67efb705.json","sourceId":"ctrl:nist-csf-2:DE.AE-08","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:4eb3df316d996f630fc641782483e17b51a585a6c9eccd77ef22ec4c7a682e73","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-03-92c70175.json","sourceId":"ctrl:nist-csf-2:GV.SC-03","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:535862a4ca89715fb900e6659b249e4006f28142ca72a01bb6bb2975c8df09e4","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-04-a64cbb61.json","sourceId":"ctrl:nist-csf-2:GV.RM-04","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:54c659f7630744ecb079efb9db089ab9b97c353ea68af5aaffd67bb2c6afa20b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-ov-01-19ee87a8.json","sourceId":"ctrl:nist-csf-2:GV.OV-01","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:55adfc55e9e4b65fe2d31ef8d3012394da69779bd344299d9d98afba5ccb2aa4","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-04-ccaf1868.json","sourceId":"ctrl:nist-csf-2:GV.SC-04","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:5bb7d70b5ee9e1fbc2e690086bc8c6c87c3981f2956df79404841a49b0f6beb9","properties":{"control_id":"GV.SC-05","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-03-c9edcf93.json","sourceId":"uc:UC-TPRM-03","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-05-27e42222.json","targetId":"ctrl:nist-csf-2:GV.SC-05","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:60656af39e5efdd590728857fde49ca2a95f3892cc4a55b7f9d8b342e62460fc","properties":{"control_id":"DE.CM-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-log-04-4bc40d21.json","sourceId":"uc:UC-LOG-04","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-cm-01-5a17881e.json","targetId":"ctrl:nist-csf-2:DE.CM-01","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:60e5aeaa14fd18fcdc3f1f654b173a1a38b9d8665fc865be38fcf55ed2398e08","properties":{"control_id":"GV.SC-08","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-05-039b6350.json","sourceId":"uc:UC-TPRM-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-08-0bb8f74f.json","targetId":"ctrl:nist-csf-2:GV.SC-08","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:644eafb401e2554492733991f471d02011d4c2262d35d799b1905537c8da0701","properties":{"control_id":"DE.CM-06","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-log-09-54136146.json","sourceId":"uc:UC-LOG-09","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-cm-06-241a1dc5.json","targetId":"ctrl:nist-csf-2:DE.CM-06","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:656e86110ec583b19eabcda6fccbe612add0b5c24ed0d100da8008278799d7f9","properties":{"control_id":"GV.OC-04","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-02-70e0507c.json","sourceId":"uc:UC-GOV-02","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-oc-04-da71308a.json","targetId":"ctrl:nist-csf-2:GV.OC-04","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:66ebc5ea839a145b3f52b6aa224dee18c1b6038f35e5c07046c80d83cfbce371","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-07-a597b302.json","sourceId":"ctrl:nist-csf-2:DE.AE-07","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:6a5ebb57ae53a67fcc9b5ebf7ca945ac28365d4a61f80a38086ce1ca08a3ac88","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-oc-01-e996c461.json","sourceId":"ctrl:nist-csf-2:GV.OC-01","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:6faf3d3528c52dcfcd7674b4a957807f6442281522504461f3d09ccd761aebcd","properties":{"control_id":"GV.OV-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-22-2a70149b.json","sourceId":"uc:UC-AUDIT-22","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-ov-02-d7467a40.json","targetId":"ctrl:nist-csf-2:GV.OV-02","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:7003ab0e4d35ce9e5f6e3c2758435e92b712d4378bf32b826d59ba6664879e90","properties":{"control_id":"GV.RM-06","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-03-31e0ad29.json","sourceId":"uc:UC-RISK-03","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-06-aa913e7b.json","targetId":"ctrl:nist-csf-2:GV.RM-06","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:709fcc459cd44ee480f15e5b5638d9bb67a1baed9f95ad747e1d2a3906313eb0","properties":{"control_id":"GV.SC-07","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-04-e6aef252.json","sourceId":"uc:UC-TPRM-04","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-07-640ab80f.json","targetId":"ctrl:nist-csf-2:GV.SC-07","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:741954628bb073379b2e87135819a6fa4c757e93cab90a1045b84843aaf2c561","properties":{"control_id":"GV.RM-07","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-07-b86de728.json","sourceId":"uc:UC-RISK-07","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-07-715f6bd4.json","targetId":"ctrl:nist-csf-2:GV.RM-07","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:765d086148e3fe40f7f7a5ae74a8ed47745c6a2602d873aa0e6b698dd3fee1e3","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-ov-02-d7467a40.json","sourceId":"ctrl:nist-csf-2:GV.OV-02","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:775672079475f3b2508b44103d395d4650a0f39db64feae75109b1d1578c2829","properties":{"control_id":"DE.CM-09","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-vuln-06-3863b890.json","sourceId":"uc:UC-VULN-06","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-cm-09-e2e2548a.json","targetId":"ctrl:nist-csf-2:DE.CM-09","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:77ab17bd71037f78d1ce06542e69073a9f776b5bcfa21aaf1c7a7cc9cdd890f6","properties":{"control_id":"DE.AE-07","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-07-a597b302.json","targetId":"ctrl:nist-csf-2:DE.AE-07","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:7c88645873ad26067703dfff2fa5edbe8d16c2aa87ee258ea3d14f7db1426f7d","properties":{"control_id":"GV.SC-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-02-03d3af49.json","targetId":"ctrl:nist-csf-2:GV.SC-02","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:7e110a0b74490294b6ee6827e6121c458c9d8af13275924ac1a29f52002662a1","properties":{"control_id":"GV.RR-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rr-01-011a9146.json","targetId":"ctrl:nist-csf-2:GV.RR-01","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:82a62ed565df57f5331e26541441c1f05ef6ed894c4970ce97b66d9734e94df9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-01-a04dd496.json","sourceId":"ctrl:nist-csf-2:GV.RM-01","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:89c3dff8bc83b6dae43662e765e87412b25982b73a9bdd382a4653d120ccd514","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-06-aa913e7b.json","sourceId":"ctrl:nist-csf-2:GV.RM-06","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:8c529b16ca6c18fbb81f197fceb6948f4d079dcaec09b63f1a868e84d610b35f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-07-640ab80f.json","sourceId":"ctrl:nist-csf-2:GV.SC-07","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:90643faef3c896206b0ca47a8b46aa57f71afeca85508290607ad39a6560e102","properties":{"control_id":"GV.RM-03","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-02-0f8519bb.json","sourceId":"uc:UC-RISK-02","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-03-4891faf8.json","targetId":"ctrl:nist-csf-2:GV.RM-03","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:906722d49afd5b21b387e40a953d95b696b4032e627600139fbcda17a5fdc259","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-02-1f4071e1.json","sourceId":"ctrl:nist-csf-2:DE.AE-02","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:922aa7d7cc8072dace637dfcc0e9d478635fe23c723bcbf38784dbaddbcf11cc","properties":{"control_id":"GV.OV-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-05-b3a47944.json","sourceId":"uc:UC-GOV-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-ov-01-19ee87a8.json","targetId":"ctrl:nist-csf-2:GV.OV-01","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:96f09c16ddd2943108b5d0e4941f674169f68e870ad1a3114f4f9fca59cce2d2","properties":{"control_id":"DE.CM-03","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-log-07-659fa92d.json","sourceId":"uc:UC-LOG-07","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-cm-03-9f258e61.json","targetId":"ctrl:nist-csf-2:DE.CM-03","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:9955f3cb99e2bab3946f5ef8d7330f97b476938f7cbee9ff8ec6d9f2ca659f2e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-cm-09-e2e2548a.json","sourceId":"ctrl:nist-csf-2:DE.CM-09","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:997a90021e39415129a99a6680eb1938c5ec00d07df67b38db98b551533b3898","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-05-27e42222.json","sourceId":"ctrl:nist-csf-2:GV.SC-05","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:99884d5363a26a6a3590a38c5036ff368ee9f7e526bc2f5c1bed2dde4431d7d5","properties":{"control_id":"DE.AE-04","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-ir-05-0e11ebf5.json","sourceId":"uc:UC-IR-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-04-186bb6c1.json","targetId":"ctrl:nist-csf-2:DE.AE-04","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:9ac0892a983e372789eaf022b024591dbc8cfc48a702d327eb056a0cdeb8d4c4","properties":{"control_id":"GV.PO-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-14-f4f2c470.json","sourceId":"uc:UC-GOV-14","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-po-02-4745ed81.json","targetId":"ctrl:nist-csf-2:GV.PO-02","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:a131a1febde0e725a526468c8b3631b470809c72d7fb40f725eb624149093739","properties":{"control_id":"GV.RR-03","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-11-a13b60d3.json","sourceId":"uc:UC-GOV-11","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rr-03-f8d87e54.json","targetId":"ctrl:nist-csf-2:GV.RR-03","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:a1922758600bdc17200eb4a0c970ef6e3492d9fffd6777a1a42307c7c742cc06","properties":{"control_id":"GV.SC-06","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-02-c35b26eb.json","sourceId":"uc:UC-TPRM-02","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-06-7725080e.json","targetId":"ctrl:nist-csf-2:GV.SC-06","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:a5819579ea903e0919530007e139e36974a13949b864e2e09cfecbfc226dcd1f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-oc-03-325aeeeb.json","sourceId":"ctrl:nist-csf-2:GV.OC-03","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:a662583687c68bbe25a7f081530fba83c1a921406028516a5f09b1e02ffcee1c","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-oc-04-da71308a.json","sourceId":"ctrl:nist-csf-2:GV.OC-04","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:a91afb78c87bccaac2c04ed7b276b987f8b377065769e9854b2b3aa14ff29164","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-04-186bb6c1.json","sourceId":"ctrl:nist-csf-2:DE.AE-04","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:a9ce1390dcdb40c83c99e355a511908d62dcfb48c25213d83bc9fa1d670f80eb","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-02-03d3af49.json","sourceId":"ctrl:nist-csf-2:GV.SC-02","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:aab88d3b13137d89a2d082d876c3ce3f108624b4de90640631474d7e78271ac0","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rr-04-defc7f20.json","sourceId":"ctrl:nist-csf-2:GV.RR-04","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:ab11deef560959ed5089d4a0e6196a1f1682284a086ad1b1ba26f194f35a2db9","properties":{"control_id":"GV.OC-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-02-70e0507c.json","sourceId":"uc:UC-GOV-02","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-oc-02-84d81944.json","targetId":"ctrl:nist-csf-2:GV.OC-02","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:b426d50bba331d1f15ce3702e1e6936768814d8b23c953302493b4fb803f4d57","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-po-02-4745ed81.json","sourceId":"ctrl:nist-csf-2:GV.PO-02","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:b577e76b97bde031b8cbb6456709baae08a4387b8f2648b91938cd3aade295f2","properties":{"control_id":"DE.AE-06","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-06-88d06373.json","targetId":"ctrl:nist-csf-2:DE.AE-06","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:b5934e0c4b9dbe574eebb2cb750a66a1e9792051bef88c279d12261ea0474948","properties":{"control_id":"GV.RM-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-03-31e0ad29.json","sourceId":"uc:UC-RISK-03","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-02-5a997df0.json","targetId":"ctrl:nist-csf-2:GV.RM-02","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:b758bd0b1f0477a409c095ce01264b38a4838e7e579169c449187a5183a01767","properties":{"control_id":"DE.AE-03","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-03-f45e152f.json","targetId":"ctrl:nist-csf-2:DE.AE-03","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:b7f832436ecc57d43d236cc3a887dfb2c55e59c8ff9f7fb4af2c17952115e5af","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rr-03-f8d87e54.json","sourceId":"ctrl:nist-csf-2:GV.RR-03","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:bd8eab0a83d99619b1067bc3eb12cb0d3095a815b3dea118a82406a4750a7780","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-cm-02-96e890cb.json","sourceId":"ctrl:nist-csf-2:DE.CM-02","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:bfa04869cc2cfee65acad58a0598d370ce760f17a5489ba95eba0903b37353c7","properties":{"control_id":"GV.RM-04","coverage":"partial","delta":"establishing and communicating the strategic risk-response direction itself; this UC only applies that direction during treatment selection","framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-risk-09-06ffdff1.json","sourceId":"uc:UC-RISK-09","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-04-a64cbb61.json","targetId":"ctrl:nist-csf-2:GV.RM-04","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:bfd3cff5d049df0239fe824011169dc3a1717800e610e14345f5386a2996a37e","properties":{"control_id":"DE.CM-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-log-10-17ea2aa0.json","sourceId":"uc:UC-LOG-10","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-cm-02-96e890cb.json","targetId":"ctrl:nist-csf-2:DE.CM-02","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:cb7df1cca18494a8571d27b8326691cfe00fd83420dff3ea92da8b8d3112733f","properties":{"control_id":"GV.OC-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-02-70e0507c.json","sourceId":"uc:UC-GOV-02","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-oc-01-e996c461.json","targetId":"ctrl:nist-csf-2:GV.OC-01","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:cd248f4889b85a1dedac6efe2d92c36e42eb80296249d48a5a0b7b12f03966a6","properties":{"control_id":"GV.RR-04","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-06-36a1f4aa.json","sourceId":"uc:UC-HR-06","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rr-04-defc7f20.json","targetId":"ctrl:nist-csf-2:GV.RR-04","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:d07257293a8f23d21ccfe186855c4b8d6ca9fa970a1826a3ef4bf85ed63ad9c4","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-cm-06-241a1dc5.json","sourceId":"ctrl:nist-csf-2:DE.CM-06","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:d64f32a946a805b1fa036159aa56cb168af7d7bc1b98bd605001f926402246e8","properties":{"control_id":"DE.AE-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-log-05-8f316c34.json","sourceId":"uc:UC-LOG-05","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-ae-02-1f4071e1.json","targetId":"ctrl:nist-csf-2:DE.AE-02","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:e4ffca6a9b9edeae0044e8efd3d760357fe322e2abf330c6355ba463db4f5e4c","properties":{"control_id":"GV.OC-03","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-03-9e248eb3.json","sourceId":"uc:UC-GOV-03","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-oc-03-325aeeeb.json","targetId":"ctrl:nist-csf-2:GV.OC-03","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:e67dec9567d8df830720e2d7930464088961e8c5e8c404ecf50d261f79b9afdf","properties":{"control_id":"GV.OC-05","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-02-70e0507c.json","sourceId":"uc:UC-GOV-02","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-oc-05-abe265e5.json","targetId":"ctrl:nist-csf-2:GV.OC-05","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:e79a2d79988c50fe30c34b943d6d262b20a107435787fe53c2ce3c4cc322d037","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-ov-03-fc445da9.json","sourceId":"ctrl:nist-csf-2:GV.OV-03","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:ebc153f0419f6b6730942e0dfccc70e9c7c81adf75bf66f391ba7941eb5d2aeb","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-oc-02-84d81944.json","sourceId":"ctrl:nist-csf-2:GV.OC-02","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:ebe992cd6e7b612ee9c27a81a2c57fb877d1e16d53116b6a1387cbb8d2d03a33","properties":{"control_id":"GV.RM-01","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-17-5ee3266f.json","sourceId":"uc:UC-GOV-17","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-01-a04dd496.json","targetId":"ctrl:nist-csf-2:GV.RM-01","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:ecc4bd1132775841348ce3ae9cd021e73ec96a0451ba3abc189016553763c4ce","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-08-0bb8f74f.json","sourceId":"ctrl:nist-csf-2:GV.SC-08","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:ee20675c86e4c205a7a41d34af025b022b06043a6808b05a10d7d7becede82f3","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-cm-01-5a17881e.json","sourceId":"ctrl:nist-csf-2:DE.CM-01","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:effff0f71dadbe40d45c5e6c2dd1be333690418a9af880008cab88ad1feedebd","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-de-cm-03-9f258e61.json","sourceId":"ctrl:nist-csf-2:DE.CM-03","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:fcc5d79a43db247cfe6d234d21b150bd9a09332eb632ab538edc472bb547199d","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-rm-03-4891faf8.json","sourceId":"ctrl:nist-csf-2:GV.RM-03","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:fd08aeac6a3d3eaf25170c4b641c66c9bedd6ea71171f26cc7a31c3fcf341f52","properties":{"control_id":"GV.OV-03","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-22-2a70149b.json","sourceId":"uc:UC-AUDIT-22","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-ov-03-fc445da9.json","targetId":"ctrl:nist-csf-2:GV.OV-03","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:fd305f0090b82272025b82dd373cd2ad8c017e6c1cc592676df02f39ce2f59df","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-oc-05-abe265e5.json","sourceId":"ctrl:nist-csf-2:GV.OC-05","targetDetailPath":"/data/v1/records/std-nist-csf-2-c5e53008.json","targetId":"std:nist-csf-2","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:ff8184b47e04d3a4cfab0cc7760eabf38016f3ab9330e99b2f0e5151b4ce3aad","properties":{"control_id":"GV.SC-04","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-tprm-01-16b62053.json","sourceId":"uc:UC-TPRM-01","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-gv-sc-04-ccaf1868.json","targetId":"ctrl:nist-csf-2:GV.SC-04","type":"maps_to"}],"schemaVersion":1,"scope":"sources","total":385}
