{"catalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","contextIds":["risk:access-excess-privilege","risk:access-privilege-abuse-repudiation","risk:access-provisioning-review-gap","risk:access-unauthorized-use-equipment","risk:ai-emergent-integration-risk","risk:aware-user-error-mishandling","risk:bcdr-it-resilience-outage","risk:bcdr-no-tested-continuity-plan","risk:config-poor-baseline-drift","risk:config-weak-change-control","risk:cyber-adversary-threat-sources","risk:fin-accuracy-measurement-errors","risk:fin-completeness-understatement","risk:fin-cutoff-period-errors","risk:fin-data-quality-reporting-integrity","risk:fin-existence-overstatement","risk:fin-journal-entry-management-override","risk:log-missing-audit-trail","risk:log-no-monitoring-supervision","risk:ops-process-execution-errors","risk:phys-cyber-physical-facility-attack","risk:phys-environmental-degradation","risk:phys-fire-water-suppression-gap","risk:phys-inadequate-facility-access","risk:phys-theft-of-equipment-media","risk:tech-hardware-equipment-failure","risk:tech-loss-essential-services","risk:tech-software-system-failure"],"directIds":["ctrl:soc1:SOC1-1","ctrl:soc1:SOC1-10","ctrl:soc1:SOC1-11","ctrl:soc1:SOC1-12","ctrl:soc1:SOC1-2","ctrl:soc1:SOC1-3","ctrl:soc1:SOC1-4","ctrl:soc1:SOC1-5","ctrl:soc1:SOC1-6","ctrl:soc1:SOC1-7","ctrl:soc1:SOC1-8","ctrl:soc1:SOC1-9"],"kind":"bundle","metadata":"/assets/agent_metadata.84eaa456936e4fa1.json","name":"SOC 1","next":"/assets/agent_sources-soc1-2.d5c1da0b706a32f9.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"technical","framework":"soc1","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/soc1/","description":"Logical access — controls provide reasonable assurance that logical access to applications, data, and infrastructure is restricted to authorized and appropriate users (authentication, authorization, provisioning/deprovisioning, periodic access review, privileged access).","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-1","control_type":"preventive","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"524af53436303f54d1aa6b7c50d45ef7f73062e9946cbac140ae54e7c8a1c9b1","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-soc1-soc1-1-bfab4a41.html","id":"ctrl:soc1:SOC1-1","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Asoc1%3ASOC1-1","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-1 — Logical access — controls provide reasonable assurance that logical access to applications, data, and infrastructure is restricted to authorized and appropriate users (authentication, authorization, provisioning/deprovisioning, periodic access review, privileged access).","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-soc1-soc1-1-bfab4a41.ea6b521c3a5985dd.json"},{"attributes":{"category":"physical","framework":"soc1","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/soc1/","description":"Physical security and environmental controls — controls provide reasonable assurance that physical access to facilities and data centers is restricted and that environmental protections safeguard systems.","details":{"automation":"hybrid","control_category":"physical","control_id":"SOC1-10","control_type":"preventive","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"47e618c70c080489eb7307be3edeca6523d88b4dbeb20ae6d2e96eaa21ad9dc8","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-soc1-soc1-10-43ef0cd6.html","id":"ctrl:soc1:SOC1-10","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Asoc1%3ASOC1-10","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-10 — Physical security and environmental controls — controls provide reasonable assurance that physical access to facilities and data centers is restricted and that environmental protections safeguard systems.","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-soc1-soc1-10-43ef0cd6.cacbf353a7451085.json"},{"attributes":{"category":"technical","framework":"soc1","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/soc1/","description":"System monitoring and incident management — controls provide reasonable assurance that system performance, security events, and incidents are monitored, identified, and resolved.","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-11","control_type":"detective","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"22b42978f50023925c1d2d64616e38e7348c4ca732cb88e8f150c627cbe2f014","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-soc1-soc1-11-9b7842c1.html","id":"ctrl:soc1:SOC1-11","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Asoc1%3ASOC1-11","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-11 — System monitoring and incident management — controls provide reasonable assurance that system performance, security events, and incidents are monitored, identified, and resolved.","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-soc1-soc1-11-9b7842c1.b35733e67285b58f.json"},{"attributes":{"category":"administrative","framework":"soc1","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/soc1/","description":"Vendor / subservice organization management — controls provide reasonable assurance that subservice organizations relevant to user entities' ICFR are appropriately managed and monitored.","details":{"automation":"manual","control_category":"administrative","control_id":"SOC1-12","control_type":"preventive","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"d43b6390fee577257db640e4b53ee0ea8fd9cbe93fc4eb0d30fc7419bb847b8d","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-soc1-soc1-12-05ba06e4.html","id":"ctrl:soc1:SOC1-12","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Asoc1%3ASOC1-12","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-12 — Vendor / subservice organization management — controls provide reasonable assurance that subservice organizations relevant to user entities' ICFR are appropriately managed and monitored.","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-soc1-soc1-12-05ba06e4.8f14db80fee3cca8.json"},{"attributes":{"category":"technical","framework":"soc1","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/soc1/","description":"Change management — controls provide reasonable assurance that changes to applications and infrastructure are authorized, tested, approved, and migrated to production appropriately.","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-2","control_type":"preventive","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"796704f44b18dcc70050500ef0c901fcfc2922b6e26573a84c05dca4b487037d","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-soc1-soc1-2-7fcfb329.html","id":"ctrl:soc1:SOC1-2","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Asoc1%3ASOC1-2","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-2 — Change management — controls provide reasonable assurance that changes to applications and infrastructure are authorized, tested, approved, and migrated to production appropriately.","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-soc1-soc1-2-7fcfb329.cfd013c6937fa55f.json"},{"attributes":{"category":"technical","framework":"soc1","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/soc1/","description":"Program development / SDLC — controls provide reasonable assurance that new systems and applications are developed, tested, approved, and implemented in accordance with management's intent.","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-3","control_type":"preventive","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"673c6ca1c8fc663b8a376da2d25d686d67d60de06ce8dce05d317174c8f1f236","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-soc1-soc1-3-762891cb.html","id":"ctrl:soc1:SOC1-3","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Asoc1%3ASOC1-3","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-3 — Program development / SDLC — controls provide reasonable assurance that new systems and applications are developed, tested, approved, and implemented in accordance with management's intent.","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-soc1-soc1-3-762891cb.5bb7f1bba230e34a.json"},{"attributes":{"category":"technical","framework":"soc1","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/soc1/","description":"Computer operations / job scheduling — controls provide reasonable assurance that production batch jobs and scheduled processing are appropriately defined, executed, monitored, and that exceptions/failures are identified and resolved.","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-4","control_type":"detective","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"10df49aa91d5f8f27333b71cc905456e212d4696f840de96ee609f3e42a4c74e","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-soc1-soc1-4-2584ed29.html","id":"ctrl:soc1:SOC1-4","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Asoc1%3ASOC1-4","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-4 — Computer operations / job scheduling — controls provide reasonable assurance that production batch jobs and scheduled processing are appropriately defined, executed, monitored, and that exceptions/failures are identified and resolved.","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-soc1-soc1-4-2584ed29.bb520ec1bea7338d.json"},{"attributes":{"category":"technical","framework":"soc1","type":"corrective"},"canonicalUrl":"https://evidenceflows.com/frameworks/soc1/","description":"Backup and recovery — controls provide reasonable assurance that data is backed up, retained, and recoverable, and that restoration is tested.","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-5","control_type":"corrective","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"0409e19fc3ce60adc9961026a87f4f1a0435874ad95bab4dd944468e1e8c7e11","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-soc1-soc1-5-d064ade6.html","id":"ctrl:soc1:SOC1-5","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Asoc1%3ASOC1-5","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-5 — Backup and recovery — controls provide reasonable assurance that data is backed up, retained, and recoverable, and that restoration is tested.","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-soc1-soc1-5-d064ade6.6bde79446cd8a438.json"},{"attributes":{"category":"technical","framework":"soc1","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/soc1/","description":"Data transmission / interface controls — controls provide reasonable assurance that data transmitted to and from the system and across interfaces is complete, accurate, authorized, and timely.","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-6","control_type":"detective","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":7,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"dd088472e8750bb3570cf2949d4a2fe00ac32dac24705d78b180a41dd1026395","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-soc1-soc1-6-b85280f6.html","id":"ctrl:soc1:SOC1-6","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Asoc1%3ASOC1-6","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-6 — Data transmission / interface controls — controls provide reasonable assurance that data transmitted to and from the system and across interfaces is complete, accurate, authorized, and timely.","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-soc1-soc1-6-b85280f6.6859ad41ac5cd2f3.json"},{"attributes":{"category":"technical","framework":"soc1","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/soc1/","description":"Data input — controls provide reasonable assurance that transactions and data input into the system are complete, accurate, and authorized.","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-7","control_type":"preventive","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":7,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"237592551871f597f5b988feaa3d1ca906a1d65430985ce60bfd4ad3f39e0322","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-soc1-soc1-7-20ea752e.html","id":"ctrl:soc1:SOC1-7","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Asoc1%3ASOC1-7","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-7 — Data input — controls provide reasonable assurance that transactions and data input into the system are complete, accurate, and authorized.","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-soc1-soc1-7-20ea752e.e0471f8c4b4dcee2.json"},{"attributes":{"category":"technical","framework":"soc1","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/soc1/","description":"Data processing — controls provide reasonable assurance that transactions are processed completely, accurately, and in the proper period.","details":{"automation":"automated","control_category":"technical","control_id":"SOC1-8","control_type":"preventive","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":7,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"fc695c2b039d51ea358e8f58b9432e94bbde8618d4dddf9f6c31fcad4f013100","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-soc1-soc1-8-9602488c.html","id":"ctrl:soc1:SOC1-8","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Asoc1%3ASOC1-8","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-8 — Data processing — controls provide reasonable assurance that transactions are processed completely, accurately, and in the proper period.","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-soc1-soc1-8-9602488c.9be2951e472f4db1.json"},{"attributes":{"category":"technical","framework":"soc1","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/soc1/","description":"Data output / reporting — controls provide reasonable assurance that output and reports provided to user entities are complete, accurate, and distributed only to authorized recipients.","details":{"automation":"hybrid","control_category":"technical","control_id":"SOC1-9","control_type":"detective","domains":["Access Control & Identity Management","Secure Configuration & Change Management","Secure Development (SDLC) & Application Security","Business Continuity & Disaster Recovery","Logging, Monitoring & Detection","Incident Management & Response","Physical & Environmental Security","Third-Party / Supply-Chain Risk","Financial Reporting Controls (SOX)"],"framework":"soc1","group":"Typical control objective domains","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":7,"source_pages":null,"source_url":null},"direct":true,"history":{"digest":"e768531d90a42252d09ca6c71a774c393583fe196bc307c81b776c2ec97957e8","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-soc1-soc1-9-7278adb1.html","id":"ctrl:soc1:SOC1-9","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Asoc1%3ASOC1-9","sourceIds":["soc1"],"sourceUrl":null,"title":"SOC1-9 — Data output / reporting — controls provide reasonable assurance that output and reports provided to user entities are complete, accurate, and distributed only to authorized recipients.","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-soc1-soc1-9-7278adb1.d4c9e224c34fe94e.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management","Data Protection & Privacy"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event","nist-privacy-risk"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Aaccess-excess-privilege","description":"Overly broad or wrongly assigned access rights, applications/services running with excessive privileges, and failure to enforce least privilege — a compromise or insider then gains broad access to systems and data.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"access-excess-privilege","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event","nist-privacy-risk"],"treatment":"mitigate"},"direct":false,"history":{"digest":"e809d5c42b898a087d3d28b269c8663d902d0912b2d22c208c3b8e0df3cacc64","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-access-excess-privilege-cd8adadc.html","id":"risk:access-excess-privilege","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Aaccess-excess-privilege","sourceIds":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Excessive privilege and wrong assignment of access rights","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-access-excess-privilege-cd8adadc.26d10ae695d1d7a9.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Aaccess-privilege-abuse-repudiation","description":"Authorized users or administrators exploit legitimate access beyond permitted scope, fabricate or forge credentials/rights to gain privileges, and repudiate performed actions — undermining accountability and audit-trail integrity.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"access-privilege-abuse-repudiation","taxonomies":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source"],"treatment":"mitigate"},"direct":false,"history":{"digest":"1e0e8688c40889153dbdde5420258869eb274346d8d72b0cc6611efd5b582c70","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-access-privilege-abuse-repudiation-343a8917.html","id":"risk:access-privilege-abuse-repudiation","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Aaccess-privilege-abuse-repudiation","sourceIds":["aiuc-1","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Abuse of rights, forged rights, and repudiation of actions","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-access-privilege-abuse-repudiation-343a8917.8d438cfffb9d8e3d.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Aaccess-provisioning-review-gap","description":"No formal user registration/de-registration procedure and no periodic access-rights review, so orphaned or excessive accounts accumulate and access is not revoked when roles change or personnel leave.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"access-provisioning-review-gap","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"history":{"digest":"e66e2a1ba3637ce87e6954e4e6261a91857d9b7d33852aea9642927a607de509","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-access-provisioning-review-gap-dc152038.html","id":"risk:access-provisioning-review-gap","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Aaccess-provisioning-review-gap","sourceIds":["iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","soc1","soc2","sox"],"sourceUrl":null,"title":"Weak account provisioning/de-registration and access review","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-access-provisioning-review-gap-dc152038.4bc0180054da880a.json"},{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management"],"inherent_rating":"medium","taxonomy":["iso-27005-threat","nist-800-30-threat-event"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Aaccess-unauthorized-use-equipment","description":"Use of systems, networks, or devices without authorization, and users with authorized access reaching resources that exceed their authorization, potentially to exfiltrate data or conduct attacks.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"access-unauthorized-use-equipment","taxonomies":["iso-27005-threat","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"history":{"digest":"b327d4b0091aa93eb734f2bc8776bd79c68af5257cdbde47026eb6c6a2fc9717","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-access-unauthorized-use-equipment-d2082944.html","id":"risk:access-unauthorized-use-equipment","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Aaccess-unauthorized-use-equipment","sourceIds":["aiuc-1","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Unauthorized use of equipment and unauthorized access escalation","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-access-unauthorized-use-equipment-d2082944.44b40bf19241d510.json"},{"attributes":{"category":"ai_governance","domain":["AI Governance","Secure Development (SDLC) & Application Security"],"inherent_rating":"medium","taxonomy":["iso-23894-ai-risk"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Aai-emergent-integration-risk","description":"Large-scale or multi-model pipelines exhibit emergent capabilities/failures not present in any component and not predictable from component testing; integration with legacy systems introduces interface mismatches and configuration errors.","details":{"category":"ai_governance","impact":"high","inherent_rating":"medium","likelihood":"medium","risk_id":"ai-emergent-integration-risk","taxonomies":["iso-23894-ai-risk"],"treatment":"mitigate"},"direct":false,"history":{"digest":"c324475c42c3ba11219842a2f84bc7f49c11688d2a1919dfce4665b14021ee43","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-ai-emergent-integration-risk-8490271c.html","id":"risk:ai-emergent-integration-risk","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Aai-emergent-integration-risk","sourceIds":["aiuc-1","cobit-2019","eu-ai-act","iso-27001","iso-42001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","soc1","soc2","sox"],"sourceUrl":null,"title":"Emergent behaviour and unsafe AI system integration","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-ai-emergent-integration-risk-8490271c.a5a9a840facd2492.json"},{"attributes":{"category":"operational","domain":["Awareness & Training","Data Protection & Privacy","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source","iso-27005-vulnerability"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Aaware-user-error-mishandling","description":"Authorized users make mistakes — incorrect data entry, misconfiguration, improper procedures, incorrect privilege settings, or spilling/mishandling sensitive information — causing harm to information assets without malicious intent.","details":{"category":"operational","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"aware-user-error-mishandling","taxonomies":["iso-27005-threat","nist-800-30-threat-event","nist-800-30-threat-source","iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"history":{"digest":"4f9c62db14ebe1cf0a83396a74afd3b5a5bd58bad5b06429a1eae1cd17a4cb95","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-aware-user-error-mishandling-149a1d3b.html","id":"risk:aware-user-error-mishandling","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Aaware-user-error-mishandling","sourceIds":["aiuc-1","gdpr","iso-27001","nist-800-53","nist-ai-agent-identity","nist-ai-tevv-athlon","nist-csf-2","nydfs-500","soc1","soc2"],"sourceUrl":null,"title":"User error and mishandling of sensitive information","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-aware-user-error-mishandling-149a1d3b.8f173c5ec7bdbc4c.json"},{"attributes":{"category":"business_continuity","domain":["Business Continuity & Disaster Recovery","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["coso-erm-risk","basel-operational-risk"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Abcdr-it-resilience-outage","description":"Critical technology infrastructure or applications experience unplanned outages, data loss, or prolonged recovery times — including failure of DR systems to activate — disrupting operations and harming stakeholders.","details":{"category":"business_continuity","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"bcdr-it-resilience-outage","taxonomies":["coso-erm-risk","basel-operational-risk"],"treatment":"mitigate"},"direct":false,"history":{"digest":"6427a4f83a6e0a54015e5bdf829262e3d54546faf348d93e4a3ed3326520264f","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-bcdr-it-resilience-outage-18dfc108.html","id":"risk:bcdr-it-resilience-outage","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Abcdr-it-resilience-outage","sourceIds":["cobit-2019","dora","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"sourceUrl":null,"title":"IT resilience failure — unplanned outage, data loss, slow recovery","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-bcdr-it-resilience-outage-18dfc108.2cef3facf8185560.json"},{"attributes":{"category":"business_continuity","domain":["Business Continuity & Disaster Recovery","Risk Assessment & Management"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk","iso-27005-vulnerability"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Abcdr-no-tested-continuity-plan","description":"No BCP/DR plan, or plans that exist but have never been exercised end-to-end, so a natural disaster, pandemic, civil unrest, or infrastructure failure disables critical processes with no tested recovery path.","details":{"category":"business_continuity","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"bcdr-no-tested-continuity-plan","taxonomies":["enterprise-risk","coso-erm-risk","iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"history":{"digest":"def716839a3331d06fab2c6d1a03af6de7aa56311ecfc59fe6cebe381e7a1615","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-bcdr-no-tested-continuity-plan-d4d9e7a9.html","id":"risk:bcdr-no-tested-continuity-plan","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Abcdr-no-tested-continuity-plan","sourceIds":["cobit-2019","dora","iso-27001","nist-800-53","nydfs-500","soc1","soc2","sox"],"sourceUrl":null,"title":"Absent or untested business continuity / disaster recovery plan","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-bcdr-no-tested-continuity-plan-d4d9e7a9.94b99eb895275746.json"},{"attributes":{"category":"cyber_security","domain":["Secure Configuration & Change Management","Vulnerability & Patch Management"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Aconfig-poor-baseline-drift","description":"Without documented, enforced baseline configurations and change control, systems drift into insecure states, contain unauthorized changes, or expose unnecessary network services, expanding attack surface.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"config-poor-baseline-drift","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"history":{"digest":"01a8769ad2ddecba0aacdc723d6d20cf777ef004d9ec364f6d9d4670710806df","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-config-poor-baseline-drift-2dd66324.html","id":"risk:config-poor-baseline-drift","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Aconfig-poor-baseline-drift","sourceIds":["coso-ic","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Poor configuration management and insecure baseline drift","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-config-poor-baseline-drift-2dd66324.155ac7ee0f5daa17.json"},{"attributes":{"category":"cyber_security","domain":["Secure Configuration & Change Management","Secure Development (SDLC) & Application Security"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Aconfig-weak-change-control","description":"Changes to systems, software, hardware, or configurations without formal approval and testing (including unauthorized or poorly tested hardware/config changes) introduce new vulnerabilities, instability, or failed releases.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"config-weak-change-control","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"history":{"digest":"430dab2adf3bd7844590901d1f91e315e12628c925e8fb76091293f407ac0666","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-config-weak-change-control-e7d90eaf.html","id":"risk:config-weak-change-control","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Aconfig-weak-change-control","sourceIds":["cobit-2019","coso-ic","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"sourceUrl":null,"title":"Absent or weak change-control procedures","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-config-weak-change-control-e7d90eaf.b813bff91bab72d6.json"},{"attributes":{"category":"cyber_security","domain":["Risk Assessment & Management","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["nist-800-30-threat-source"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Acyber-adversary-threat-sources","description":"Because capable, motivated threat actors - outsiders, privileged and non-privileged insiders, organized groups, competitors, malicious partners or suppliers, and nation-states - actively target the organization's cyber resources, deliberate attacks are attempted against its systems and data, resulting in compromise, disruption, or theft when defenses are outmatched.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"cyber-adversary-threat-sources","taxonomies":["nist-800-30-threat-source"],"treatment":"mitigate"},"direct":false,"history":{"digest":"709992401c3d33c0e26b47d16599cb5cfb434a111e7abbcba92d17e8f2803361","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-cyber-adversary-threat-sources-fa9e3003.html","id":"risk:cyber-adversary-threat-sources","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Acyber-adversary-threat-sources","sourceIds":["aiuc-1","cobit-2019","coso-ic","gdpr","iso-27001","iso-31000","nist-800-53","nist-csf-2","nydfs-500","soc1","soc2","sox"],"sourceUrl":null,"title":"Attacks by capable, motivated threat actors","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-cyber-adversary-threat-sources-fa9e3003.d7a2a0d4aa7cae13.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)"],"inherent_rating":"medium","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Afin-accuracy-measurement-errors","description":"Errors in revenue recognition amounts, cost of goods sold, depreciation/amortization, payroll calculations, fair-value measurement, journal-entry posting, tax provision, and foreign-currency translation misstating the financial statements.","details":{"category":"financial_reporting","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"fin-accuracy-measurement-errors","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"history":{"digest":"aa012375295c0de63147d605c708192c82cfc597a9eb8cbacfde67deebf17d4a","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-fin-accuracy-measurement-errors-fd727255.html","id":"risk:fin-accuracy-measurement-errors","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Afin-accuracy-measurement-errors","sourceIds":["cobit-2019","soc1","soc2","sox"],"sourceUrl":null,"title":"Measurement and calculation errors (accuracy)","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-fin-accuracy-measurement-errors-fd727255.36531308c46e73d8.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)"],"inherent_rating":"high","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Afin-completeness-understatement","description":"Unrecorded payables (cut-off failure), accrued expenses, unrecorded revenue for delivered goods, off-balance-sheet obligations, uncaptured inventory write-downs, and understated payroll/tax liabilities — understating obligations and overstating income.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fin-completeness-understatement","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"history":{"digest":"7e133ead8a87ceefa64104deb5b36f34bfa33c28f732df51516b712872c9ae6a","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-fin-completeness-understatement-4b9388d1.html","id":"risk:fin-completeness-understatement","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Afin-completeness-understatement","sourceIds":["cobit-2019","soc1","soc2","sox"],"sourceUrl":null,"title":"Understatement of liabilities/expenses (completeness)","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-fin-completeness-understatement-4b9388d1.e939d5915967f02b.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)"],"inherent_rating":"medium","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Afin-cutoff-period-errors","description":"Revenue, vendor invoices, payroll, capital expenditure, treasury transactions, or tax provisions recorded in the wrong period — deliberately shifted to meet targets or erroneously mis-timed — distorting period results.","details":{"category":"financial_reporting","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"fin-cutoff-period-errors","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"history":{"digest":"d167fd324ce7811896952126c060d86a1d2dc2fc1c5e8e5cc0a1eed1fc188740","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-fin-cutoff-period-errors-180e8bcf.html","id":"risk:fin-cutoff-period-errors","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Afin-cutoff-period-errors","sourceIds":["cobit-2019","soc1","soc2","sox"],"sourceUrl":null,"title":"Period cut-off errors","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-fin-cutoff-period-errors-180e8bcf.3642c5c7d5314bb0.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)","Data Protection & Privacy","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["enterprise-risk","coso-erm-risk"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Afin-data-quality-reporting-integrity","description":"Poor data lineage, inconsistent master-data definitions, or uncontrolled data transformation (weak IPE completeness/accuracy) cause management decisions and regulatory reports to rest on inaccurate or incomplete data.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fin-data-quality-reporting-integrity","taxonomies":["enterprise-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"history":{"digest":"04a7faafc577ed9039a7b49c44bacb12a79f4a169b1ea42d2cc5c0218e085cc7","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-fin-data-quality-reporting-integrity-276baaa6.html","id":"risk:fin-data-quality-reporting-integrity","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Afin-data-quality-reporting-integrity","sourceIds":["cobit-2019","iso-27001","soc1","soc2","sox"],"sourceUrl":null,"title":"Data-quality and IPE integrity failures in reporting","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-fin-data-quality-reporting-integrity-276baaa6.ab13735cca733177.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)"],"inherent_rating":"high","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Afin-existence-overstatement","description":"Revenue, receivables, inventory, capitalized assets, prepaid expenses, treasury investments, or tax assets recorded without underlying existence or occurrence — inflating the balance sheet and income statement.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fin-existence-overstatement","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"history":{"digest":"cce71b8b75812a73e9200283f6a92e1a7f55dc8ce7b6fd0e1e1f2653f360c039","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-fin-existence-overstatement-0e009631.html","id":"risk:fin-existence-overstatement","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Afin-existence-overstatement","sourceIds":["cobit-2019","nist-800-53","soc1","soc2","sox"],"sourceUrl":null,"title":"Overstatement of assets/revenue (existence & occurrence)","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-fin-existence-overstatement-0e009631.7241de5f2260062b.json"},{"attributes":{"category":"financial_reporting","domain":["Financial Reporting Controls (SOX)","Logging, Monitoring & Detection"],"inherent_rating":"high","taxonomy":["sox-rmm-assertion"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Afin-journal-entry-management-override","description":"Manual/automated journal entries posted with transposition errors, wrong account codes, or amounts; recurring entries not updated; and top-side entries used to override controls and manage earnings at period-end.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"fin-journal-entry-management-override","taxonomies":["sox-rmm-assertion"],"treatment":"mitigate"},"direct":false,"history":{"digest":"610719467931b19d303ea3c6ae7c4c43c998733a3d5d0590f1a8144ac4224a62","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-fin-journal-entry-management-override-b0c0ed68.html","id":"risk:fin-journal-entry-management-override","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Afin-journal-entry-management-override","sourceIds":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2","sox"],"sourceUrl":null,"title":"Manual journal entries and management-override risk","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-fin-journal-entry-management-override-b0c0ed68.ae7d4cd81e4d8c08.json"},{"attributes":{"category":"cyber_security","domain":["Logging, Monitoring & Detection","Incident Management & Response"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Alog-missing-audit-trail","description":"Absence of logging/audit trails means unauthorized activity cannot be detected, investigated, or attributed, and adversary actions (obfuscation of intrusion detection, tampering with logs) go unnoticed.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"high","likelihood":"high","risk_id":"log-missing-audit-trail","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"history":{"digest":"89fee1e066eb9a24e0411462663aae13afed9253c6e69caa3abc2902965ecdc1","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-log-missing-audit-trail-37d1ba80.html","id":"risk:log-missing-audit-trail","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Alog-missing-audit-trail","sourceIds":["aiuc-1","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss","soc1"],"sourceUrl":null,"title":"Missing or insufficient logging and audit trails","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-log-missing-audit-trail-37d1ba80.8972260312d6ee39.json"},{"attributes":{"category":"cyber_security","domain":["Logging, Monitoring & Detection","Incident Management & Response"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Alog-no-monitoring-supervision","description":"Absence of monitoring mechanisms and supervision of personnel actions (especially privileged users) allows undetected misuse, and no process exists to supervise and escalate detected security breaches.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"log-no-monitoring-supervision","taxonomies":["iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"history":{"digest":"e422749dca0ee160dad08c51e328f18e5fa933acb4951b70816743d7874344a6","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-log-no-monitoring-supervision-712fe573.html","id":"risk:log-no-monitoring-supervision","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Alog-no-monitoring-supervision","sourceIds":["cobit-2019","gdpr","hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc1","soc2"],"sourceUrl":null,"title":"No security monitoring or supervision of privileged activity","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-log-no-monitoring-supervision-712fe573.9ded85935cf204a8.json"},{"attributes":{"category":"operational","domain":["Risk Assessment & Management","Financial Reporting Controls (SOX)"],"inherent_rating":"medium","taxonomy":["basel-operational-risk","coso-erm-risk"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Aops-process-execution-errors","description":"Data-entry (fat-finger) errors, incorrect settlement instructions, collateral-management errors, reconciliation failures, and mis-application of corporate actions cause failed settlement, penalties, and undetected position discrepancies.","details":{"category":"operational","impact":"medium","inherent_rating":"medium","likelihood":"high","risk_id":"ops-process-execution-errors","taxonomies":["basel-operational-risk","coso-erm-risk"],"treatment":"mitigate"},"direct":false,"history":{"digest":"3a6ba7ea48a1a1591ba19a67bf463a4b3e5955858d8ef34ff39dabf43d1e3306","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-ops-process-execution-errors-530a1b11.html","id":"risk:ops-process-execution-errors","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Aops-process-execution-errors","sourceIds":["cobit-2019","soc1","soc2","sox"],"sourceUrl":null,"title":"Transaction-processing and execution errors","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-ops-process-execution-errors-530a1b11.7634f4dd9f46e108.json"},{"attributes":{"category":"cyber_security","domain":["Physical & Environmental Security","Business Continuity & Disaster Recovery"],"inherent_rating":"medium","taxonomy":["nist-800-30-threat-event"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Aphys-cyber-physical-facility-attack","description":"Adversary conducts physical attacks on facilities (arson) or supporting infrastructure (cuts power/water), or cyber-physical attacks (remotely altering HVAC), damaging systems and supporting utilities.","details":{"category":"cyber_security","impact":"high","inherent_rating":"medium","likelihood":"low","risk_id":"phys-cyber-physical-facility-attack","taxonomies":["nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"history":{"digest":"eb384d72052a84bac7101ae4b7415d753844611b0b66bd371ee51256cc24e3ab","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-phys-cyber-physical-facility-attack-e372d06e.html","id":"risk:phys-cyber-physical-facility-attack","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Aphys-cyber-physical-facility-attack","sourceIds":["hipaa","iso-27001","nist-800-53","nist-csf-2","soc1","soc2"],"sourceUrl":null,"title":"Physical and cyber-physical attacks on facilities and infrastructure","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-phys-cyber-physical-facility-attack-e372d06e.e273d2b092447529.json"},{"attributes":{"category":"operational","domain":["Physical & Environmental Security"],"inherent_rating":"medium","taxonomy":["iso-27005-threat","iso-27005-vulnerability","nist-800-30-threat-source"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Aphys-environmental-degradation","description":"Equipment sited without environmental controls suffers from dust, corrosion, freezing, humidity, voltage or temperature variation, and electromagnetic/thermal radiation or EMP, causing malfunction or failure.","details":{"category":"operational","impact":"medium","inherent_rating":"medium","likelihood":"low","risk_id":"phys-environmental-degradation","taxonomies":["iso-27005-threat","iso-27005-vulnerability","nist-800-30-threat-source"],"treatment":"mitigate"},"direct":false,"history":{"digest":"9a99a24a0962ba695e175c97caa69a7c0b26c4899d33f564ed253438f026c075","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-phys-environmental-degradation-137ba6a3.html","id":"risk:phys-environmental-degradation","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Aphys-environmental-degradation","sourceIds":["iso-27001","nist-800-53","nist-csf-2","soc1"],"sourceUrl":null,"title":"Environmental degradation of equipment (dust, humidity, temperature, EMI)","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-phys-environmental-degradation-137ba6a3.171eafb248be0390.json"},{"attributes":{"category":"operational","domain":["Physical & Environmental Security","Business Continuity & Disaster Recovery"],"inherent_rating":"medium","taxonomy":["iso-27005-vulnerability","iso-27005-threat"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Aphys-fire-water-suppression-gap","description":"Absence of fire suppression, smoke detection, flood barriers, or drainage in facilities housing information assets, and poor cabling infrastructure susceptible to damage, tapping, or accidental disconnection.","details":{"category":"operational","impact":"high","inherent_rating":"medium","likelihood":"low","risk_id":"phys-fire-water-suppression-gap","taxonomies":["iso-27005-vulnerability","iso-27005-threat"],"treatment":"mitigate"},"direct":false,"history":{"digest":"fb70c51f4c2f6a2efa3355bc9a2eae5ceea8ede6c5bf4d3ef1585fbbc54deeba","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-phys-fire-water-suppression-gap-ac966b92.html","id":"risk:phys-fire-water-suppression-gap","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Aphys-fire-water-suppression-gap","sourceIds":["iso-27001","nist-800-53","nist-csf-2","soc1"],"sourceUrl":null,"title":"Inadequate protection against fire, flood and physical hazards","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-phys-fire-water-suppression-gap-ac966b92.df2f1b64c4088cfb.json"},{"attributes":{"category":"cyber_security","domain":["Physical & Environmental Security","Access Control & Identity Management"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Aphys-inadequate-facility-access","description":"Buildings and sensitive areas lacking perimeter security, key-card/lock/mantrap controls, or supervision of visitors and cleaning/outside staff allow unauthorized physical access to equipment and media — including tailgating past physical checks.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"phys-inadequate-facility-access","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event"],"treatment":"mitigate"},"direct":false,"history":{"digest":"8f9ff8f5ae54d919f05b19ad0f6440c702901b660983afb01d7c90ee0748e28b","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-phys-inadequate-facility-access-a83f3330.html","id":"risk:phys-inadequate-facility-access","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Aphys-inadequate-facility-access","sourceIds":["hipaa","iso-27001","nist-800-53","nist-csf-2","soc1","soc2"],"sourceUrl":null,"title":"Inadequate physical protection and access controls","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-phys-inadequate-facility-access-a83f3330.adbee0de383e695b.json"},{"attributes":{"category":"cyber_security","domain":["Physical & Environmental Security","Asset Management & Inventory","Data Protection & Privacy"],"inherent_rating":"medium","taxonomy":["iso-27005-threat","nist-800-30-threat-event","iso-27005-vulnerability"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Aphys-theft-of-equipment-media","description":"Physical stealing of storage media, printouts, or computing/network equipment (including unattended laptops outside the perimeter), potentially exposing stored data. Unprotected storage locations increase exposure.","details":{"category":"cyber_security","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"phys-theft-of-equipment-media","taxonomies":["iso-27005-threat","nist-800-30-threat-event","iso-27005-vulnerability"],"treatment":"mitigate"},"direct":false,"history":{"digest":"f7107891ac6c2fac0bd0a2e9b7fd4664a92b438fa02875703dc8d0e55177f419","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-phys-theft-of-equipment-media-c64433e7.html","id":"risk:phys-theft-of-equipment-media","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Aphys-theft-of-equipment-media","sourceIds":["hipaa","iso-27001","nist-800-53","nist-csf-2","pci-dss","soc1","soc2"],"sourceUrl":null,"title":"Theft of equipment, media or unattended devices","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-phys-theft-of-equipment-media-c64433e7.8880ca4afc4762c8.json"},{"attributes":{"category":"operational","domain":["Business Continuity & Disaster Recovery","Asset Management & Inventory"],"inherent_rating":"medium","taxonomy":["iso-27005-threat","nist-800-30-threat-source","nist-800-30-threat-event","basel-operational-risk"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Atech-hardware-equipment-failure","description":"Malfunction or breakdown of storage, processing, communications, sensor, controller, or display equipment (aging, resource depletion, disk errors) disrupting availability or integrity — including intermittent/degraded operation producing incorrect results.","details":{"category":"operational","impact":"medium","inherent_rating":"medium","likelihood":"medium","risk_id":"tech-hardware-equipment-failure","taxonomies":["iso-27005-threat","nist-800-30-threat-source","nist-800-30-threat-event","basel-operational-risk"],"treatment":"mitigate"},"direct":false,"history":{"digest":"f218e8ccc1fa9b7c6944c25754fdc008c3c484ef90d716903eddf44d276b8839","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-tech-hardware-equipment-failure-25948451.html","id":"risk:tech-hardware-equipment-failure","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Atech-hardware-equipment-failure","sourceIds":["cobit-2019","dora","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"sourceUrl":null,"title":"Hardware and equipment failure","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-tech-hardware-equipment-failure-25948451.a29d16e970867fd0.json"},{"attributes":{"category":"business_continuity","domain":["Business Continuity & Disaster Recovery","Physical & Environmental Security"],"inherent_rating":"high","taxonomy":["iso-27005-threat","iso-27005-vulnerability","nist-800-30-threat-source","basel-operational-risk"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Atech-loss-essential-services","description":"Interruption of power supply, air-conditioning/water utilities, or telecommunications — from unstable grids, single power feeds, UPS/generator failure, or carrier/fiber outages — stops operations or harms equipment and personnel.","details":{"category":"business_continuity","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"tech-loss-essential-services","taxonomies":["iso-27005-threat","iso-27005-vulnerability","nist-800-30-threat-source","basel-operational-risk"],"treatment":"mitigate"},"direct":false,"history":{"digest":"b93a9f02bf2d4916884a7634032b6a742b95e8bfc40ffd2924455c1c65d6cc07","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-tech-loss-essential-services-b7feae05.html","id":"risk:tech-loss-essential-services","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Atech-loss-essential-services","sourceIds":["cobit-2019","iso-27001","nist-800-53","nist-csf-2","nydfs-500","soc1"],"sourceUrl":null,"title":"Loss of essential services (power, HVAC, telecoms)","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-tech-loss-essential-services-b7feae05.615f3c29b817556e.json"},{"attributes":{"category":"operational","domain":["Business Continuity & Disaster Recovery","Secure Development (SDLC) & Application Security"],"inherent_rating":"high","taxonomy":["iso-27005-threat","nist-800-30-threat-source","basel-operational-risk"]},"canonicalUrl":"https://evidenceflows.com/?v=1&node=risk%3Atech-software-system-failure","description":"Failure or malfunction of operating-system, networking, or application software (defects, resource depletion, failed releases) causing loss of availability/integrity and impeding mission/business functions — including core banking/payments outages.","details":{"category":"operational","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"tech-software-system-failure","taxonomies":["iso-27005-threat","nist-800-30-threat-source","basel-operational-risk"],"treatment":"mitigate"},"direct":false,"history":{"digest":"8f7ecbc3392d87451f182310fffafc67e1a4ab52cfecbbef7daa8a4bb06f26c3","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/risk-tech-software-system-failure-2e2c5364.html","id":"risk:tech-software-system-failure","mapUrl":"https://evidenceflows.com/?v=1&node=risk%3Atech-software-system-failure","sourceIds":["cobit-2019","dora","iso-27001","nist-800-53","nist-csf-2","soc1","soc2","sox"],"sourceUrl":null,"title":"Software and information-system failure","type":"risk","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-risk-tech-software-system-failure-2e2c5364.f81f388a0a057bea.json"}],"relationships":[{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:082ce7de28fdc456c8e68f7bf2b6f2f2af4a25425c80e8e87c82e9d347e259f9","properties":{"rationale":"Auto-disabling dormant accounts and prompt termination removal close the orphaned-account vector for unauthorized access.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/risk-access-unauthorized-use-equipment-d2082944.json","targetId":"risk:access-unauthorized-use-equipment","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:11fe9a986e34244ae40027d08cce29410f0ad1ec4a74cb082300df6f05ac6c05","properties":{"rationale":"Access authorization plus review of physical/environmental events deters and detects an adversary physically reaching and sabotaging infrastructure.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-19-08a17359.json","sourceId":"uc:UC-ACCESS-19","targetDetailPath":"/data/v1/records/risk-phys-cyber-physical-facility-attack-e372d06e.json","targetId":"risk:phys-cyber-physical-facility-attack","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:1448b5981f0f84eae0edf17bdeddb04df6bb1bab4d08fb48d84c2c8e23575315","properties":{"rationale":"Owner-approved provisioning with role-based entitlements and 1-business-day deprovisioning on termination directly eliminates orphaned accounts and un-revoked access.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/risk-access-provisioning-review-gap-dc152038.json","targetId":"risk:access-provisioning-review-gap","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:1453ec0d0a9b31e2eb4d51ab3c43a632bc169a42bdb8336f101fea32af775363","properties":{"control_id":"SOC1-12","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-21-14f45683.json","sourceId":"uc:UC-ACCESS-21","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-12-05ba06e4.json","targetId":"ctrl:soc1:SOC1-12","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:1c5ed5869ef6bfd8447a6778631af2d091fa13a9f89c7c6007ac2e5129a61405","properties":{"control_id":"SOC1-7","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-7-20ea752e.json","targetId":"ctrl:soc1:SOC1-7","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:303f150d8121d11f1a7baaf39d40fc40dd40ba0a7fcaab174fafe354a8d4b648","properties":{"control_id":"SOC1-9","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-9-7278adb1.json","targetId":"ctrl:soc1:SOC1-9","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:33dcd40af1a39867875bc4253e4c8c4a79e06449acbc0d315f7104aeab6b3ad2","properties":{"control_id":"SOC1-6","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-6-b85280f6.json","targetId":"ctrl:soc1:SOC1-6","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:3482f940501c517a67197f708fd3cb684305fd5024709ad7e5dffbade6b03082","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-4-2584ed29.json","sourceId":"ctrl:soc1:SOC1-4","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:35e1dfb346a72fd0c22d2413ff5a7d57a2ebd258234bdaa359d941754b0c242b","properties":{"rationale":"Systems generate protected log records made available for continuous monitoring, directly remedying absent/insufficient audit trails.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/risk-log-missing-audit-trail-37d1ba80.json","targetId":"risk:log-missing-audit-trail","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:3b26f5b7dd3ea6d611ce3884e501d07d1c17144ae41c092fef0c7588ce3ad15b","properties":{"control_id":"SOC1-3","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-3-762891cb.json","targetId":"ctrl:soc1:SOC1-3","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:3cb85a07ecd989ddfb977e2e28f315672ff6498a55a05836692b3add9de727a7","properties":{"rationale":"Temperature/humidity control and power conditioning directly prevent equipment degradation from thermal and voltage variation.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-19-08a17359.json","sourceId":"uc:UC-ACCESS-19","targetDetailPath":"/data/v1/records/risk-phys-environmental-degradation-137ba6a3.json","targetId":"risk:phys-environmental-degradation","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:3eeba4eca39f8b884fcc75287de1c376d7cadac924a9d21760d4842cca42dee5","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-7-20ea752e.json","sourceId":"ctrl:soc1:SOC1-7","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:4987cfed4954248b8ed56bc0bbc3dca0d46b95d8bbd753c0fa0c8c6fab25422e","properties":{"rationale":"Incident identification and capacity/performance monitoring surface error- and misconfiguration-driven incidents, enabling correction that limits impact.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/risk-aware-user-error-mishandling-149a1d3b.json","targetId":"risk:aware-user-error-mishandling","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:522207fd6d9b165c0039e3025b319ff4c0759411ea7c5ea4bfad8a4296747421","properties":{"rationale":"scheduled protected backups with tested restoration confirm recoverability within objectives, reducing outage/data-loss/slow-recovery","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-17-c9ecd00d.json","sourceId":"uc:UC-ACCESS-17","targetDetailPath":"/data/v1/records/risk-bcdr-it-resilience-outage-18dfc108.json","targetId":"risk:bcdr-it-resilience-outage","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:53321dcf48fee33a1e4347c5d958372eed452f042a342ec40af6ad00679f46f6","properties":{"rationale":"Input edit checks catch journal-entry transposition and format errors before posting.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/risk-fin-journal-entry-management-override-b0c0ed68.json","targetId":"risk:fin-journal-entry-management-override","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:5797f2efd8a8cd404420f154f4e500255e3e960ce54c6b7d097051edc40f6b05","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-11-9b7842c1.json","sourceId":"ctrl:soc1:SOC1-11","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:5a89cf0f679caeba093b024d4116046089f748f6c912e73e2e281611062987af","properties":{"rationale":"Operating fire detection and suppression directly mitigates the fire hazard to systems that is the core gap this risk names.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-19-08a17359.json","sourceId":"uc:UC-ACCESS-19","targetDetailPath":"/data/v1/records/risk-phys-fire-water-suppression-gap-ac966b92.json","targetId":"risk:phys-fire-water-suppression-gap","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:5e0f088619589520d16d49dc65833d9f48229353895adf2f6420f1f71b6db42b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-1-bfab4a41.json","sourceId":"ctrl:soc1:SOC1-1","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:5f22736e12ef926d9b071321940afbdc54d6227b4d46ccb66c91d0bf3f5c3c89","properties":{"rationale":"Interface reconciliation and output validation preserve completeness/accuracy of data used in reporting.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/risk-fin-data-quality-reporting-integrity-276baaa6.json","targetId":"risk:fin-data-quality-reporting-integrity","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:610a50fbfce562d7abb329df448ae492410a9a88750151ea34b93e955dfdf08a","properties":{"rationale":"Requiring authorized, documented changes reduces the unauthorized changes that drive drift, though baseline monitoring is the operative control.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/risk-config-poor-baseline-drift-2dd66324.json","targetId":"risk:config-poor-baseline-drift","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:681a6786c06c86e379fe0f4643d18c70bf76177ccd58a2185be021943a45e9f3","properties":{"control_id":"SOC1-4","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-17-c9ecd00d.json","sourceId":"uc:UC-ACCESS-17","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-4-2584ed29.json","targetId":"ctrl:soc1:SOC1-4","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:6b710d6a56e7a4b07aefe80567fefddc69ff19c8c060fa0f70b307e36aa1b835","properties":{"rationale":"monitoring batch/scheduled processing and resolving logged failures directly limits system-failure impact","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-17-c9ecd00d.json","sourceId":"uc:UC-ACCESS-17","targetDetailPath":"/data/v1/records/risk-tech-software-system-failure-2e2c5364.json","targetId":"risk:tech-software-system-failure","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:6c815b812ba264ef62d6cf7e0c231c815cef0e6891cd1d8eb074d6564b155aa3","properties":{"rationale":"Continuously monitors security events against thresholds with alert triage and tracked incident resolution, filling the no-monitoring gap.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/risk-log-no-monitoring-supervision-712fe573.json","targetId":"risk:log-no-monitoring-supervision","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:7140895cb754da3b3fb1b55b2fb55668cb267adc5c21b8e8bd64f92de8e68b2d","properties":{"rationale":"Proper-period processing contributes, but ACCESS-20 centers on input/interface completeness and accuracy; the operative cut-off controls are period-end close review and automated processing period enforcement.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/risk-fin-cutoff-period-errors-180e8bcf.json","targetId":"risk:fin-cutoff-period-errors","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:7c3a185818b8aa491bee8c358ee5433277ecf04932f4c54f7a61ebd250cc7cf1","properties":{"rationale":"Monitors performance/capacity against thresholds and projects/tunes resource use, directly reducing capacity-driven outages; incident tracking shortens recovery.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/risk-bcdr-it-resilience-outage-18dfc108.json","targetId":"risk:bcdr-it-resilience-outage","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:7d87c2ca05792ba32958cff58e1fbded7b657cfdb235299ba395db1effbd517e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-12-05ba06e4.json","sourceId":"ctrl:soc1:SOC1-12","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:8042e50c8400feb9ba8232e6e9b8b7dba985fb195e97a397d35b5d09e90e8b9b","properties":{"control_id":"SOC1-11","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-11-9b7842c1.json","targetId":"ctrl:soc1:SOC1-11","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:82c5c2a6412b6bd1788c545deba7ea85028834f492e55e2af8ed87fe97ac2c8e","properties":{"rationale":"Power conditioning and backup directly sustain systems through power disruption, reducing loss-of-power impact.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-19-08a17359.json","sourceId":"uc:UC-ACCESS-19","targetDetailPath":"/data/v1/records/risk-tech-loss-essential-services-b7feae05.json","targetId":"risk:tech-loss-essential-services","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:897843185d2d78e8517e151151b9b8afc945cd5abe90f11f8a076f64364ee8a4","properties":{"rationale":"Authorizing, badging, logging, monitoring, and revoking physical access is the direct control preventing unauthorized entry to facilities and secure areas.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-19-08a17359.json","sourceId":"uc:UC-ACCESS-19","targetDetailPath":"/data/v1/records/risk-phys-inadequate-facility-access-a83f3330.json","targetId":"risk:phys-inadequate-facility-access","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:8e6742e480b41e66a020b38a90eb94480944cbf497754834c3ddda5bec65dd58","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-5-d064ade6.json","sourceId":"ctrl:soc1:SOC1-5","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:8e9356e1aafa162e56d7ec0b8878ef0e0ae86695d6b9ef63446429a8dc7225a0","properties":{"rationale":"Authorization validation of inputs reduces unauthorized/fictitious entries entering processing.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/risk-fin-existence-overstatement-0e009631.json","targetId":"risk:fin-existence-overstatement","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:916a5f73c86982a998a42038eb41a19435b88179395ca277226a86d2ec11a2dc","properties":{"rationale":"Restricting and revoking physical access keeps unauthorized persons away from equipment and media, directly preventing on-site theft.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-19-08a17359.json","sourceId":"uc:UC-ACCESS-19","targetDetailPath":"/data/v1/records/risk-phys-theft-of-equipment-media-c64433e7.json","targetId":"risk:phys-theft-of-equipment-media","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:98442e227966546c39abf81dc0d410be51413eae6b905290fba01ac8719022de","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-9-7278adb1.json","sourceId":"ctrl:soc1:SOC1-9","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:9cd63182cb1af7f6e50ef091319214c504b8f5863b32de90be1c597a0e551ac6","properties":{"control_id":"SOC1-5","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-17-c9ecd00d.json","sourceId":"uc:UC-ACCESS-17","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-5-d064ade6.json","targetId":"ctrl:soc1:SOC1-5","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:a2e1805733a26b7d9aa4907769037519f52061354e3a99da55492a7950b96b53","properties":{"control_id":"SOC1-10","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-19-08a17359.json","sourceId":"uc:UC-ACCESS-19","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-10-43ef0cd6.json","targetId":"ctrl:soc1:SOC1-10","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:a2e38565659d2389482f09121d6f3a226ad91bb51d3f4a289a62de12de94f513","properties":{"rationale":"Pre-production testing and approval gates catch legacy-integration interface mismatches and configuration errors before they reach production.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/risk-ai-emergent-integration-risk-8490271c.json","targetId":"risk:ai-emergent-integration-risk","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:a306a3d84f530dae589def12cc9c1cd68e204ef07784a630b04381d253540b95","properties":{"rationale":"periodic restoration testing exercises the recovery path","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-17-c9ecd00d.json","sourceId":"uc:UC-ACCESS-17","targetDetailPath":"/data/v1/records/risk-bcdr-no-tested-continuity-plan-d4d9e7a9.json","targetId":"risk:bcdr-no-tested-continuity-plan","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:a8e947d41b9ce280ec46a8aa353bc1de04d27649e8737ad3a268cd54ef74a093","properties":{"control_id":"SOC1-1","coverage":"partial","delta":"authentication, periodic review, and privileged access satisfied by companion unified controls","framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-1-bfab4a41.json","targetId":"ctrl:soc1:SOC1-1","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:a91da0cf407c7f7f8372e3661427e45682359b9adc643c7ec5dc243ac1c57827","properties":{"rationale":"Edit checks and batch totals validate processing accuracy, catching calculation and posting errors.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/risk-fin-accuracy-measurement-errors-fd727255.json","targetId":"risk:fin-accuracy-measurement-errors","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:ac926831df5567af31dda7687bb08beb6241ad883936c5e38dcee1bd556bd753","properties":{"control_id":"SOC1-2","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-2-7fcfb329.json","targetId":"ctrl:soc1:SOC1-2","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:afd5822474b74e64ccfb40b345a7188165ef1ab0e454c5bab35471af16ebd43f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-8-9602488c.json","sourceId":"ctrl:soc1:SOC1-8","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:b1fdc19aba428a2f288414f58d4c6877e17f56f919f2846fa8743e5b6d745dc5","properties":{"rationale":"Batch totals and completeness validation ensure all transactions are captured, preventing unrecorded items.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/risk-fin-completeness-understatement-4b9388d1.json","targetId":"risk:fin-completeness-understatement","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:b4d92548374a81b2bfd10351d0d6bffa2a829e747b1b01b0bee88a2e14ceeaf5","properties":{"rationale":"backup and tested restoration recover data lost to equipment failure","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-17-c9ecd00d.json","sourceId":"uc:UC-ACCESS-17","targetDetailPath":"/data/v1/records/risk-tech-hardware-equipment-failure-25948451.json","targetId":"risk:tech-hardware-equipment-failure","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:b588dd72669f70c111b1d540bb1db20d3797bdc9d35338d28ec08de5a1eb9352","properties":{"control_id":"SOC1-8","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-8-9602488c.json","targetId":"ctrl:soc1:SOC1-8","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:bac757e49dbfd195de7f3e65ab597d65874a137a35603edf85a19f35c554b40b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-10-43ef0cd6.json","sourceId":"ctrl:soc1:SOC1-10","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:be88249853f99703d19cefb0ad41a99cd93d410c5b64fd1ff7f47b7359d6cb3f","properties":{"rationale":"The authorize->test->approve->independent-migration gate IS the change-control process, directly preventing unapproved or untested changes.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/risk-config-weak-change-control-e7d90eaf.json","targetId":"risk:config-weak-change-control","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:c98f016859301db5b87ab34820a1c012b990ef0f66df57ae7d30bb94bbca3443","properties":{"rationale":"Edit checks, batch totals and interface reconciliation catch data-entry and processing execution errors.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-20-92554410.json","sourceId":"uc:UC-ACCESS-20","targetDetailPath":"/data/v1/records/risk-ops-process-execution-errors-530a1b11.json","targetId":"risk:ops-process-execution-errors","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:cf137512b108434acb4692dc06fe51fba1530cd3829a3ef8b1904e30510f8527","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-6-b85280f6.json","sourceId":"ctrl:soc1:SOC1-6","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:d0d07d418148d734088375ce0012f28de40045ab3411397bfc3bd43059407743","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-3-762891cb.json","sourceId":"ctrl:soc1:SOC1-3","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:dfc315612c713723a50c9d8914f9a7dbc9a9d82d7da7ce0cca39ac67d98d100a","properties":{"rationale":"Role-based, owner-approved provisioning and modify-on-role-change help limit wrong assignment and accumulation, but the operative least-privilege defense is role design (UC-03) and periodic access review (UC-02).","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/risk-access-excess-privilege-cd8adadc.json","targetId":"risk:access-excess-privilege","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:f346a38d911d1f90dd9b17be32550423e8663599fe22040b606f95ea7a3cb858","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-soc1-soc1-2-7fcfb329.json","sourceId":"ctrl:soc1:SOC1-2","targetDetailPath":"/data/v1/records/std-soc1-05a7010d.json","targetId":"std:soc1","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:f58e9acd1374bdbce84d3819c1f1ddf398cf90c365abed4378c3b5e88b182afd","properties":{"rationale":"Security-event monitoring with alert triage contributes to detecting attacks, though specialized detection sits in dedicated SIEM/IDS controls.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-18-8ffbd456.json","sourceId":"uc:UC-ACCESS-18","targetDetailPath":"/data/v1/records/risk-cyber-adversary-threat-sources-fa9e3003.json","targetId":"risk:cyber-adversary-threat-sources","type":"mitigates"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:f67ff06fb773d0f1089d4819b048691037c347f94ad9b19a46047afa3f3ca5fb","properties":{"rationale":"Accounts uniquely attributable to individuals plus logged provisioning/modification events underpin the accountability that counters repudiation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/risk-access-privilege-abuse-repudiation-343a8917.json","targetId":"risk:access-privilege-abuse-repudiation","type":"mitigates"}],"schemaVersion":1,"scope":"sources","total":80}
