{"catalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","contextIds":["ctrl:cobit-2019:DSS01","ctrl:cobit-2019:DSS02","ctrl:cobit-2019:DSS03","ctrl:cobit-2019:MEA03","ctrl:coso-ic:P13","ctrl:dora:DORA-Art17-23","ctrl:gdpr:GDPR-Art30","ctrl:gdpr:GDPR-Art6","ctrl:hipaa:HIPAA-164.310","ctrl:iso-27001:A.5.10","ctrl:iso-27001:A.5.11","ctrl:iso-27001:A.5.12","ctrl:iso-27001:A.5.13","ctrl:iso-27001:A.5.14","ctrl:iso-27001:A.5.32","ctrl:iso-27001:A.5.9","ctrl:iso-27001:A.7.1","ctrl:iso-27001:A.7.10","ctrl:iso-27001:A.7.14","ctrl:iso-27001:A.7.2","ctrl:iso-27001:A.7.3","ctrl:iso-27001:A.7.4","ctrl:iso-27001:A.7.6","ctrl:iso-27001:A.7.9","ctrl:iso-27001:A.8.1","ctrl:iso-27001:A.8.10","ctrl:iso-27001:A.8.13","ctrl:iso-27001:A.8.14","ctrl:iso-27001:A.8.19","ctrl:nist-800-53:AC-20","ctrl:nist-800-53:CM-10","ctrl:nist-800-53:CM-11","ctrl:nist-800-53:CM-14","ctrl:nist-800-53:CM-8","ctrl:nist-800-53:CP-10","ctrl:nist-800-53:CP-6","ctrl:nist-800-53:CP-7","ctrl:nist-800-53:CP-8","ctrl:nist-800-53:CP-9","ctrl:nist-800-53:MA-3"],"directIds":[],"kind":"bundle","metadata":"/assets/agent_metadata.84eaa456936e4fa1.json","name":"Asset Management & Inventory","next":"/assets/agent_topics-asset-management-inventory-2.b42fb45622bd4f96.json","page":1,"pageSize":40,"records":[{"attributes":{"category":"administrative","framework":"cobit-2019","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/cobit-2019/","description":"Managed Operations","details":{"automation":"hybrid","control_category":"administrative","control_id":"DSS01","control_type":"preventive","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"cobit-2019","group":"Deliver, Service and Support","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"0f978eb5d67a4d8c696b754bc4efb7ea725e8ac0c5af9ea9dce58bfe6962f51c","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-cobit-2019-dss01-d3ff2961.html","id":"ctrl:cobit-2019:DSS01","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Acobit-2019%3ADSS01","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"DSS01 — Managed Operations","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-cobit-2019-dss01-d3ff2961.3f77ed9cdadedc9a.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"corrective"},"canonicalUrl":"https://evidenceflows.com/frameworks/cobit-2019/","description":"Managed Service Requests and Incidents","details":{"automation":"hybrid","control_category":"administrative","control_id":"DSS02","control_type":"corrective","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"cobit-2019","group":"Deliver, Service and Support","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"c3054225f389c70198634f35abc5bcb285cc678d294252b2560d75044c7532bc","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-cobit-2019-dss02-af5bca5d.html","id":"ctrl:cobit-2019:DSS02","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Acobit-2019%3ADSS02","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"DSS02 — Managed Service Requests and Incidents","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-cobit-2019-dss02-af5bca5d.d9218a4b31c470e5.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"corrective"},"canonicalUrl":"https://evidenceflows.com/frameworks/cobit-2019/","description":"Managed Problems","details":{"automation":"manual","control_category":"administrative","control_id":"DSS03","control_type":"corrective","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Logging, Monitoring & Detection","Governance, Policy & Oversight"],"framework":"cobit-2019","group":"Deliver, Service and Support","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"fa94651cd7f34385dcdc64403e2f31ff96cd2d85f63dea62616c5c909067406a","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-cobit-2019-dss03-2540740f.html","id":"ctrl:cobit-2019:DSS03","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Acobit-2019%3ADSS03","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"DSS03 — Managed Problems","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-cobit-2019-dss03-2540740f.3bd6a028b224e2af.json"},{"attributes":{"category":"administrative","framework":"cobit-2019","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/cobit-2019/","description":"Managed Compliance With External Requirements","details":{"automation":"manual","control_category":"administrative","control_id":"MEA03","control_type":"detective","domains":["Compliance, Audit & Assurance","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"cobit-2019","group":"Monitor, Evaluate and Assess","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"ba314ae487ff8e54b4d34e58f67236cf2d9f6dfca035dfe19829eec4a411e02a","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-cobit-2019-mea03-99c7dcca.html","id":"ctrl:cobit-2019:MEA03","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Acobit-2019%3AMEA03","sourceIds":["cobit-2019"],"sourceUrl":null,"title":"MEA03 — Managed Compliance With External Requirements","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-cobit-2019-mea03-99c7dcca.4c2a519aba50add0.json"},{"attributes":{"category":"administrative","framework":"coso-ic","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/coso-ic/","description":"The organization obtains or generates and uses relevant, quality information to support the functioning of internal control.","details":{"automation":"manual","control_category":"administrative","control_id":"P13","control_type":"preventive","domains":["Asset Management & Inventory","Data Protection & Privacy","Financial Reporting Controls (SOX)"],"framework":"coso-ic","group":"Information & Communication","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"4269b572c5fce45211468759678c0fbaec03d5f95f06f081be11d614beb05cf0","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-coso-ic-p13-0c70843b.html","id":"ctrl:coso-ic:P13","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Acoso-ic%3AP13","sourceIds":["coso-ic"],"sourceUrl":null,"title":"P13 — The organization obtains or generates and uses relevant, quality information to support the functioning of internal control.","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-coso-ic-p13-0c70843b.2af72198fefbc96e.json"},{"attributes":{"category":"administrative","framework":"dora","type":"corrective"},"canonicalUrl":"https://evidenceflows.com/frameworks/dora/","description":"ICT-related incident management, classification and reporting","details":{"automation":"hybrid","control_category":"administrative","control_id":"DORA-Art17-23","control_type":"corrective","domains":["Business Continuity & Disaster Recovery","Incident Management & Response","Third-Party / Supply-Chain Risk","Governance, Policy & Oversight","Risk Assessment & Management"],"framework":"dora","group":"EU DORA (Digital Operational Resilience Act)","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"c6a2f613c020e4b6214e9cffde4361a389808573bab1613b6d11f598c6ab0a99","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-dora-dora-art17-23-9aa7977f.html","id":"ctrl:dora:DORA-Art17-23","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Adora%3ADORA-Art17-23","sourceIds":["dora"],"sourceUrl":null,"title":"DORA-Art17-23 — ICT-related incident management, classification and reporting","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-dora-dora-art17-23-9aa7977f.0916c3b4c498fa50.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/gdpr/","description":"Records of processing activities (RoPA)","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art30","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"b6a86e2c5094937e1d65bd3648a5a9088d5ca0de5d0c8b52641717e6364e91a0","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art30-e7db10f3.html","id":"ctrl:gdpr:GDPR-Art30","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art30","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art30 — Records of processing activities (RoPA)","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-gdpr-gdpr-art30-e7db10f3.bfc8ae4f79ddd44c.json"},{"attributes":{"category":"administrative","framework":"gdpr","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/gdpr/","description":"Lawfulness of processing","details":{"automation":"manual","control_category":"administrative","control_id":"GDPR-Art6","control_type":"preventive","domains":["Data Protection & Privacy","Governance, Policy & Oversight","Incident Management & Response","Third-Party / Supply-Chain Risk","Risk Assessment & Management"],"framework":"gdpr","group":"EU GDPR","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"8d547d906d76036b88426a98d96d7381c473f905360626bacf3f0caba68f7156","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-gdpr-gdpr-art6-cbe66aa0.html","id":"ctrl:gdpr:GDPR-Art6","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Agdpr%3AGDPR-Art6","sourceIds":["gdpr"],"sourceUrl":null,"title":"GDPR-Art6 — Lawfulness of processing","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-gdpr-gdpr-art6-cbe66aa0.418586ffc5da184f.json"},{"attributes":{"category":"physical","framework":"hipaa","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/hipaa/","description":"Physical safeguards (facility access controls, workstation use/security, device and media controls)","details":{"automation":"hybrid","control_category":"physical","control_id":"HIPAA-164.310","control_type":"preventive","domains":["Governance, Policy & Oversight","Risk Assessment & Management","Access Control & Identity Management","Physical & Environmental Security","Logging, Monitoring & Detection","Business Continuity & Disaster Recovery","Third-Party / Supply-Chain Risk","Data Protection & Privacy"],"framework":"hipaa","group":"HIPAA Security Rule","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"adb12c362e92d36aa4096751d1e9dd3b72bf81fd1edc0197528761c69ab52c41","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-hipaa-hipaa-164-310-9cf84fad.html","id":"ctrl:hipaa:HIPAA-164.310","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Ahipaa%3AHIPAA-164.310","sourceIds":["hipaa"],"sourceUrl":null,"title":"HIPAA-164.310 — Physical safeguards (facility access controls, workstation use/security, device and media controls)","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-hipaa-hipaa-164-310-9cf84fad.c50f954814bf68ca.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Acceptable use of information and other associated assets","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.10","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"dc13f309cb6e0e31f2b9f96d9f27d2d645f570347fc2f0f80588c10113bba8ce","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-10-2d5f0877.html","id":"ctrl:iso-27001:A.5.10","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.10","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.10 — Acceptable use of information and other associated assets","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-5-10-2d5f0877.ef8c9213d8ba9031.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Return of assets","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.11","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"e982ce05616cda124a8573bae660af8a20fc0720b305cc8e5a689f954d254c11","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-11-07680424.html","id":"ctrl:iso-27001:A.5.11","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.11","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.11 — Return of assets","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-5-11-07680424.ea23ac0f736f6e84.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Classification of information","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.12","control_type":"preventive","domains":["Asset Management & Inventory","Data Protection & Privacy"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"27a99da8e743c3e724eb3d9d19522c16e684df1a1e8263af704db04ddf740677","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-12-eb4887b2.html","id":"ctrl:iso-27001:A.5.12","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.12","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.12 — Classification of information","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-5-12-eb4887b2.1504284e69a6bfc2.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Labelling of information","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.13","control_type":"preventive","domains":["Asset Management & Inventory","Data Protection & Privacy"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"2208cdb3fa25bfedcbf9507b289a5b8ff92e3820e4fe3c71e96aacdfd29d2673","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-13-b1e84751.html","id":"ctrl:iso-27001:A.5.13","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.13","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.13 — Labelling of information","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-5-13-b1e84751.bc5555281a428bde.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Information transfer","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.14","control_type":"preventive","domains":["Asset Management & Inventory","Network & Communications Security"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":1,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"163fe4e37c4fabc4e2c332bcb2aceae0a8e8d920feb8a205417b33ac15e24d32","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-14-c427daf1.html","id":"ctrl:iso-27001:A.5.14","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.14","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.14 — Information transfer","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-5-14-c427daf1.2bc199273c42d0df.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Intellectual property rights","details":{"automation":"manual","control_category":"administrative","control_id":"A.5.32","control_type":"preventive","domains":["Compliance, Audit & Assurance"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"335bab2c5a9659bda2a44f1752c9b435440a19ed8341bf5737e8c3b915624a6b","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-32-7342e3f4.html","id":"ctrl:iso-27001:A.5.32","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.32","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.32 — Intellectual property rights","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-5-32-7342e3f4.555732b191121c02.json"},{"attributes":{"category":"administrative","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Inventory of information and other associated assets","details":{"automation":"hybrid","control_category":"administrative","control_id":"A.5.9","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Organizational controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"3101901b4f5a8a9525bdfbc3cc29ae44e7669b08e6f8e64ac0a1993cb187b729","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-5-9-64706ee7.html","id":"ctrl:iso-27001:A.5.9","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.5.9","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.5.9 — Inventory of information and other associated assets","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-5-9-64706ee7.fabe690729cb3123.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Physical security perimeters","details":{"automation":"manual","control_category":"physical","control_id":"A.7.1","control_type":"preventive","domains":["Physical & Environmental Security"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"95fd0e28654651ce265083fc4ed306d55d3d2019ec547572b8472b89381213d5","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-1-a327b00e.html","id":"ctrl:iso-27001:A.7.1","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.1","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.1 — Physical security perimeters","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-7-1-a327b00e.91948f0c9a507375.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Storage media","details":{"automation":"manual","control_category":"physical","control_id":"A.7.10","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"1b99afe8c4c659056a8e7b2004284af27123be09b56cab162807ddca14cd1480","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-10-2bfc8971.html","id":"ctrl:iso-27001:A.7.10","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.10","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.10 — Storage media","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-7-10-2bfc8971.82ef637c31f957f6.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Secure disposal or re-use of equipment","details":{"automation":"manual","control_category":"physical","control_id":"A.7.14","control_type":"preventive","domains":["Asset Management & Inventory","Physical & Environmental Security"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"a0ef86d5af4cddc0a7185ac301821e8553bb9b187e667b53b62c8e21c4be37e3","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-14-5ada9a8e.html","id":"ctrl:iso-27001:A.7.14","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.14","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.14 — Secure disposal or re-use of equipment","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-7-14-5ada9a8e.86027db86007f91d.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Physical entry","details":{"automation":"hybrid","control_category":"physical","control_id":"A.7.2","control_type":"preventive","domains":["Physical & Environmental Security"],"framework":"iso-27001","group":"Physical controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"13cd66ecd8e8b2493ae1828552524502d2ed0f8045c6d5622f48ffcdd5d53903","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-2-7f774ee6.html","id":"ctrl:iso-27001:A.7.2","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.2","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.2 — Physical entry","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-7-2-7f774ee6.e7a23742722e89b4.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Securing offices, rooms and facilities","details":{"automation":"manual","control_category":"physical","control_id":"A.7.3","control_type":"preventive","domains":["Physical & Environmental Security"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"acbf0023727f7d776b5593bc3624f1b83cbc4fa18c5ca506a5f2af6eaffd5ba6","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-3-1b2f4ae0.html","id":"ctrl:iso-27001:A.7.3","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.3","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.3 — Securing offices, rooms and facilities","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-7-3-1b2f4ae0.501a6bacddaea0a7.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"detective"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Physical security monitoring","details":{"automation":"hybrid","control_category":"physical","control_id":"A.7.4","control_type":"detective","domains":["Physical & Environmental Security"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"dc502d5c71818504d97ba9436a6d9ba1b4aec8f97b13f598fb96aa697d2f56dd","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-4-9f51f324.html","id":"ctrl:iso-27001:A.7.4","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.4","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.4 — Physical security monitoring","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-7-4-9f51f324.4c6014a94b595eeb.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Working in secure areas","details":{"automation":"manual","control_category":"physical","control_id":"A.7.6","control_type":"preventive","domains":["Physical & Environmental Security"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"47f2f2c0c574a51b94cda7d07ecfa44190a664be7f5534d932be6b13dea0ab33","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-6-3e5f12bc.html","id":"ctrl:iso-27001:A.7.6","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.6","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.6 — Working in secure areas","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-7-6-3e5f12bc.9cb0af3529e788c0.json"},{"attributes":{"category":"physical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Security of assets off-premises","details":{"automation":"manual","control_category":"physical","control_id":"A.7.9","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Physical controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"63b41153943b5095918ff37ca656dbc519eb358fa7b9287e4fd0e51d091e26d5","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-7-9-43947bba.html","id":"ctrl:iso-27001:A.7.9","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.7.9","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.7.9 — Security of assets off-premises","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-7-9-43947bba.4ed7cbb9266feb6d.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"User endpoint devices","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.1","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"01542fcea4889c4e3dad564c4bfe4bd1e2e03d9d90c523e6c172aaa89f0746f8","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-1-12f14999.html","id":"ctrl:iso-27001:A.8.1","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.1","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.1 — User endpoint devices","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-8-1-12f14999.f24810689ad360f7.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Information deletion","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.10","control_type":"preventive","domains":["Data Protection & Privacy"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":3,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"74fb26e84d818eefd0b534c6636f7ff1bfc0f631e37cb603889e12ca131ed3a7","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-10-8e3feb8b.html","id":"ctrl:iso-27001:A.8.10","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.10","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.10 — Information deletion","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-8-10-8e3feb8b.8c6b988be73a9f9f.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"corrective"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Information backup","details":{"automation":"automated","control_category":"technical","control_id":"A.8.13","control_type":"corrective","domains":["Business Continuity & Disaster Recovery"],"framework":"iso-27001","group":"Technological controls","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"a3cff3d0d3614b605532b6235f0bdc81510e18504c44556a61e482de0784b3c9","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-13-23e70806.html","id":"ctrl:iso-27001:A.8.13","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.13","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.13 — Information backup","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-8-13-23e70806.1b7764dedaab6c95.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"corrective"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Redundancy of information processing facilities","details":{"automation":"automated","control_category":"technical","control_id":"A.8.14","control_type":"corrective","domains":["Business Continuity & Disaster Recovery"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"d909ea9cf16e39720f0547e34335f54ab7f19f3e224f107241498d398ac924af","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-14-3901c4da.html","id":"ctrl:iso-27001:A.8.14","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.14","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.14 — Redundancy of information processing facilities","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-8-14-3901c4da.97a52fce97e87d14.json"},{"attributes":{"category":"technical","framework":"iso-27001","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/iso-27001/","description":"Installation of software on operational systems","details":{"automation":"hybrid","control_category":"technical","control_id":"A.8.19","control_type":"preventive","domains":["Secure Configuration & Change Management"],"framework":"iso-27001","group":"Technological controls","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"9dfcf2fed4205593e27bc9f6fa0dcc5552095df25bbad78014d74fc99dc404c1","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-iso-27001-a-8-19-44c22e39.html","id":"ctrl:iso-27001:A.8.19","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Aiso-27001%3AA.8.19","sourceIds":["iso-27001"],"sourceUrl":null,"title":"A.8.19 — Installation of software on operational systems","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-iso-27001-a-8-19-44c22e39.105ef1b2433fd422.json"},{"attributes":{"category":"administrative","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-800-53/","description":"Use of External Systems","details":{"automation":"manual","control_category":"administrative","control_id":"AC-20","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"nist-800-53","group":"Access Control","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":4,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"4786f5a9b189312d4cb2cb9e2e2e75bd9304cbb2908c789637a8551582a926b2","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-800-53-ac-20-6e822026.html","id":"ctrl:nist-800-53:AC-20","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-800-53%3AAC-20","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"AC-20 — Use of External Systems","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-800-53-ac-20-6e822026.1e1f474dd66851ac.json"},{"attributes":{"category":"administrative","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-800-53/","description":"Software Usage Restrictions","details":{"automation":"manual","control_category":"administrative","control_id":"CM-10","control_type":"preventive","domains":["Secure Configuration & Change Management","Asset Management & Inventory"],"framework":"nist-800-53","group":"Configuration Management","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"4174ba7be236a9b9fad5e267568cc335625231ec2aea87ef75e8c8e3c33cd9af","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-800-53-cm-10-5490946c.html","id":"ctrl:nist-800-53:CM-10","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-800-53%3ACM-10","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CM-10 — Software Usage Restrictions","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-800-53-cm-10-5490946c.240cbeb0b0a4a5e7.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-800-53/","description":"User-installed Software","details":{"automation":"hybrid","control_category":"technical","control_id":"CM-11","control_type":"preventive","domains":["Secure Configuration & Change Management"],"framework":"nist-800-53","group":"Configuration Management","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"52a8714cb9b4deb25d4aa833039266e5ac59047aec4dd030c0428efc37902b8b","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-800-53-cm-11-8a205c95.html","id":"ctrl:nist-800-53:CM-11","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-800-53%3ACM-11","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CM-11 — User-installed Software","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-800-53-cm-11-8a205c95.d9bd41b1bae27727.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-800-53/","description":"Signed Components","details":{"automation":"automated","control_category":"technical","control_id":"CM-14","control_type":"preventive","domains":["Secure Configuration & Change Management","Asset Management & Inventory"],"framework":"nist-800-53","group":"Configuration Management","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"8c992c57e1f78c81c0d0ea8048b4d879abca9659a37ce1f80f1bee83865862af","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-800-53-cm-14-64650a51.html","id":"ctrl:nist-800-53:CM-14","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-800-53%3ACM-14","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CM-14 — Signed Components","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-800-53-cm-14-64650a51.8f5e9e098a8df459.json"},{"attributes":{"category":"administrative","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-800-53/","description":"System Component Inventory","details":{"automation":"hybrid","control_category":"administrative","control_id":"CM-8","control_type":"preventive","domains":["Asset Management & Inventory"],"framework":"nist-800-53","group":"Configuration Management","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"173f6e12fc39e78742b9ff075bc8e1dc12f4813c2e17e42410e3a65a77fbb5e6","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-800-53-cm-8-d6b0ba27.html","id":"ctrl:nist-800-53:CM-8","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-800-53%3ACM-8","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CM-8 — System Component Inventory","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-800-53-cm-8-d6b0ba27.c30eae65e3cbaaf2.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"corrective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-800-53/","description":"System Recovery and Reconstitution","details":{"automation":"hybrid","control_category":"technical","control_id":"CP-10","control_type":"corrective","domains":["Business Continuity & Disaster Recovery"],"framework":"nist-800-53","group":"Contingency Planning","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":5,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"f01ae76a94b31e5daccba68f57cc44c16c986725fbf624b01c1068e33dc2d4c7","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-800-53-cp-10-8d8dfd5a.html","id":"ctrl:nist-800-53:CP-10","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-800-53%3ACP-10","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CP-10 — System Recovery and Reconstitution","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-800-53-cp-10-8d8dfd5a.048fec295f6b1938.json"},{"attributes":{"category":"physical","framework":"nist-800-53","type":"corrective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-800-53/","description":"Alternate Storage Site","details":{"automation":"manual","control_category":"physical","control_id":"CP-6","control_type":"corrective","domains":["Business Continuity & Disaster Recovery"],"framework":"nist-800-53","group":"Contingency Planning","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"49c1db80a628adf0b42fad2c0d45553b65575c449335f59ffedf18c018c6eaf2","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-800-53-cp-6-8b2868ea.html","id":"ctrl:nist-800-53:CP-6","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-800-53%3ACP-6","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CP-6 — Alternate Storage Site","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-800-53-cp-6-8b2868ea.f1351d55524c442d.json"},{"attributes":{"category":"physical","framework":"nist-800-53","type":"corrective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-800-53/","description":"Alternate Processing Site","details":{"automation":"manual","control_category":"physical","control_id":"CP-7","control_type":"corrective","domains":["Business Continuity & Disaster Recovery"],"framework":"nist-800-53","group":"Contingency Planning","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"53d1b3660e2bc21078f7173b8e00e3718607ce861194ed3e1664ad6588101cd9","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-800-53-cp-7-b42f3ba9.html","id":"ctrl:nist-800-53:CP-7","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-800-53%3ACP-7","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CP-7 — Alternate Processing Site","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-800-53-cp-7-b42f3ba9.b5e31c327885656b.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"corrective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-800-53/","description":"Telecommunications Services","details":{"automation":"hybrid","control_category":"technical","control_id":"CP-8","control_type":"corrective","domains":["Business Continuity & Disaster Recovery"],"framework":"nist-800-53","group":"Contingency Planning","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"7f9c94895305ef059223a30b11d58fc1fb640469d49197a1303db616458e522f","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-800-53-cp-8-cc006118.html","id":"ctrl:nist-800-53:CP-8","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-800-53%3ACP-8","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CP-8 — Telecommunications Services","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-800-53-cp-8-cc006118.7144d1b216b73353.json"},{"attributes":{"category":"technical","framework":"nist-800-53","type":"corrective"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-800-53/","description":"System Backup","details":{"automation":"automated","control_category":"technical","control_id":"CP-9","control_type":"corrective","domains":["Business Continuity & Disaster Recovery"],"framework":"nist-800-53","group":"Contingency Planning","key_control":true,"requirement_frequency":null,"requirement_status":null,"risk_count":6,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"6ec7ed24bb47858a383a1a09ca59be29c21f9289374c752479749bc2a69d1c89","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-800-53-cp-9-d9112bea.html","id":"ctrl:nist-800-53:CP-9","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-800-53%3ACP-9","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"CP-9 — System Backup","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-800-53-cp-9-d9112bea.8ac0dd412d4db644.json"},{"attributes":{"category":"administrative","framework":"nist-800-53","type":"preventive"},"canonicalUrl":"https://evidenceflows.com/frameworks/nist-800-53/","description":"Maintenance Tools","details":{"automation":"manual","control_category":"administrative","control_id":"MA-3","control_type":"preventive","domains":["Secure Configuration & Change Management"],"framework":"nist-800-53","group":"Maintenance","key_control":false,"requirement_frequency":null,"requirement_status":null,"risk_count":2,"source_pages":null,"source_url":null},"direct":false,"history":{"digest":"41c9d1e67430b08be5196f1d3c8c8ae77e54bde739d3e5dfe0b7a963d3f2532f","firstSeenAt":"2026-09-17T22:28:00Z","firstSeenRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","updatedAt":"2026-09-17T22:28:00Z","updatedRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e"},"htmlUrl":"/agents/records/ctrl-nist-800-53-ma-3-1dc1f1d5.html","id":"ctrl:nist-800-53:MA-3","mapUrl":"https://evidenceflows.com/?v=1&node=ctrl%3Anist-800-53%3AMA-3","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"MA-3 — Maintenance Tools","type":"control","updatedAt":"2026-09-17T22:28:00Z","url":"/assets/agent_record-ctrl-nist-800-53-ma-3-1dc1f1d5.ad0ddb8d77f90cab.json"}],"relationships":[{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:0193ee372df87471f989640b9a67875fec12d77ca2480b3c725772ea14d52169","properties":{"control_id":"A.8.1","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-1-12f14999.json","targetId":"ctrl:iso-27001:A.8.1","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:066a3a0e5eb15d5845581b56b0e1609668817c04ae2412887b1e532a9815acfd","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-1-a327b00e.json","sourceId":"ctrl:iso-27001:A.7.1","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:10d0f981e11b450b1cb9af6b4c7f2a68baebfa3b64cfe1f67f257533fd9a70c9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-ma-3-1dc1f1d5.json","sourceId":"ctrl:nist-800-53:MA-3","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:10f2c8f3da582a25784d9db0b56806fe33641235b08257f7ed6a433ed4973603","properties":{"control_id":"A.7.10","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-10-2bfc8971.json","targetId":"ctrl:iso-27001:A.7.10","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:147ae985b733872ac1b56a5c69d128a1273023f70c2ca3795bb209a971d54203","properties":{"control_id":"A.8.13","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-03-d30f4ccf.json","sourceId":"uc:UC-BCDR-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-13-23e70806.json","targetId":"ctrl:iso-27001:A.8.13","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:154d032b8c8a51251df0659b39df888301f7cb7aae1f872ad0aa66f4279be75b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-310-9cf84fad.json","sourceId":"ctrl:hipaa:HIPAA-164.310","targetDetailPath":"/data/v1/records/std-hipaa-a825d271.json","targetId":"std:hipaa","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:165477b789f44ce9d930421335c11f36733e2cb74deaafce7580ec576dacad75","properties":{"control_id":"MEA03","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-24-fa96fe18.json","sourceId":"uc:UC-AUDIT-24","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-mea03-99c7dcca.json","targetId":"ctrl:cobit-2019:MEA03","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:169d6622df6fde59aa992aa7416fb7c99cae450e0c56b5f5b5e87dc64e061da5","properties":{"control_id":"A.7.6","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-6-3e5f12bc.json","targetId":"ctrl:iso-27001:A.7.6","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:176b2ff48f0328e6487bbba5bb2db8598d2eed6505c55c794d9b1c1b814e9dcc","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-14-5ada9a8e.json","sourceId":"ctrl:iso-27001:A.7.14","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:180cd078fc831b671b5afb4ab1987c145fe458af88d172f34c611ab5240242d8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art30-e7db10f3.json","sourceId":"ctrl:gdpr:GDPR-Art30","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:18457278e43b410f52161ca8640e0370690eb4a499175ad48b54070e4905c372","properties":{"control_id":"A.7.9","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-9-43947bba.json","targetId":"ctrl:iso-27001:A.7.9","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:1e436015deeb46e84ecb360078a2ec5da9b1a73ab35cb977613f368ef5081c90","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-10-5490946c.json","sourceId":"ctrl:nist-800-53:CM-10","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:1f351b41c6da0c2df1781cfe55b9bd525fa4f987dd6f2432800908487b9d0e8e","properties":{"control_id":"A.7.1","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-1-a327b00e.json","targetId":"ctrl:iso-27001:A.7.1","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:20e4b2a31e5517b32fa223ea9b1b8fd79f1f9756c4fd2ee3519a688b1e5e002f","properties":{"control_id":"DSS02","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss02-af5bca5d.json","targetId":"ctrl:cobit-2019:DSS02","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:238a45d8ea4f46ef5f4ceef5591956db44382d3276460b6165f8af6cac02f025","properties":{"control_id":"A.5.14","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-08-7413af1c.json","sourceId":"uc:UC-ASSET-08","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-14-c427daf1.json","targetId":"ctrl:iso-27001:A.5.14","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:2525c39295ea228ebb567a859879ac822a2efc6cfd453409cbb70d179fbbcfac","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-3-1b2f4ae0.json","sourceId":"ctrl:iso-27001:A.7.3","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:27dd5e945af28141d844fab51e3199d7c1f67cead03cf2660e5481fa101c8ec7","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-9-64706ee7.json","sourceId":"ctrl:iso-27001:A.5.9","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:2cb89276c4531270f1a98b51d3cff3d981127e180cb4fac86e7f8a121b6ed785","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-9-d9112bea.json","sourceId":"ctrl:nist-800-53:CP-9","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:2e2b50c86f8b2218c14fb4e9569a5c8a0507a11726b723c80dff2fd945514676","properties":{"control_id":"A.8.10","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-data-09-f83a01a3.json","sourceId":"uc:UC-DATA-09","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-10-8e3feb8b.json","targetId":"ctrl:iso-27001:A.8.10","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:2fa9ee745188901dc9cf334d826e8e52a294a06c63ae786f99df85acdb98780d","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-dss02-af5bca5d.json","sourceId":"ctrl:cobit-2019:DSS02","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:3165ad3f02bcdb9746b97d6edcc165a99e985acca005200d7abf6cd12495da6a","properties":{"control_id":"A.5.13","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","sourceId":"uc:UC-ASSET-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-13-b1e84751.json","targetId":"ctrl:iso-27001:A.5.13","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:36569c96d581a0f13c86b5cebcc2272b76c64149dd4942b9c22b3145bcbefe45","properties":{"control_id":"A.5.12","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-03-3e6216cd.json","sourceId":"uc:UC-ASSET-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-12-eb4887b2.json","targetId":"ctrl:iso-27001:A.5.12","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:39b30f0980dc2a4c11b9ce2b623bbf9a939d0e5b5aace19f0d2e7cc96a2afa98","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-10-8e3feb8b.json","sourceId":"ctrl:iso-27001:A.8.10","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:3cdceed58717a8955895a09f9613a3e23c9f0f9b2ca82d5699366641c3d670d2","properties":{"control_id":"A.5.11","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-07-5039208b.json","sourceId":"uc:UC-ASSET-07","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-11-07680424.json","targetId":"ctrl:iso-27001:A.5.11","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:3dbf331723a49242ebe31772d373a6634fca02ad4e43de322e54db40626811f5","properties":{"control_id":"A.7.4","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-02-05f35d07.json","sourceId":"uc:UC-PHYS-02","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-4-9f51f324.json","targetId":"ctrl:iso-27001:A.7.4","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:42ae85e554b79183ad5bea734690a293ff4d9ee213e7f81c944c2c034d22b91e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-10-8d8dfd5a.json","sourceId":"ctrl:nist-800-53:CP-10","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:44cc4186b5c1bb4eff60a99d8daf742e4590cc9298b27c249ab8845d231946b4","properties":{"control_id":"A.7.3","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-3-1b2f4ae0.json","targetId":"ctrl:iso-27001:A.7.3","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:487724165a10b9798cbe1ef95c6cb5b09f052f518fe78f70353322a25de9a5db","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-14-3901c4da.json","sourceId":"ctrl:iso-27001:A.8.14","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:512ba21439e87bc291748f791f63165c51c302598232ea229c29542a3578a201","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-dss03-2540740f.json","sourceId":"ctrl:cobit-2019:DSS03","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:51eb1aaf372e56e178e80a1502ebfcf0f2725d63b17c3f28280480fc3cce7f20","properties":{"control_id":"A.7.2","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-2-7f774ee6.json","targetId":"ctrl:iso-27001:A.7.2","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:521a89a1ca7581bbd368a446574c3a54f920420d19d82a0f4a5512f7200a8cd7","properties":{"control_id":"P13","coverage":"partial","delta":"COSO expects quality information supporting all internal control components","framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-02-6c6ac61b.json","sourceId":"uc:UC-ASSET-02","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p13-0c70843b.json","targetId":"ctrl:coso-ic:P13","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:524a42280be8e0712969b39078dfe8a89b3683d09127c7a7556f44b8bc25f7f9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-6-8b2868ea.json","sourceId":"ctrl:nist-800-53:CP-6","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:5a1cadd30ef153d96c37530c120af1562f4fc2e98f1b340e21fb987963c815f7","properties":{"control_id":"A.8.19","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-config-05-84d5ee43.json","sourceId":"uc:UC-CONFIG-05","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-19-44c22e39.json","targetId":"ctrl:iso-27001:A.8.19","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:6211dca87613b36dc26a16c224980c7d5e044c31c777bf4c86c9880d1a51ee8e","properties":{"control_id":"A.5.10","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-10-2d5f0877.json","targetId":"ctrl:iso-27001:A.5.10","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:6245560e88a0b25a51c060ec56866eed4994290ee0d92752753fc75bd841b7e1","properties":{"control_id":"A.5.32","coverage":"partial","delta":"operational IPR safeguards - license/asset registers with usage-vs-entitlement enforcement, proof-of-license retention, and acquisition from authorized sources - beyond registering and periodically evaluating the obligation","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-24-fa96fe18.json","sourceId":"uc:UC-AUDIT-24","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-32-7342e3f4.json","targetId":"ctrl:iso-27001:A.5.32","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:6301bb8cf6f4875e4d952e85a9fc2d0b2bed417d787eecd0b09b7a45ed5a94c8","properties":{"control_id":"CM-11","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-config-05-84d5ee43.json","sourceId":"uc:UC-CONFIG-05","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-11-8a205c95.json","targetId":"ctrl:nist-800-53:CM-11","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:66b3d3aad91497c34fbf2759a01d50a1872a5c3b0a00bc4fb7a7ea0a60d7ef30","properties":{"control_id":"MA-3","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-config-08-e94308da.json","sourceId":"uc:UC-CONFIG-08","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ma-3-1dc1f1d5.json","targetId":"ctrl:nist-800-53:MA-3","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:67a81d9aca89e4727d57d92fc43b1c8cbe3b0c88584059ee23fb1534698bdc32","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-coso-ic-p13-0c70843b.json","sourceId":"ctrl:coso-ic:P13","targetDetailPath":"/data/v1/records/std-coso-ic-3f80f565.json","targetId":"std:coso-ic","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:6af614e2df6e6cbc6408a920bff22a8f313e53b22bf9fd40b97a28f4fb1e3822","properties":{"control_id":"AC-20","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-06-d13d9c7f.json","sourceId":"uc:UC-ASSET-06","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-20-6e822026.json","targetId":"ctrl:nist-800-53:AC-20","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:6c4f29c5c1ef53eef065930a6efca8c7f780ffff4c3c5becbf5a5c49ab2ec6b3","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-14-64650a51.json","sourceId":"ctrl:nist-800-53:CM-14","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:6cd84798e905847e4af7974212aca5ac6b13a2458f611342d5d25dac426d73e0","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-14-c427daf1.json","sourceId":"ctrl:iso-27001:A.5.14","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:6cd89c31a0f6722453e9f1cb4ee69e4fdb4992f60f3243d03259b9058b5738c2","properties":{"control_id":"DSS01","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"equal","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-12-0d9cc358.json","sourceId":"uc:UC-BCDR-12","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss01-d3ff2961.json","targetId":"ctrl:cobit-2019:DSS01","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:6ea2241cc7573102a2aa155e24e4f6d70ec70c02aab173cecabbec89872ced48","properties":{"control_id":"GDPR-Art6","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-data-01-9fcf72e8.json","sourceId":"uc:UC-DATA-01","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art6-cbe66aa0.json","targetId":"ctrl:gdpr:GDPR-Art6","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:6fa8c61aa8f5bf102eca5de1145906d3c2b635e765a122d5fea40e943b36360a","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-10-2bfc8971.json","sourceId":"ctrl:iso-27001:A.7.10","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:7048bc38b1c19805455ed20fca10e5ab08ce34c3afa5cff4429f02cedf05f05e","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-19-44c22e39.json","sourceId":"ctrl:iso-27001:A.8.19","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:756e56aa28d97bf259c164c3a495b12aa99c615b674fb0906739098afb29070a","properties":{"control_id":"A.8.14","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-04-5d004f42.json","sourceId":"uc:UC-BCDR-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-14-3901c4da.json","targetId":"ctrl:iso-27001:A.8.14","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:7600e8066bd80f681f6cdd1adaff667045e6a5a0ff9a75dcdce290af53c5d65d","properties":{"control_id":"HIPAA-164.310","coverage":"partial","delta":"also covers workstation use/security and device and media controls","framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-phys-01-354431a7.json","sourceId":"uc:UC-PHYS-01","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-310-9cf84fad.json","targetId":"ctrl:hipaa:HIPAA-164.310","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:7b190dc2b7f123c2b0335469fe3cbd6b4641a35e43788a8ef24e109959e26c7b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-7-b42f3ba9.json","sourceId":"ctrl:nist-800-53:CP-7","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:7be827f3f5f3b5ec04d16ec812c4240d136e0301d0b63eca8450857a1eed7d00","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-13-b1e84751.json","sourceId":"ctrl:iso-27001:A.5.13","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:7c4757cbea8a44d57e05fb416fa000732b28c508b262641ae99493be0ed4c882","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-11-07680424.json","sourceId":"ctrl:iso-27001:A.5.11","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:7def629af2e63fd82808e5330d7a6291c876c04b5d6a94c9439d1d9e8229b592","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-10-2d5f0877.json","sourceId":"ctrl:iso-27001:A.5.10","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:84965314f57b1f964f26b51977ca58ae0531e7ad88e5a04a6527a95f2ad721f8","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-20-6e822026.json","sourceId":"ctrl:nist-800-53:AC-20","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:8b9de4df2b9b11f4758d16caba3a14418486d52562080438d56995febeaf4511","properties":{"control_id":"DORA-Art17-23","coverage":"partial","delta":"major-incident report clocks: initial 24h, intermediate 72h, final 1 month","framework":"dora","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Regulation (EU) 2022/2554"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/ctrl-dora-dora-art17-23-9aa7977f.json","targetId":"ctrl:dora:DORA-Art17-23","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:960d0f0d80955dfcf6ff9d5494af149cc09ad90267ced52de0c441b7a6fa5258","properties":{"control_id":"GDPR-Art30","coverage":"full","delta":null,"framework":"gdpr","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Regulation (EU) 2016/679"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-02-6c6ac61b.json","sourceId":"uc:UC-ASSET-02","targetDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art30-e7db10f3.json","targetId":"ctrl:gdpr:GDPR-Art30","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:96f2fb180f84f99fb86941c3b49202eb0caef57d3105f6680d156665adeddebd","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-dss01-d3ff2961.json","sourceId":"ctrl:cobit-2019:DSS01","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:9cf7441a234b2e10473c8821a2cd7077ba4c41b418d5433379f0fdd638b535e2","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-6-3e5f12bc.json","sourceId":"ctrl:iso-27001:A.7.6","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:9f229e45003f2c7c825f7932294437466bf8be9e39c6c4ab0bcb25d8dc6b2192","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-dora-dora-art17-23-9aa7977f.json","sourceId":"ctrl:dora:DORA-Art17-23","targetDetailPath":"/data/v1/records/std-dora-95cf939d.json","targetId":"std:dora","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:a34d1b95310d02df2f38016789331618ad71256de254d7d5290a8d14dc84ba75","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-2-7f774ee6.json","sourceId":"ctrl:iso-27001:A.7.2","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:a3b9aa8dc72577ef82f115806dd492aee5b6087954584bbabb0d498bc835896a","properties":{"control_id":"CP-10","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-07-e5d74596.json","sourceId":"uc:UC-BCDR-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-10-8d8dfd5a.json","targetId":"ctrl:nist-800-53:CP-10","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:a73ec3cd22801fc393e49ceaaaebeb68441349a625535ea5f13c226d0ef9b5ea","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-32-7342e3f4.json","sourceId":"ctrl:iso-27001:A.5.32","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:a945420f1311deb2ede68743201f30e4c3b8977422c38ceae982e25b19d47deb","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-9-43947bba.json","sourceId":"ctrl:iso-27001:A.7.9","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:acbedbf085108cdf393bb33351fbcf48e610d18345317ae33d0037259992e143","properties":{"control_id":"CM-10","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-config-05-84d5ee43.json","sourceId":"uc:UC-CONFIG-05","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-10-5490946c.json","targetId":"ctrl:nist-800-53:CM-10","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:b06dd8979f216ebfd8a54ea6e4a2f9f3783324b5e41888b2bb10b06f271e56e0","properties":{"control_id":"CP-9","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-03-d30f4ccf.json","sourceId":"uc:UC-BCDR-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-9-d9112bea.json","targetId":"ctrl:nist-800-53:CP-9","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:b4899f7912335a7240c0671a7d3f47a9fbe675ab613f66e382e3146270615b93","properties":{"control_id":"A.7.14","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-04-347e095f.json","sourceId":"uc:UC-ASSET-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-14-5ada9a8e.json","targetId":"ctrl:iso-27001:A.7.14","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:b99514009d751c4de5dcc2cc86e5c023aed69f78a104e25390068405c5caf7c9","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-8-cc006118.json","sourceId":"ctrl:nist-800-53:CP-8","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:bb81974adc1ada5498944c8d63e01254f1dd56c1067d93f111a7108e053a2b5f","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-7-4-9f51f324.json","sourceId":"ctrl:iso-27001:A.7.4","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:bf750d3c6442fa00e90c0f7f6c2b6ad46182baf74575d4b56bb9a668ff64f93b","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-1-12f14999.json","sourceId":"ctrl:iso-27001:A.8.1","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:bfb7de3a8015b3a23a00a22565f5ec4ed0ddcdd12489f4bb54574cd8ddbc7472","properties":{"control_id":"DSS03","coverage":"full","delta":null,"framework":"cobit-2019","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2019"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-06-c505e5bd.json","sourceId":"uc:UC-BCDR-06","targetDetailPath":"/data/v1/records/ctrl-cobit-2019-dss03-2540740f.json","targetId":"ctrl:cobit-2019:DSS03","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:cbf5b1fd90a88dc6e4b251867131daf48c0905ada385c3258cfe4fa4ea7b95e1","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-gdpr-gdpr-art6-cbe66aa0.json","sourceId":"ctrl:gdpr:GDPR-Art6","targetDetailPath":"/data/v1/records/std-gdpr-17d65d0b.json","targetId":"std:gdpr","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:cef009418dd209296a5536bef4f3ea2ed698d83ab27d7147585bfe22c8a477fa","properties":{"control_id":"CP-8","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-04-5d004f42.json","sourceId":"uc:UC-BCDR-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-8-cc006118.json","targetId":"ctrl:nist-800-53:CP-8","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:d0ea89650d6c0179809d1fef5a3584ceaeeee59d78450193d0b2c71a83fc4608","properties":{"control_id":"CM-8","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-8-d6b0ba27.json","targetId":"ctrl:nist-800-53:CM-8","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:d47a58eb6d3c1d423e8a62159f33a83555f2ec34e8506657e6f990dfac5cacb5","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-11-8a205c95.json","sourceId":"ctrl:nist-800-53:CM-11","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:d9e6e946442603aaa9b6e365c4fb9d605c4c50779bdc4c1096c55f30636bd335","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-12-eb4887b2.json","sourceId":"ctrl:iso-27001:A.5.12","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:dd37b54a97d7a95a246a6ff755255a6880b917586da6259561c950566b3787b3","properties":{"control_id":"CP-7","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-04-5d004f42.json","sourceId":"uc:UC-BCDR-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-7-b42f3ba9.json","targetId":"ctrl:nist-800-53:CP-7","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:ddb0646430e762b2edd17c5ab6751bb80c3cb89ba0766edd3f89033aacc36cd0","properties":{"control_id":"CP-6","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-bcdr-04-5d004f42.json","sourceId":"uc:UC-BCDR-04","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cp-6-8b2868ea.json","targetId":"ctrl:nist-800-53:CP-6","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:dfe559816aa8494a6d1fd4b26b3aea935be01495f24dc5dffe6db21953a20c19","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-13-23e70806.json","sourceId":"ctrl:iso-27001:A.8.13","targetDetailPath":"/data/v1/records/std-iso-27001-656201bd.json","targetId":"std:iso-27001","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:e115412b6dbd6e8acfd6e03c6f5a8f3d855469e2439b614314f3c5731fa7e439","properties":{"control_id":"A.5.9","coverage":"partial","delta":"inventorying information (data) assets themselves, addressed by the data-inventory control","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-asset-01-04dbd5db.json","sourceId":"uc:UC-ASSET-01","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-9-64706ee7.json","targetId":"ctrl:iso-27001:A.5.9","type":"maps_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:eb4f44d97f08b10b4d8988ddd92feffde262f146c9d895c2b11f7766e58f875d","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-cobit-2019-mea03-99c7dcca.json","sourceId":"ctrl:cobit-2019:MEA03","targetDetailPath":"/data/v1/records/std-cobit-2019-2181ce0c.json","targetId":"std:cobit-2019","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:f28187b4b13bb811680bf53dc2228fd88a3f228694d5dab047c9dd7fc4896441","properties":{},"sourceDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-8-d6b0ba27.json","sourceId":"ctrl:nist-800-53:CM-8","targetDetailPath":"/data/v1/records/std-nist-800-53-94591ee2.json","targetId":"std:nist-800-53","type":"belongs_to"},{"expectedCatalogRevision":"791ff2dd3a45707290badee660f185e514d15f1cf518908628f425c2f2c56ee4","id":"rel:f9b6574049a8871d046cf6854d785cb6baf1e72ff41e7206fc5b9b3e17a9a3cd","properties":{"control_id":"CM-14","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-config-06-31f293f7.json","sourceId":"uc:UC-CONFIG-06","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-cm-14-64650a51.json","targetId":"ctrl:nist-800-53:CM-14","type":"maps_to"}],"schemaVersion":1,"scope":"topics","total":193}
