{"catalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://assureswarm.com/controls/?v=1&node=uc%3AUC-GOV-36","description":"Establish, document, and disseminate policies and procedures for system and communications protection, including the required use of cryptography and encryption, secured communication channels, and multi-factor and strong authentication expectations for remote and privileged access. Review and update these policies at defined intervals and as cryptographic standards and threats evolve.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"SC-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"NIS2-Art21h","coverage":"full","framework":"nis2","relationship":"superset_of"},{"control_id":"NIS2-Art21j","coverage":"partial","delta":"actual deployment of MFA and secured emergency communication systems","framework":"nis2","relationship":"intersects_with"}],"statement":"Establish, document, and disseminate policies and procedures for system and communications protection, including the required use of cryptography and encryption, secured communication channels, and multi-factor and strong authentication expectations for remote and privileged access. Review and update these policies at defined intervals and as cryptographic standards and threats evolve.","title":"Maintain communications security and cryptography policies","unified_id":"UC-GOV-36"},"id":"uc:UC-GOV-36","mapUrl":"https://assureswarm.com/controls/?v=1&node=uc%3AUC-GOV-36","sourceIds":["nis2","nist-800-53"],"sourceUrl":null,"title":"UC-GOV-36 — Maintain communications security and cryptography policies","type":"unified"},"relationships":[{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:166855d3a2e2b69b9c4db7645bbfd56c9cc7d36d893b9f99cdfc09cd532b423c","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/controls/data/v1/records/uc-uc-gov-36-8eac71a2.json","targetId":"uc:UC-GOV-36","type":"tests"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:189b3985dfa4c056997dd2abf022b0f59bd800f8a62097d80e959879fc0e55b0","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-g9-d1e65641.json","sourceId":"wf:G9","targetDetailPath":"/controls/data/v1/records/uc-uc-gov-36-8eac71a2.json","targetId":"uc:UC-GOV-36","type":"oversees"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:251c0e73768ca98fda93f31a33027edba793af39a97341f6031fd10d38f36631","properties":{"rationale":"Establishing communications-security and cryptography policies (encryption, MFA expectations) remedies missing policy for this domain.","strength":"primary"},"sourceDetailPath":"/controls/data/v1/records/uc-uc-gov-36-8eac71a2.json","sourceId":"uc:UC-GOV-36","targetDetailPath":"/controls/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:41aaa7a64c3af985962f3ffbcae842e2e36a2e728a20575c4b0bc514d1fdc3ec","properties":{"control_id":"NIS2-Art21h","coverage":"full","delta":null,"framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/controls/data/v1/records/uc-uc-gov-36-8eac71a2.json","sourceId":"uc:UC-GOV-36","targetDetailPath":"/controls/data/v1/records/ctrl-nis2-nis2-art21h-59950523.json","targetId":"ctrl:nis2:NIS2-Art21h","type":"maps_to"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:5275d1a4960973895785ebf2e65f6f951a2eb9fa4cd28fb7baa7f87e5698bece","properties":{"control_id":"SC-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/controls/data/v1/records/uc-uc-gov-36-8eac71a2.json","sourceId":"uc:UC-GOV-36","targetDetailPath":"/controls/data/v1/records/ctrl-nist-800-53-sc-1-e5853fb5.json","targetId":"ctrl:nist-800-53:SC-1","type":"maps_to"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:6b57a277a7d8f8fa698438f9358b04b4dfa0a04db4dcdaaeab3804dde976104c","properties":{"control_id":"NIS2-Art21j","coverage":"partial","delta":"actual deployment of MFA and secured emergency communication systems","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/controls/data/v1/records/uc-uc-gov-36-8eac71a2.json","sourceId":"uc:UC-GOV-36","targetDetailPath":"/controls/data/v1/records/ctrl-nis2-nis2-art21j-49982c35.json","targetId":"ctrl:nis2:NIS2-Art21j","type":"maps_to"},{"expectedCatalogRevision":"f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e","id":"rel:84597e04a3c368bb0c99544fbdc2d416be456559ea49b7d5f8358d138ae4df6c","properties":{},"sourceDetailPath":"/controls/data/v1/records/wf-c26-0d7976b8.json","sourceId":"wf:C26","targetDetailPath":"/controls/data/v1/records/uc-uc-gov-36-8eac71a2.json","targetId":"uc:UC-GOV-36","type":"operates"}],"schemaVersion":1}
