[
{
"control_id": "GV.OC-01",
"control_name": "Organizational context",
"regulation": "UN_R156",
"articles": ["1"],
"coverage": "full",
"notes": "Section 1 scope for software update type approval"
},
{
"control_id": "GV.RM-01",
"control_name": "Risk management objectives",
"regulation": "UN_R156",
"articles": ["7"],
"coverage": "full",
"notes": "Section 7 SUMS requires documented processes"
},
{
"control_id": "GV.RR-01",
"control_name": "Organizational roles and responsibilities",
"regulation": "UN_R156",
"articles": ["7"],
"coverage": "full",
"notes": "Section 7.1.2 organizational processes for SUMS"
},
{
"control_id": "GV.PO-01",
"control_name": "Cybersecurity policy",
"regulation": "UN_R156",
"articles": ["7"],
"coverage": "full",
"notes": "Section 7 requires SUMS policies for secure updates"
},
{
"control_id": "ID.AM-02",
"control_name": "Software platforms and applications inventories",
"regulation": "UN_R156",
"articles": ["7"],
"coverage": "full",
"notes": "Section 7.1.2 RXSWIN for software version tracking"
},
{
"control_id": "ID.RA-01",
"control_name": "Vulnerabilities in assets are identified",
"regulation": "UN_R156",
"articles": ["7"],
"coverage": "full",
"notes": "Section 7 security-relevant software update management"
},
{
"control_id": "PR.DS-02",
"control_name": "Data-in-transit is protected",
"regulation": "UN_R156",
"articles": ["7"],
"coverage": "full",
"notes": "Section 7.2 secure OTA update transmission"
},
{
"control_id": "PR.PS-01",
"control_name": "Configuration management practices established",
"regulation": "UN_R156",
"articles": ["7"],
"coverage": "full",
"notes": "Section 7.1.2 RXSWIN configuration management"
},
{
"control_id": "PR.PS-02",
"control_name": "Software is maintained and updated",
"regulation": "UN_R156",
"articles": ["7"],
"coverage": "full",
"notes": "Section 7 entire regulation focused on software updates"
},
{
"control_id": "DE.AE-02",
"control_name": "Potentially adverse events are analyzed",
"regulation": "UN_R156",
"articles": ["7"],
"coverage": "partial",
"notes": "Section 7.1.3 documentation of update issues"
},
{
"control_id": "RS.MA-01",
"control_name": "Incident response plan is executed",
"regulation": "UN_R156",
"articles": ["7"],
"coverage": "partial",
"notes": "Section 7 update rollback and failure handling"
},
{
"control_id": "RC.RP-01",
"control_name": "Recovery plan is executed",
"regulation": "UN_R156",
"articles": ["7"],
"coverage": "full",
"notes": "Section 7.2 safe update failure recovery"
}
]