unified

UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle

All accounts are created only on a documented, owner-approved request that specifies role-based entitlements and is uniquely attributable to an individual or service. Access is modified on role change and disabled or removed within one business day of termination or loss of authorization, with dormant accounts automatically disabled after a defined period. All provisioning, modification, and deprovisioning events are logged and retained as evidence.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Access Control & Identity Management
type
preventive
category
technical

Details

unified_id
UC-ACCESS-01
title
Provision and deprovision accounts through a managed lifecycle
statement
All accounts are created only on a documented, owner-approved request that specifies role-based entitlements and is uniquely attributable to an individual or service. Access is modified on role change and disabled or removed within one business day of termination or loss of authorization, with dormant accounts automatically disabled after a defined period. All provisioning, modification, and deprovisioning events are logged and retained as evidence.
domain
Access Control & Identity Management
control_type
preventive
control_category
technical
members
  • framework
    nist-800-53
    control_id
    AC-2
    coverage
    partial
    delta
    periodic account review satisfied by the separate access review control
    relationship
    intersects_with
  • framework
    soc2
    control_id
    CC6.2
    coverage
    full
    relationship
    superset_of
  • framework
    soc1
    control_id
    SOC1-1
    coverage
    partial
    delta
    authentication, periodic review, and privileged access satisfied by companion unified controls
    relationship
    intersects_with
  • framework
    sox
    control_id
    ITGC-AC
    coverage
    partial
    delta
    authentication, recertification, privileged access, segregation of duties, and physical access security satisfied by companion controls
    relationship
    intersects_with
guidance

    Source

    No record-specific source URL is provided.

    Connections