unified
UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle
All accounts are created only on a documented, owner-approved request that specifies role-based entitlements and is uniquely attributable to an individual or service. Access is modified on role change and disabled or removed within one business day of termination or loss of authorization, with dormant accounts automatically disabled after a defined period. All provisioning, modification, and deprovisioning events are logged and retained as evidence.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Access Control & Identity Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-ACCESS-01
- title
- Provision and deprovision accounts through a managed lifecycle
- statement
- All accounts are created only on a documented, owner-approved request that specifies role-based entitlements and is uniquely attributable to an individual or service. Access is modified on role change and disabled or removed within one business day of termination or loss of authorization, with dormant accounts automatically disabled after a defined period. All provisioning, modification, and deprovisioning events are logged and retained as evidence.
- domain
- Access Control & Identity Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- AC-2
- coverage
- partial
- delta
- periodic account review satisfied by the separate access review control
- relationship
- intersects_with
- framework
- soc2
- control_id
- CC6.2
- coverage
- full
- relationship
- superset_of
- framework
- soc1
- control_id
- SOC1-1
- coverage
- partial
- delta
- authentication, periodic review, and privileged access satisfied by companion unified controls
- relationship
- intersects_with
- framework
- sox
- control_id
- ITGC-AC
- coverage
- partial
- delta
- authentication, recertification, privileged access, segregation of duties, and physical access security satisfied by companion controls
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- related
- rationale
- Auto-disabling dormant accounts and prompt termination removal close the orphaned-account vector for unauthorized access.
- UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle mitigates Weak account provisioning/de-registration and access review
- strength
- primary
- rationale
- Owner-approved provisioning with role-based entitlements and 1-business-day deprovisioning on termination directly eliminates orphaned accounts and un-revoked access.
- UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle maps_to ITGC-AC — Access to programs and data — logical and physical access security: authentication, authorization, user provisioning/deprovisioning, periodic access recertification, privileged/administrative access, and segregation of duties enforced via access.
- framework
- sox
- control_id
- ITGC-AC
- coverage
- partial
- delta
- authentication, recertification, privileged access, segregation of duties, and physical access security satisfied by companion controls
- relationship
- intersects_with
- source_version
- SOX §302/§404 (2002), PCAOB AS 2201
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOX ITGC Testing tests UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle
- Offboarding & Access Revocation operates UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle
- UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle maps_to CC6.2 — Prior to issuing system credentials and granting system access, the entity registers and authorizes new internal and external users whose access is administered by the entity. For those users whose access is administered by the entity, user system credentials are removed when user access is no longer authorized.
- framework
- soc2
- control_id
- CC6.2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Type II Interim Testing tests UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle
- UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle maps_to AC-2 — Account Management
- framework
- nist-800-53
- control_id
- AC-2
- coverage
- partial
- delta
- periodic account review satisfied by the separate access review control
- relationship
- intersects_with
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ITGC Change & Provisioning Testing tests UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle
- Employee Onboarding operates UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle
- Transfer & Access Modification operates UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle
- Employee Offboarding operates UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle
- UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle maps_to SOC1-1 — Logical access — controls provide reasonable assurance that logical access to applications, data, and infrastructure is restricted to authorized and appropriate users (authentication, authorization, provisioning/deprovisioning, periodic access review, privileged access).
- framework
- soc1
- control_id
- SOC1-1
- coverage
- partial
- delta
- authentication, periodic review, and privileged access satisfied by companion unified controls
- relationship
- intersects_with
- source_version
- SSAE 18 (current AICPA SOC suite)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- System ITGC Operation operates UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle
- SOC 2 Trust Services Readiness tests UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle
- Onboarding & Access Provisioning operates UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle
- UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle mitigates Excessive privilege and wrong assignment of access rights
- strength
- related
- rationale
- Role-based, owner-approved provisioning and modify-on-role-change help limit wrong assignment and accumulation, but the operative least-privilege defense is role design (UC-03) and periodic access review (UC-02).
- UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- related
- rationale
- Accounts uniquely attributable to individuals plus logged provisioning/modification events underpin the accountability that counters repudiation.
- Joiner-Mover-Leaver Access Lifecycle operates UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle