unified
UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties
A documented access control policy grants access strictly on business need-to-know, with entitlements defined through roles that default to least privilege. Segregation-of-duties conflicts (e.g., request versus approve, develop versus deploy) are defined in a conflict matrix, enforced in systems, and mitigated with compensating controls where unavoidable. Role and entitlement definitions are approved by data or system owners and re-approved whenever they change.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Access Control & Identity Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-ACCESS-03
- title
- Enforce least privilege, need-to-know, and segregation of duties
- statement
- A documented access control policy grants access strictly on business need-to-know, with entitlements defined through roles that default to least privilege. Segregation-of-duties conflicts (e.g., request versus approve, develop versus deploy) are defined in a conflict matrix, enforced in systems, and mitigated with compensating controls where unavoidable. Role and entitlement definitions are approved by data or system owners and re-approved whenever they change.
- domain
- Access Control & Identity Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- AC-5
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- AC-6
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- PR.AA-05
- coverage
- partial
- delta
- periodic review of granted access rights, addressed by the access-review control
- relationship
- intersects_with
- framework
- iso-27001
- control_id
- A.5.15
- coverage
- partial
- delta
- also requires rules controlling physical access to information and assets
- relationship
- intersects_with
- framework
- soc2
- control_id
- CC6.3
- coverage
- partial
- delta
- modifying/removing access on change and periodic role review handled by companion controls
- relationship
- intersects_with
- framework
- pci-dss
- control_id
- PCI-Req7
- coverage
- partial
- delta
- semiannual review of all user accounts and privileges (7.2.4) not covered
- relationship
- intersects_with
- framework
- aiuc-1
- control_id
- A003
- coverage
- partial
- delta
- agent-specific enforcement: data access scoped per task, user role, agent role, and context at inference time
- relationship
- intersects_with
- guidance
- source
- nist-ai-agent-identity
- sourceTitle
- NIST NCCoE: Software and AI Agent Identity and Authorization
- propositionId
- NIST-AGI-03
- propositionTitle
- Context-sensitive authorization and least privilege
- sourcePages
- Concept paper pp. 4, 6: Authorization; Areas of Interest
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties mitigates Revenue-recognition misstatement (fictitious, mis-timed, mis-measured)
- strength
- primary
- rationale
- Segregation of duties across the revenue cycle directly prevents one party initiating and recording fictitious or mis-timed revenue.
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties maps_to CC6.3 — The entity authorizes, modifies, or removes access to data, software, functions, and other protected information assets based on roles, responsibilities, or the system design and changes, giving consideration to the concepts of least privilege and segregation of duties, to meet the entity's objectives.
- framework
- soc2
- control_id
- CC6.3
- coverage
- partial
- delta
- modifying/removing access on change and periodic role review handled by companion controls
- relationship
- intersects_with
- source_version
- 2017 TSC
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties maps_to PR.AA-05 — Identity Management, Authentication, and Access Control: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties
- framework
- nist-csf-2
- control_id
- PR.AA-05
- coverage
- partial
- delta
- periodic review of granted access rights, addressed by the access-review control
- relationship
- intersects_with
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ITGC Change & Provisioning Testing tests UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties informed_by NIST-AGI-03 — Context-sensitive authorization and least privilege
- framework
- nist-ai-agent-identity
- control_id
- NIST-AGI-03
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- February 2026 draft concept paper
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- Concept paper pp. 4, 6: Authorization; Areas of Interest
- SOC 2 Type II Interim Testing tests UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties
- User Access Review & Recertification operates UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- related
- rationale
- Least privilege constrains authorized users from reaching resources beyond their authorization.
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties maps_to AC-5 — Separation of Duties
- framework
- nist-800-53
- control_id
- AC-5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Onboarding & Access Provisioning operates UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties maps_to A.5.15 — Access control
- framework
- iso-27001
- control_id
- A.5.15
- coverage
- partial
- delta
- also requires rules controlling physical access to information and assets
- relationship
- intersects_with
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties mitigates Segregation-of-duties conflicts in financial processes
- strength
- primary
- rationale
- A defined, system-enforced SoD conflict matrix directly prevents concentration of incompatible duties.
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties maps_to AC-6 — Least Privilege
- framework
- nist-800-53
- control_id
- AC-6
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOC 2 Trust Services Readiness tests UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties
- Transfer & Access Modification operates UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties mitigates Insufficient personnel screening and vetting
- strength
- related
- rationale
- Least privilege bounds the blast radius of an inadequately vetted insider, reducing impact if a poorly screened individual turns malicious.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties mitigates Excessive privilege and wrong assignment of access rights
- strength
- primary
- rationale
- Roles defaulting to least privilege on need-to-know are the direct defense against overly broad or wrongly assigned access rights.
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- primary
- rationale
- Need-to-know least privilege directly limits the scope available for abuse of rights and privilege escalation.
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties mitigates Manual journal entries and management-override risk
- strength
- related
- rationale
- SoD separating request from approve limits any one person posting and approving unauthorized journal entries.
- Joiner-Mover-Leaver Access Lifecycle operates UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties maps_to PCI-Req7 — Restrict access to system components and cardholder data by business need to know
- framework
- pci-dss
- control_id
- PCI-Req7
- coverage
- partial
- delta
- semiannual review of all user accounts and privileges (7.2.4) not covered
- relationship
- intersects_with
- source_version
- v4.0.1
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties maps_to A003 — Limit AI agent data access
- framework
- aiuc-1
- control_id
- A003
- coverage
- partial
- delta
- agent-specific enforcement: data access scoped per task, user role, agent role, and context at inference time
- relationship
- intersects_with
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.