unified

UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties

A documented access control policy grants access strictly on business need-to-know, with entitlements defined through roles that default to least privilege. Segregation-of-duties conflicts (e.g., request versus approve, develop versus deploy) are defined in a conflict matrix, enforced in systems, and mitigated with compensating controls where unavoidable. Role and entitlement definitions are approved by data or system owners and re-approved whenever they change.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Access Control & Identity Management
type
preventive
category
technical

Details

unified_id
UC-ACCESS-03
title
Enforce least privilege, need-to-know, and segregation of duties
statement
A documented access control policy grants access strictly on business need-to-know, with entitlements defined through roles that default to least privilege. Segregation-of-duties conflicts (e.g., request versus approve, develop versus deploy) are defined in a conflict matrix, enforced in systems, and mitigated with compensating controls where unavoidable. Role and entitlement definitions are approved by data or system owners and re-approved whenever they change.
domain
Access Control & Identity Management
control_type
preventive
control_category
technical
members
  • framework
    nist-800-53
    control_id
    AC-5
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    AC-6
    coverage
    full
    relationship
    superset_of
  • framework
    nist-csf-2
    control_id
    PR.AA-05
    coverage
    partial
    delta
    periodic review of granted access rights, addressed by the access-review control
    relationship
    intersects_with
  • framework
    iso-27001
    control_id
    A.5.15
    coverage
    partial
    delta
    also requires rules controlling physical access to information and assets
    relationship
    intersects_with
  • framework
    soc2
    control_id
    CC6.3
    coverage
    partial
    delta
    modifying/removing access on change and periodic role review handled by companion controls
    relationship
    intersects_with
  • framework
    pci-dss
    control_id
    PCI-Req7
    coverage
    partial
    delta
    semiannual review of all user accounts and privileges (7.2.4) not covered
    relationship
    intersects_with
  • framework
    aiuc-1
    control_id
    A003
    coverage
    partial
    delta
    agent-specific enforcement: data access scoped per task, user role, agent role, and context at inference time
    relationship
    intersects_with
guidance
  • source
    nist-ai-agent-identity
    sourceTitle
    NIST NCCoE: Software and AI Agent Identity and Authorization
    propositionId
    NIST-AGI-03
    propositionTitle
    Context-sensitive authorization and least privilege
    sourcePages
    Concept paper pp. 4, 6: Authorization; Areas of Interest

Source

No record-specific source URL is provided.

Connections