unified
UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software
Privileged access rights are individually authorized against a business justification, time-bound or periodically recertified, and issued on separate accounts distinct from daily-use identities. Use of utility programs capable of overriding system or application controls is restricted to authorized administrators and logged. Application allowlisting or equivalent controls prevent installation and execution of unauthorized software on managed systems.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Access Control & Identity Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-ACCESS-04
- title
- Restrict privileged rights, utilities, and unauthorized software
- statement
- Privileged access rights are individually authorized against a business justification, time-bound or periodically recertified, and issued on separate accounts distinct from daily-use identities. Use of utility programs capable of overriding system or application controls is restricted to authorized administrators and logged. Application allowlisting or equivalent controls prevent installation and execution of unauthorized software on managed systems.
- domain
- Access Control & Identity Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-csf-2
- control_id
- PR.PS-05
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.2
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.18
- coverage
- full
- relationship
- superset_of
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software maps_to A.8.2 — Privileged access rights
- framework
- iso-27001
- control_id
- A.8.2
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software
- Privileged Access Review operates UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software
- Privileged Access & Authorization Model Management operates UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software
- UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software mitigates Excessive privilege and wrong assignment of access rights
- strength
- primary
- rationale
- Individually justified, time-bound privileged rights on separate admin accounts directly curb excessive privilege.
- UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software maps_to PR.PS-05 — Platform Security: Installation and execution of unauthorized software are prevented
- framework
- nist-csf-2
- control_id
- PR.PS-05
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software mitigates Manual journal entries and management-override risk
- strength
- primary
- rationale
- Restricting privileged access to the GL/ERP directly limits unauthorized journal entries and top-side management override.
- UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software maps_to A.8.18 — Use of privileged utility programs
- framework
- iso-27001
- control_id
- A.8.18
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- related
- rationale
- Application allowlisting blocks unauthorized software and utility restriction prevents control-override escalation.
- SOX ITGC Testing tests UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software
- UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software mitigates Segregation-of-duties conflicts in financial processes
- strength
- related
- rationale
- Separate admin accounts distinct from daily-use identities enforce develop-vs-deploy duty separation.
- UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- primary
- rationale
- Restricting and logging privileged and utility-program use on separate admin identities directly limits and attributes abuse of rights.