unified
UC-ACCESS-05 — Enforce approved authorizations for information and functions
Systems mediate every access attempt through a tamper-resistant, always-invoked enforcement mechanism that applies approved authorizations before granting access to information or functions. Restrictions use roles and security attributes bound to data and subjects, limiting access to sensitive information, source code, and administrative functions to explicitly authorized identities. Enforcement rules are applied consistently across applications, databases, and infrastructure and are tested for effectiveness.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Access Control & Identity Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-ACCESS-05
- title
- Enforce approved authorizations for information and functions
- statement
- Systems mediate every access attempt through a tamper-resistant, always-invoked enforcement mechanism that applies approved authorizations before granting access to information or functions. Restrictions use roles and security attributes bound to data and subjects, limiting access to sensitive information, source code, and administrative functions to explicitly authorized identities. Enforcement rules are applied consistently across applications, databases, and infrastructure and are tested for effectiveness.
- domain
- Access Control & Identity Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- AC-3
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- AC-16
- coverage
- partial
- delta
- defining permitted attribute values and auditing/periodically reviewing attribute associations
- relationship
- intersects_with
- framework
- nist-800-53
- control_id
- AC-24
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- AC-25
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.3
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.8.4
- coverage
- full
- relationship
- superset_of
- framework
- gdpr
- control_id
- GDPR-Art32
- coverage
- partial
- delta
- also requires encryption, resilience, and effectiveness testing addressed in other domains
- relationship
- intersects_with
- framework
- hipaa
- control_id
- HIPAA-164.312(a)
- coverage
- partial
- relationship
- intersects_with
- delta
- automatic logoff and encryption/decryption of ePHI are satisfied by the session-lock (UC-ACCESS-12) and cryptographic (UC-CRYPTO-01) companion controls; emergency-access is an availability arm
- framework
- aiuc-1
- control_id
- B007
- coverage
- partial
- delta
- quarterly review of user access privileges to AI systems, including administrative, configuration, and training-data access
- relationship
- intersects_with
- guidance
- source
- nist-ai-agent-identity
- sourceTitle
- NIST NCCoE: Software and AI Agent Identity and Authorization
- propositionId
- NIST-AGI-03
- propositionTitle
- Context-sensitive authorization and least privilege
- sourcePages
- Concept paper pp. 4, 6: Authorization; Areas of Interest
- source
- nist-ai-agent-identity
- sourceTitle
- NIST NCCoE: Software and AI Agent Identity and Authorization
- propositionId
- NIST-AGI-04
- propositionTitle
- Delegated authority and human accountability
- sourcePages
- Concept paper pp. 4, 6: Authorization; Access Delegation
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-05 — Enforce approved authorizations for information and functions informed_by NIST-AGI-03 — Context-sensitive authorization and least privilege
- framework
- nist-ai-agent-identity
- control_id
- NIST-AGI-03
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- February 2026 draft concept paper
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- Concept paper pp. 4, 6: Authorization; Areas of Interest
- UC-ACCESS-05 — Enforce approved authorizations for information and functions informed_by NIST-AGI-04 — Delegated authority and human accountability
- framework
- nist-ai-agent-identity
- control_id
- NIST-AGI-04
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- February 2026 draft concept paper
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- Concept paper pp. 4, 6: Authorization; Access Delegation
- UC-ACCESS-05 — Enforce approved authorizations for information and functions maps_to B007 — Enforce user access privileges to AI systems
- framework
- aiuc-1
- control_id
- B007
- coverage
- partial
- delta
- quarterly review of user access privileges to AI systems, including administrative, configuration, and training-data access
- relationship
- intersects_with
- source_version
- July 15, 2026 release (quarterly update cadence)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-05 — Enforce approved authorizations for information and functions maps_to AC-16 — Security and Privacy Attributes
- framework
- nist-800-53
- control_id
- AC-16
- coverage
- partial
- delta
- defining permitted attribute values and auditing/periodically reviewing attribute associations
- relationship
- intersects_with
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-05 — Enforce approved authorizations for information and functions mitigates Segregation-of-duties conflicts in financial processes
- strength
- related
- rationale
- Role- and attribute-based enforcement applies the SoD separations defined for sensitive financial and administrative functions.
- UC-ACCESS-05 — Enforce approved authorizations for information and functions maps_to GDPR-Art32 — Security of processing
- framework
- gdpr
- control_id
- GDPR-Art32
- coverage
- partial
- delta
- also requires encryption, resilience, and effectiveness testing addressed in other domains
- relationship
- intersects_with
- source_version
- Regulation (EU) 2016/679
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-05 — Enforce approved authorizations for information and functions maps_to AC-24 — Access Control Decisions
- framework
- nist-800-53
- control_id
- AC-24
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-05 — Enforce approved authorizations for information and functions mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- primary
- rationale
- Mediating every access attempt against approved authorizations directly blocks users reaching resources exceeding their authorization.
- UC-ACCESS-05 — Enforce approved authorizations for information and functions maps_to HIPAA-164.312(a) — Technical access control for ePHI (unique user ID, emergency access, automatic logoff, encryption/decryption)
- framework
- hipaa
- control_id
- HIPAA-164.312(a)
- coverage
- partial
- relationship
- intersects_with
- delta
- automatic logoff and encryption/decryption of ePHI are satisfied by the session-lock (UC-ACCESS-12) and cryptographic (UC-CRYPTO-01) companion controls; emergency-access is an availability arm
- source_version
- 45 CFR Parts 160/164 (Security, Privacy, Breach Notification)
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-05 — Enforce approved authorizations for information and functions maps_to A.8.4 — Access to source code
- framework
- iso-27001
- control_id
- A.8.4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-05 — Enforce approved authorizations for information and functions maps_to A.8.3 — Information access restriction
- framework
- iso-27001
- control_id
- A.8.3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-05 — Enforce approved authorizations for information and functions mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- primary
- rationale
- Always-invoked, tamper-resistant authorization enforcement blocks access beyond permitted scope and resists forged rights.
- Privileged Access & Authorization Model Management operates UC-ACCESS-05 — Enforce approved authorizations for information and functions
- SOX ITGC Testing tests UC-ACCESS-05 — Enforce approved authorizations for information and functions
- UC-ACCESS-05 — Enforce approved authorizations for information and functions maps_to AC-3 — Access Enforcement
- framework
- nist-800-53
- control_id
- AC-3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-05 — Enforce approved authorizations for information and functions mitigates Client intake, documentation and account-management failures
- strength
- related
- rationale
- Enforced authorization restricts access to client accounts and data, countering the unauthorized-access-to-client-accounts component.
- Security Control Assessment & POA&M Remediation tests UC-ACCESS-05 — Enforce approved authorizations for information and functions
- UC-ACCESS-05 — Enforce approved authorizations for information and functions maps_to AC-25 — Reference Monitor
- framework
- nist-800-53
- control_id
- AC-25
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ACCESS-05 — Enforce approved authorizations for information and functions