unified

UC-ACCESS-05 — Enforce approved authorizations for information and functions

Systems mediate every access attempt through a tamper-resistant, always-invoked enforcement mechanism that applies approved authorizations before granting access to information or functions. Restrictions use roles and security attributes bound to data and subjects, limiting access to sensitive information, source code, and administrative functions to explicitly authorized identities. Enforcement rules are applied consistently across applications, databases, and infrastructure and are tested for effectiveness.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Access Control & Identity Management
type
preventive
category
technical

Details

unified_id
UC-ACCESS-05
title
Enforce approved authorizations for information and functions
statement
Systems mediate every access attempt through a tamper-resistant, always-invoked enforcement mechanism that applies approved authorizations before granting access to information or functions. Restrictions use roles and security attributes bound to data and subjects, limiting access to sensitive information, source code, and administrative functions to explicitly authorized identities. Enforcement rules are applied consistently across applications, databases, and infrastructure and are tested for effectiveness.
domain
Access Control & Identity Management
control_type
preventive
control_category
technical
members
  • framework
    nist-800-53
    control_id
    AC-3
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    AC-16
    coverage
    partial
    delta
    defining permitted attribute values and auditing/periodically reviewing attribute associations
    relationship
    intersects_with
  • framework
    nist-800-53
    control_id
    AC-24
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    AC-25
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.8.3
    coverage
    full
    relationship
    superset_of
  • framework
    iso-27001
    control_id
    A.8.4
    coverage
    full
    relationship
    superset_of
  • framework
    gdpr
    control_id
    GDPR-Art32
    coverage
    partial
    delta
    also requires encryption, resilience, and effectiveness testing addressed in other domains
    relationship
    intersects_with
  • framework
    hipaa
    control_id
    HIPAA-164.312(a)
    coverage
    partial
    relationship
    intersects_with
    delta
    automatic logoff and encryption/decryption of ePHI are satisfied by the session-lock (UC-ACCESS-12) and cryptographic (UC-CRYPTO-01) companion controls; emergency-access is an availability arm
  • framework
    aiuc-1
    control_id
    B007
    coverage
    partial
    delta
    quarterly review of user access privileges to AI systems, including administrative, configuration, and training-data access
    relationship
    intersects_with
guidance
  • source
    nist-ai-agent-identity
    sourceTitle
    NIST NCCoE: Software and AI Agent Identity and Authorization
    propositionId
    NIST-AGI-03
    propositionTitle
    Context-sensitive authorization and least privilege
    sourcePages
    Concept paper pp. 4, 6: Authorization; Areas of Interest
  • source
    nist-ai-agent-identity
    sourceTitle
    NIST NCCoE: Software and AI Agent Identity and Authorization
    propositionId
    NIST-AGI-04
    propositionTitle
    Delegated authority and human accountability
    sourcePages
    Concept paper pp. 4, 6: Authorization; Access Delegation

Source

No record-specific source URL is provided.

Connections