unified
UC-ACCESS-06 — Manage unique identities and identifiers end to end
Every user, service, and device is assigned a unique identifier from an authoritative source; shared or group identifiers are prohibited except under documented approval with compensating controls. Identifiers are issued through a controlled process, mapped to accountable owners, deactivated promptly when no longer needed, and not reused for a defined period.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Access Control & Identity Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-ACCESS-06
- title
- Manage unique identities and identifiers end to end
- statement
- Every user, service, and device is assigned a unique identifier from an authoritative source; shared or group identifiers are prohibited except under documented approval with compensating controls. Identifiers are issued through a controlled process, mapped to accountable owners, deactivated promptly when no longer needed, and not reused for a defined period.
- domain
- Access Control & Identity Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- IA-4
- coverage
- full
- relationship
- superset_of
- framework
- nist-csf-2
- control_id
- PR.AA-01
- coverage
- partial
- delta
- credential issuance and protection satisfied by the authenticator management control
- relationship
- intersects_with
- framework
- iso-27001
- control_id
- A.5.16
- coverage
- full
- relationship
- superset_of
- guidance
- source
- nist-ai-agent-identity
- sourceTitle
- NIST NCCoE: Software and AI Agent Identity and Authorization
- propositionId
- NIST-AGI-01
- propositionTitle
- Distinct agent identities and identity boundaries
- sourcePages
- Concept paper pp. 4, 6: Identification; Areas of Interest
Source
No record-specific source URL is provided.
Connections
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ACCESS-06 — Manage unique identities and identifiers end to end
- UC-ACCESS-06 — Manage unique identities and identifiers end to end maps_to A.5.16 — Identity management
- framework
- iso-27001
- control_id
- A.5.16
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Control Assessment & POA&M Remediation tests UC-ACCESS-06 — Manage unique identities and identifiers end to end
- UC-ACCESS-06 — Manage unique identities and identifiers end to end mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- primary
- rationale
- Unique, non-shared identifiers mapped to accountable owners are the attribution foundation that defeats repudiation of actions.
- UC-ACCESS-06 — Manage unique identities and identifiers end to end mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- related
- rationale
- Prohibiting shared/group IDs and no-reuse rules close shared-account vectors for unauthorized use.
- UC-ACCESS-06 — Manage unique identities and identifiers end to end maps_to PR.AA-01 — Identity Management, Authentication, and Access Control: Identities and credentials for authorized users, services, and hardware are managed by the organization
- framework
- nist-csf-2
- control_id
- PR.AA-01
- coverage
- partial
- delta
- credential issuance and protection satisfied by the authenticator management control
- relationship
- intersects_with
- source_version
- 2.0
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-06 — Manage unique identities and identifiers end to end mitigates Weak account provisioning/de-registration and access review
- strength
- related
- rationale
- Prompt deactivation of identifiers no longer needed supports timely de-registration.
- UC-ACCESS-06 — Manage unique identities and identifiers end to end maps_to IA-4 — Identifier Management
- framework
- nist-800-53
- control_id
- IA-4
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Identity & Authenticator Lifecycle Administration operates UC-ACCESS-06 — Manage unique identities and identifiers end to end
- UC-ACCESS-06 — Manage unique identities and identifiers end to end informed_by NIST-AGI-01 — Distinct agent identities and identity boundaries
- framework
- nist-ai-agent-identity
- control_id
- NIST-AGI-01
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- February 2026 draft concept paper
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- Concept paper pp. 4, 6: Identification; Areas of Interest