unified
UC-ACCESS-08 — Manage and protect authenticators across their lifecycle
Authenticators (passwords, tokens, keys, certificates) are issued through a verified process, with vendor defaults changed before use and minimum strength requirements enforced. Authentication information is protected in storage (salted hashing or encryption) and in transmission, masked during entry, and never embedded in code or scripts. Authenticators are revoked on compromise or separation and rotated at defined intervals or events.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Access Control & Identity Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-ACCESS-08
- title
- Manage and protect authenticators across their lifecycle
- statement
- Authenticators (passwords, tokens, keys, certificates) are issued through a verified process, with vendor defaults changed before use and minimum strength requirements enforced. Authentication information is protected in storage (salted hashing or encryption) and in transmission, masked during entry, and never embedded in code or scripts. Authenticators are revoked on compromise or separation and rotated at defined intervals or events.
- domain
- Access Control & Identity Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- IA-5
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- IA-6
- coverage
- full
- relationship
- superset_of
- framework
- iso-27001
- control_id
- A.5.17
- coverage
- partial
- delta
- advising personnel on proper handling and protection of authentication information
- relationship
- intersects_with
- guidance
- source
- nist-ai-agent-identity
- sourceTitle
- NIST NCCoE: Software and AI Agent Identity and Authorization
- propositionId
- NIST-AGI-02
- propositionTitle
- Agent authentication and credential lifecycle
- sourcePages
- Concept paper pp. 4, 7: Authentication; Relevant Standards and Guidelines
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-08 — Manage and protect authenticators across their lifecycle mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- related
- rationale
- Changing vendor defaults before use closes the default-credential path to unauthorized system use.
- UC-ACCESS-08 — Manage and protect authenticators across their lifecycle mitigates Abuse of rights, forged rights, and repudiation of actions
- strength
- related
- rationale
- Never embedding keys in code and protecting authenticators prevents credential/key forgery used to gain privileges.
- UC-ACCESS-08 — Manage and protect authenticators across their lifecycle maps_to IA-6 — Authentication Feedback
- framework
- nist-800-53
- control_id
- IA-6
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Identity Assurance Review oversees UC-ACCESS-08 — Manage and protect authenticators across their lifecycle
- UC-ACCESS-08 — Manage and protect authenticators across their lifecycle maps_to A.5.17 — Authentication information
- framework
- iso-27001
- control_id
- A.5.17
- coverage
- partial
- delta
- advising personnel on proper handling and protection of authentication information
- relationship
- intersects_with
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-08 — Manage and protect authenticators across their lifecycle mitigates Weak authentication and password management
- strength
- primary
- rationale
- Enforced minimum strength, changed vendor defaults, salted-hash/encrypted storage, and protected transmission directly fix weak-password and clear-text credential exposure.
- UC-ACCESS-08 — Manage and protect authenticators across their lifecycle mitigates External fraud — third-party theft, forgery, payment and account fraud
- strength
- related
- rationale
- Strong, rotated authenticators revoked on compromise reduce stolen-credential account takeover.
- UC-ACCESS-08 — Manage and protect authenticators across their lifecycle informed_by NIST-AGI-02 — Agent authentication and credential lifecycle
- framework
- nist-ai-agent-identity
- control_id
- NIST-AGI-02
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- February 2026 draft concept paper
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- Concept paper pp. 4, 7: Authentication; Relevant Standards and Guidelines
- System ITGC Operation operates UC-ACCESS-08 — Manage and protect authenticators across their lifecycle
- Identity & Authenticator Lifecycle Administration operates UC-ACCESS-08 — Manage and protect authenticators across their lifecycle
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-ACCESS-08 — Manage and protect authenticators across their lifecycle
- UC-ACCESS-08 — Manage and protect authenticators across their lifecycle maps_to IA-5 — Authenticator Management
- framework
- nist-800-53
- control_id
- IA-5
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.