unified
UC-ACCESS-10 — Authenticate devices and services before granting connections
Devices and services (non-person entities) are uniquely identified and mutually authenticated before local, remote, or network connections are established, using cryptographically verifiable credentials such as certificates or managed service identities. Shared static secrets are prohibited or vaulted, and non-person credentials are inventoried and rotated.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Access Control & Identity Management
- type
- preventive
- category
- technical
Details
- unified_id
- UC-ACCESS-10
- title
- Authenticate devices and services before granting connections
- statement
- Devices and services (non-person entities) are uniquely identified and mutually authenticated before local, remote, or network connections are established, using cryptographically verifiable credentials such as certificates or managed service identities. Shared static secrets are prohibited or vaulted, and non-person credentials are inventoried and rotated.
- domain
- Access Control & Identity Management
- control_type
- preventive
- control_category
- technical
- members
- framework
- nist-800-53
- control_id
- IA-3
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- IA-9
- coverage
- full
- relationship
- superset_of
- guidance
- source
- nist-ai-agent-identity
- sourceTitle
- NIST NCCoE: Software and AI Agent Identity and Authorization
- propositionId
- NIST-AGI-02
- propositionTitle
- Agent authentication and credential lifecycle
- sourcePages
- Concept paper pp. 4, 7: Authentication; Relevant Standards and Guidelines
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-10 — Authenticate devices and services before granting connections mitigates Remote-work, mobile and split-tunneling exposure
- strength
- related
- rationale
- Requiring verifiable device credentials to connect blocks reintroduction of untrusted or compromised devices.
- UC-ACCESS-10 — Authenticate devices and services before granting connections informed_by NIST-AGI-02 — Agent authentication and credential lifecycle
- framework
- nist-ai-agent-identity
- control_id
- NIST-AGI-02
- coverage
- guidance
- relationship
- informs
- delta
- Not provided
- source_version
- February 2026 draft concept paper
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- sourcePages
- Concept paper pp. 4, 7: Authentication; Relevant Standards and Guidelines
- UC-ACCESS-10 — Authenticate devices and services before granting connections mitigates Weak authentication and password management
- strength
- related
- rationale
- Cryptographic non-person credentials with no shared static secrets extend strong authentication to services and devices.
- UC-ACCESS-10 — Authenticate devices and services before granting connections maps_to IA-3 — Device Identification and Authentication
- framework
- nist-800-53
- control_id
- IA-3
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Secure Connectivity & Network Trust Services Operation operates UC-ACCESS-10 — Authenticate devices and services before granting connections
- UC-ACCESS-10 — Authenticate devices and services before granting connections mitigates Unauthorized use of equipment and unauthorized access escalation
- strength
- primary
- rationale
- Mutually authenticating devices and services before any connection directly blocks rogue or unauthorized devices from connecting.
- Security Control Assessment & POA&M Remediation tests UC-ACCESS-10 — Authenticate devices and services before granting connections
- UC-ACCESS-10 — Authenticate devices and services before granting connections maps_to IA-9 — Service Identification and Authentication
- framework
- nist-800-53
- control_id
- IA-9
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.