unified

UC-ACCESS-10 — Authenticate devices and services before granting connections

Devices and services (non-person entities) are uniquely identified and mutually authenticated before local, remote, or network connections are established, using cryptographically verifiable credentials such as certificates or managed service identities. Shared static secrets are prohibited or vaulted, and non-person credentials are inventoried and rotated.

Record JSON · Open in map · Data retrieval guide

Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.

Attributes

domain
Access Control & Identity Management
type
preventive
category
technical

Details

unified_id
UC-ACCESS-10
title
Authenticate devices and services before granting connections
statement
Devices and services (non-person entities) are uniquely identified and mutually authenticated before local, remote, or network connections are established, using cryptographically verifiable credentials such as certificates or managed service identities. Shared static secrets are prohibited or vaulted, and non-person credentials are inventoried and rotated.
domain
Access Control & Identity Management
control_type
preventive
control_category
technical
members
  • framework
    nist-800-53
    control_id
    IA-3
    coverage
    full
    relationship
    superset_of
  • framework
    nist-800-53
    control_id
    IA-9
    coverage
    full
    relationship
    superset_of
guidance
  • source
    nist-ai-agent-identity
    sourceTitle
    NIST NCCoE: Software and AI Agent Identity and Authorization
    propositionId
    NIST-AGI-02
    propositionTitle
    Agent authentication and credential lifecycle
    sourcePages
    Concept paper pp. 4, 7: Authentication; Relevant Standards and Guidelines

Source

No record-specific source URL is provided.

Connections