unified
UC-ACCESS-15 — Design control activities over technology access
Management selects and develops control activities, including general controls over technology, that mitigate identified access-related risks to acceptable levels, documented in a control matrix mapping risks to controls. Control designs cover the technology infrastructure, security management, and acquisition and development processes relevant to access, and are updated as risks and systems change.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-ACCESS-15
- title
- Design control activities over technology access
- statement
- Management selects and develops control activities, including general controls over technology, that mitigate identified access-related risks to acceptable levels, documented in a control matrix mapping risks to controls. Control designs cover the technology infrastructure, security management, and acquisition and development processes relevant to access, and are updated as risks and systems change.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- coso-ic
- control_id
- P10
- coverage
- partial
- delta
- principle applies across all control domains, not only access
- relationship
- intersects_with
- framework
- coso-ic
- control_id
- P11
- coverage
- partial
- delta
- principle applies across all technology domains, not only access
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-15 — Design control activities over technology access mitigates Weak internal control environment enabling fraud and error
- strength
- primary
- rationale
- Selecting and developing control activities and general technology controls (COSO P10/P11) directly builds the control environment.
- UC-ACCESS-15 — Design control activities over technology access mitigates Ineffective ICFR / undisclosed material weakness
- strength
- related
- rationale
- General controls over technology access underpin the ITGC layer supporting reliable financial reporting.
- Control Design operates UC-ACCESS-15 — Design control activities over technology access
- Annual ICFR Scoping & Risk Assessment oversees UC-ACCESS-15 — Design control activities over technology access
- UC-ACCESS-15 — Design control activities over technology access mitigates Internal fraud — asset misappropriation, embezzlement, forgery
- strength
- related
- rationale
- Access control activities limiting unauthorized access reduce opportunity for insider misappropriation.
- UC-ACCESS-15 — Design control activities over technology access maps_to P11 — The organization selects and develops general control activities over technology to support the achievement of objectives.
- framework
- coso-ic
- control_id
- P11
- coverage
- partial
- delta
- principle applies across all technology domains, not only access
- relationship
- intersects_with
- source_version
- 2013
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-ACCESS-15 — Design control activities over technology access maps_to P10 — The organization selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels.
- framework
- coso-ic
- control_id
- P10
- coverage
- partial
- delta
- principle applies across all control domains, not only access
- relationship
- intersects_with
- source_version
- 2013
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.