unified
UC-AUDIT-26 — Authorize systems and internal connections before operation
A senior accountable official formally authorizes each system to operate before production use, based on the assessed security and privacy risk to organizational operations, assets, and individuals, and reauthorizes on a defined frequency or after significant change. Internal system connections are authorized prior to establishment and documented, including interface characteristics, security and privacy requirements, and the information communicated. Authorization decisions and connection documentation are retained.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Compliance, Audit & Assurance
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-AUDIT-26
- title
- Authorize systems and internal connections before operation
- statement
- A senior accountable official formally authorizes each system to operate before production use, based on the assessed security and privacy risk to organizational operations, assets, and individuals, and reauthorizes on a defined frequency or after significant change. Internal system connections are authorized prior to establishment and documented, including interface characteristics, security and privacy requirements, and the information communicated. Authorization decisions and connection documentation are retained.
- domain
- Compliance, Audit & Assurance
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- CA-6
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- CA-9
- coverage
- partial
- delta
- periodic review of each internal connection's continued need and termination when no longer required (CA-9(c)-(d))
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-AUDIT-26 — Authorize systems and internal connections before operation mitigates Illegal processing of personal or sensitive data
- strength
- related
- rationale
- The authorization gate forces security/privacy risk to be assessed before operation, contributing to catching unlawful processing, but the operative lawful-basis/consent/DPIA controls directly prevent illegal data processing.
- UC-AUDIT-26 — Authorize systems and internal connections before operation maps_to CA-9 — Internal System Connections
- framework
- nist-800-53
- control_id
- CA-9
- coverage
- partial
- delta
- periodic review of each internal connection's continued need and termination when no longer required (CA-9(c)-(d))
- relationship
- intersects_with
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-AUDIT-26 — Authorize systems and internal connections before operation maps_to CA-6 — Authorization
- framework
- nist-800-53
- control_id
- CA-6
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- System Categorization, Security Planning & Authorization operates UC-AUDIT-26 — Authorize systems and internal connections before operation
- NIST RMF System Authorization (ATO) Cycle oversees UC-AUDIT-26 — Authorize systems and internal connections before operation
- UC-AUDIT-26 — Authorize systems and internal connections before operation mitigates Privacy-program non-compliance (GDPR, CCPA, state laws)
- strength
- related
- rationale
- The pre-operation authorization decision forces privacy requirements to be assessed before a system or internal connection is used.