unified
UC-GOV-31 — Maintain access control, identity, and personnel security policies
Establish, document, and disseminate policies and procedures governing logical access control, identification and authentication, and personnel (human resources) security — covering authorization based on need-to-know and least privilege, credential and authenticator management, and personnel screening, transfer, and termination requirements. Communicate these policies to the workforce and review and update them at defined intervals and upon significant change.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-31
- title
- Maintain access control, identity, and personnel security policies
- statement
- Establish, document, and disseminate policies and procedures governing logical access control, identification and authentication, and personnel (human resources) security — covering authorization based on need-to-know and least privilege, credential and authenticator management, and personnel screening, transfer, and termination requirements. Communicate these policies to the workforce and review and update them at defined intervals and upon significant change.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- nist-800-53
- control_id
- AC-1
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- IA-1
- coverage
- full
- relationship
- superset_of
- framework
- nist-800-53
- control_id
- PS-1
- coverage
- full
- relationship
- superset_of
- framework
- nis2
- control_id
- NIS2-Art21i
- coverage
- partial
- delta
- asset management policy and operational measures
- relationship
- intersects_with
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-GOV-31 — Maintain access control, identity, and personnel security policies maps_to IA-1 — Policy and Procedures
- framework
- nist-800-53
- control_id
- IA-1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-31 — Maintain access control, identity, and personnel security policies mitigates Missing or insufficient security and privacy policies
- strength
- primary
- rationale
- Establishing access-control, identity, and personnel-security policies remedies missing policies and undefined access duties.
- UC-GOV-31 — Maintain access control, identity, and personnel security policies maps_to NIS2-Art21i — Human resources security, access control policies and asset management
- framework
- nis2
- control_id
- NIS2-Art21i
- coverage
- partial
- delta
- asset management policy and operational measures
- relationship
- intersects_with
- source_version
- Directive (EU) 2022/2555
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-31 — Maintain access control, identity, and personnel security policies mitigates Internal fraud — asset misappropriation, embezzlement, forgery
- strength
- related
- rationale
- Least-privilege authorization and personnel screening/termination requirements reduce insider-fraud opportunity.
- UC-GOV-31 — Maintain access control, identity, and personnel security policies maps_to PS-1 — Policy and Procedures
- framework
- nist-800-53
- control_id
- PS-1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- UC-GOV-31 — Maintain access control, identity, and personnel security policies maps_to AC-1 — Policy and Procedures
- framework
- nist-800-53
- control_id
- AC-1
- coverage
- full
- relationship
- superset_of
- delta
- Not provided
- source_version
- Rev. 5
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- Security Policy Suite Review operates UC-GOV-31 — Maintain access control, identity, and personnel security policies
- Security Control Assessment & POA&M Remediation tests UC-GOV-31 — Maintain access control, identity, and personnel security policies
- Policy Lifecycle Management oversees UC-GOV-31 — Maintain access control, identity, and personnel security policies