{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"cyber_security","domain":["Access Control & Identity Management","Network & Communications Security"],"inherent_rating":"high","taxonomy":["iso-27005-vulnerability","nist-800-30-threat-event"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-weak-authentication","description":"Absent password policy, no MFA, credentials transmitted in clear text, and no session lock/logout on unattended workstations, making account compromise, brute-force login, and session hijacking easy.","details":{"category":"cyber_security","impact":"high","inherent_rating":"high","likelihood":"high","risk_id":"access-weak-authentication","taxonomies":["iso-27005-vulnerability","nist-800-30-threat-event"],"treatment":"mitigate"},"id":"risk:access-weak-authentication","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Aaccess-weak-authentication","sourceIds":["hipaa","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","nydfs-500","pci-dss"],"sourceUrl":null,"title":"Weak authentication and password management","type":"risk"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:01144b49309d686dda87005af303cb45294f11ef813ebde7d588e64322fb6246","properties":{"rationale":"Terminating connections after inactivity addresses unattended-session/no-logout exposure; primary auth strength owned elsewhere.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-03-3b26b0a0.json","sourceId":"uc:UC-NET-03","targetDetailPath":"/data/v1/records/risk-access-weak-authentication-4e35bdb2.json","targetId":"risk:access-weak-authentication","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5200eef6e0cd5fadc996700f1e305a155cac5ecdde4190bec944281139d8896c","properties":{"rationale":"Requiring mutual authentication before a remote connection is permitted reduces account compromise on those channels; MFA/password policy owned elsewhere.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-net-02-6e84b235.json","sourceId":"uc:UC-NET-02","targetDetailPath":"/data/v1/records/risk-access-weak-authentication-4e35bdb2.json","targetId":"risk:access-weak-authentication","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:59e47333cfc4a11e865b2ae80f798e9897c8f749f41604f34a33da67a77f7d5d","properties":{"rationale":"Cryptographic non-person credentials with no shared static secrets extend strong authentication to services and devices.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-10-130762ce.json","sourceId":"uc:UC-ACCESS-10","targetDetailPath":"/data/v1/records/risk-access-weak-authentication-4e35bdb2.json","targetId":"risk:access-weak-authentication","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5d617594d25b8a41b14088d5998a1bdf055119fb9f57b2e22f2d2fb80e0dae91","properties":{"rationale":"MFA with credential validation only over protected channels directly remediates absent MFA and clear-text authentication.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/risk-access-weak-authentication-4e35bdb2.json","targetId":"risk:access-weak-authentication","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8da0119df622f2584b835fe7c28594eb7376d95eb8637aa1a297bb82584fd66c","properties":{"rationale":"Enforced minimum strength, changed vendor defaults, salted-hash/encrypted storage, and protected transmission directly fix weak-password and clear-text credential exposure.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-08-7c9dc13e.json","sourceId":"uc:UC-ACCESS-08","targetDetailPath":"/data/v1/records/risk-access-weak-authentication-4e35bdb2.json","targetId":"risk:access-weak-authentication","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b72786f1fa13edfa75b3a414d40ae68e2d5ddaed4cbaf1e7d47c4d4180a09758","properties":{"rationale":"Account lockout and throttling after consecutive failed attempts directly defeat brute-force login.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-11-d0c7a1b8.json","sourceId":"uc:UC-ACCESS-11","targetDetailPath":"/data/v1/records/risk-access-weak-authentication-4e35bdb2.json","targetId":"risk:access-weak-authentication","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c3bc6914e6776492f91e9ce90dd29c2a9c9c1f0960583810fb7c725d55c0d967","properties":{"rationale":"Inactivity session lock requiring re-authentication directly fixes the missing lock/logout on unattended workstations.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-12-8ef9e477.json","sourceId":"uc:UC-ACCESS-12","targetDetailPath":"/data/v1/records/risk-access-weak-authentication-4e35bdb2.json","targetId":"risk:access-weak-authentication","type":"mitigates"}],"schemaVersion":1}
