{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Access Control & Identity Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-01","description":"All accounts are created only on a documented, owner-approved request that specifies role-based entitlements and is uniquely attributable to an individual or service. Access is modified on role change and disabled or removed within one business day of termination or loss of authorization, with dormant accounts automatically disabled after a defined period. All provisioning, modification, and deprovisioning events are logged and retained as evidence.","details":{"control_category":"technical","control_type":"preventive","domain":"Access Control & Identity Management","guidance":[],"members":[{"control_id":"AC-2","coverage":"partial","delta":"periodic account review satisfied by the separate access review control","framework":"nist-800-53","relationship":"intersects_with"},{"control_id":"CC6.2","coverage":"full","framework":"soc2","relationship":"superset_of"},{"control_id":"SOC1-1","coverage":"partial","delta":"authentication, periodic review, and privileged access satisfied by companion unified controls","framework":"soc1","relationship":"intersects_with"},{"control_id":"ITGC-AC","coverage":"partial","delta":"authentication, recertification, privileged access, segregation of duties, and physical access security satisfied by companion controls","framework":"sox","relationship":"intersects_with"}],"statement":"All accounts are created only on a documented, owner-approved request that specifies role-based entitlements and is uniquely attributable to an individual or service. Access is modified on role change and disabled or removed within one business day of termination or loss of authorization, with dormant accounts automatically disabled after a defined period. All provisioning, modification, and deprovisioning events are logged and retained as evidence.","title":"Provision and deprovision accounts through a managed lifecycle","unified_id":"UC-ACCESS-01"},"id":"uc:UC-ACCESS-01","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-01","sourceIds":["nist-800-53","soc1","soc2","sox"],"sourceUrl":null,"title":"UC-ACCESS-01 — Provision and deprovision accounts through a managed lifecycle","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:082ce7de28fdc456c8e68f7bf2b6f2f2af4a25425c80e8e87c82e9d347e259f9","properties":{"rationale":"Auto-disabling dormant accounts and prompt termination removal close the orphaned-account vector for unauthorized access.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/risk-access-unauthorized-use-equipment-d2082944.json","targetId":"risk:access-unauthorized-use-equipment","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1448b5981f0f84eae0edf17bdeddb04df6bb1bab4d08fb48d84c2c8e23575315","properties":{"rationale":"Owner-approved provisioning with role-based entitlements and 1-business-day deprovisioning on termination directly eliminates orphaned accounts and un-revoked access.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/risk-access-provisioning-review-gap-dc152038.json","targetId":"risk:access-provisioning-review-gap","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:30d160b6febe5fe4c87f741657300759414cd0ee4d903d5cdbc207e56c0389a3","properties":{"control_id":"ITGC-AC","coverage":"partial","delta":"authentication, recertification, privileged access, segregation of duties, and physical access security satisfied by companion controls","framework":"sox","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"SOX §302/§404 (2002), PCAOB AS 2201"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/ctrl-sox-itgc-ac-2b64f901.json","targetId":"ctrl:sox:ITGC-AC","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:43998ab4fc7638a98adcfd08a4c9378fcfa8a4bcf3cd920046fd6f4ced6c77a7","properties":{},"sourceDetailPath":"/data/v1/records/wf-s5-a655abf2.json","sourceId":"wf:S5","targetDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","targetId":"uc:UC-ACCESS-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4f21581b03062e5cb1d7e8dded4b1c2769304bd50a2b5316de64fd87c8d81019","properties":{},"sourceDetailPath":"/data/v1/records/wf-c68-08a38288.json","sourceId":"wf:C68","targetDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","targetId":"uc:UC-ACCESS-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6117926bb515257ea47cd345ef189a9f142cbfa7449115ed1f3f4253ea3ec625","properties":{"control_id":"CC6.2","coverage":"full","delta":null,"framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-2-639c148c.json","targetId":"ctrl:soc2:CC6.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:64fd9f3b4abe64cc3c0d53557267217a3e9c797de6ff55a8cde929a810e64252","properties":{},"sourceDetailPath":"/data/v1/records/wf-d24-a9f3daf6.json","sourceId":"wf:D24","targetDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","targetId":"uc:UC-ACCESS-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6cffab58f8a38840af96be5280c88aae9aa597e7cf1905e81fbe5790813fd668","properties":{"control_id":"AC-2","coverage":"partial","delta":"periodic account review satisfied by the separate access review control","framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-2-1f234b8c.json","targetId":"ctrl:nist-800-53:AC-2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:86db0c9873322d1205c689f0601c544cb2490815b2f5777d952cdc027a7dcd5c","properties":{},"sourceDetailPath":"/data/v1/records/wf-a18-be3cee23.json","sourceId":"wf:A18","targetDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","targetId":"uc:UC-ACCESS-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:892d5cbce4bcb4454a355c1563211aedb4e8753d82970789185897abba4d74ab","properties":{},"sourceDetailPath":"/data/v1/records/wf-d31-af2d985a.json","sourceId":"wf:D31","targetDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","targetId":"uc:UC-ACCESS-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8bbc4b45e7e90f25a667f406ef22de362a5baf4ec8e94462bcead37d09435d1a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c70-28fe2122.json","sourceId":"wf:C70","targetDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","targetId":"uc:UC-ACCESS-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:93fc2d2ec04d4d424cfb5c69e98d0452b354479b9ac273c856a1011bbff681d6","properties":{},"sourceDetailPath":"/data/v1/records/wf-d30-c61ffe25.json","sourceId":"wf:D30","targetDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","targetId":"uc:UC-ACCESS-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a8e947d41b9ce280ec46a8aa353bc1de04d27649e8737ad3a268cd54ef74a093","properties":{"control_id":"SOC1-1","coverage":"partial","delta":"authentication, periodic review, and privileged access satisfied by companion unified controls","framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-1-bfab4a41.json","targetId":"ctrl:soc1:SOC1-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c0922b9cdc5da62c6d8ceec5f75bb20d23b23fbc6ab99bc956fa1f54559ca756","properties":{},"sourceDetailPath":"/data/v1/records/wf-d40-de759eff.json","sourceId":"wf:D40","targetDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","targetId":"uc:UC-ACCESS-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c4a26ad04cf0da3510d908142d89659d636b24ebbaeb192cd3312b0e4e55e69e","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","targetId":"uc:UC-ACCESS-01","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d670b07381c84bc486b830e5722013cd12a46ceb37447e469f826e7e83f55410","properties":{},"sourceDetailPath":"/data/v1/records/wf-c69-7c87609e.json","sourceId":"wf:C69","targetDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","targetId":"uc:UC-ACCESS-01","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dfc315612c713723a50c9d8914f9a7dbc9a9d82d7da7ce0cca39ac67d98d100a","properties":{"rationale":"Role-based, owner-approved provisioning and modify-on-role-change help limit wrong assignment and accumulation, but the operative least-privilege defense is role design (UC-03) and periodic access review (UC-02).","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/risk-access-excess-privilege-cd8adadc.json","targetId":"risk:access-excess-privilege","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f67ff06fb773d0f1089d4819b048691037c347f94ad9b19a46047afa3f3ca5fb","properties":{"rationale":"Accounts uniquely attributable to individuals plus logged provisioning/modification events underpin the accountability that counters repudiation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","sourceId":"uc:UC-ACCESS-01","targetDetailPath":"/data/v1/records/risk-access-privilege-abuse-repudiation-343a8917.json","targetId":"risk:access-privilege-abuse-repudiation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fd4c9b938510f25e549bed52a8a7af3b21b9ec31b50694e37bc24c2a025e168c","properties":{},"sourceDetailPath":"/data/v1/records/wf-c19-ef930979.json","sourceId":"wf:C19","targetDetailPath":"/data/v1/records/uc-uc-access-01-1e70b922.json","targetId":"uc:UC-ACCESS-01","type":"operates"}],"schemaVersion":1}
