{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Access Control & Identity Management","type":"detective"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-02","description":"All user and privileged access rights are reviewed at least annually, and more frequently for high-risk systems, by system or data owners who confirm each entitlement remains limited to business need. Unnecessary accounts and excess privileges identified in reviews are disabled or removed within a defined SLA. Completed reviews and remediation evidence are retained.","details":{"control_category":"administrative","control_type":"detective","domain":"Access Control & Identity Management","guidance":[],"members":[{"control_id":"A.5.18","coverage":"partial","delta":"provisioning, adjustment, and revocation satisfied by the account lifecycle control","framework":"iso-27001","relationship":"intersects_with"},{"control_id":"500.7","coverage":"partial","delta":"least-privilege limits and termination revocation satisfied by companion access controls","framework":"nydfs-500","relationship":"intersects_with"}],"statement":"All user and privileged access rights are reviewed at least annually, and more frequently for high-risk systems, by system or data owners who confirm each entitlement remains limited to business need. Unnecessary accounts and excess privileges identified in reviews are disabled or removed within a defined SLA. Completed reviews and remediation evidence are retained.","title":"Review user access rights periodically","unified_id":"UC-ACCESS-02"},"id":"uc:UC-ACCESS-02","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-02","sourceIds":["iso-27001","nydfs-500"],"sourceUrl":null,"title":"UC-ACCESS-02 — Review user access rights periodically","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:00e8902e59b5f8cb4df7dfcf69939fd935ed07ec4588889ac05c71fbdbad5b61","properties":{"rationale":"Reviews confirm each entitlement stays business-limited and remove excess privilege, directly catching privilege creep and wrong assignment.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-02-0132e278.json","sourceId":"uc:UC-ACCESS-02","targetDetailPath":"/data/v1/records/risk-access-excess-privilege-cd8adadc.json","targetId":"risk:access-excess-privilege","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:01c5020a39a371f094eae5bd6b1007f582289c315c3f2edc31a5ef801c1763eb","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-access-02-0132e278.json","targetId":"uc:UC-ACCESS-02","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:34c64101a4c7fdffcef78476a8acc08f622b50a62f0956e5b1878e7fe7cd7fd6","properties":{},"sourceDetailPath":"/data/v1/records/wf-c12-d75a948f.json","sourceId":"wf:C12","targetDetailPath":"/data/v1/records/uc-uc-access-02-0132e278.json","targetId":"uc:UC-ACCESS-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4fb5e41286bbe840dd3f79f2afafe11a0543fb3b35932b30027c60dc0990141a","properties":{},"sourceDetailPath":"/data/v1/records/wf-d40-de759eff.json","sourceId":"wf:D40","targetDetailPath":"/data/v1/records/uc-uc-access-02-0132e278.json","targetId":"uc:UC-ACCESS-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:93e30651361d339234a6b3e49058d72957b2bb1f25a408ea93ec4f6fb3a073d3","properties":{},"sourceDetailPath":"/data/v1/records/wf-c72-51c36efe.json","sourceId":"wf:C72","targetDetailPath":"/data/v1/records/uc-uc-access-02-0132e278.json","targetId":"uc:UC-ACCESS-02","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9df3b2affe778942ae24edb5bf7b1f16a2743ec488ec7847a837f3bd1140f7fe","properties":{"rationale":"Periodic owner recertification of user and privileged access is the direct detective control for the missing access-review element of this risk.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-02-0132e278.json","sourceId":"uc:UC-ACCESS-02","targetDetailPath":"/data/v1/records/risk-access-provisioning-review-gap-dc152038.json","targetId":"risk:access-provisioning-review-gap","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a06d3dc3bfa286704837290a134192ad03ff22cd881b73e6ebfafaaa5df608d2","properties":{"control_id":"500.7","coverage":"partial","delta":"least-privilege limits and termination revocation satisfied by companion access controls","framework":"nydfs-500","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"23 NYCRR 500, Second Amendment"},"sourceDetailPath":"/data/v1/records/uc-uc-access-02-0132e278.json","sourceId":"uc:UC-ACCESS-02","targetDetailPath":"/data/v1/records/ctrl-nydfs-500-500-7-09439ea1.json","targetId":"ctrl:nydfs-500:500.7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cef3659c19b299952916eb1c72046246e40f0deee302865659cc3f0729e3018d","properties":{"control_id":"A.5.18","coverage":"partial","delta":"provisioning, adjustment, and revocation satisfied by the account lifecycle control","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-access-02-0132e278.json","sourceId":"uc:UC-ACCESS-02","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-18-472ef6f1.json","targetId":"ctrl:iso-27001:A.5.18","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d4b9c1bc5d5b46c50e5265631570fcfbbffcb4f968267b494fe4ef079c0a023f","properties":{"rationale":"Removing standing/excess privilege found in reviews shrinks the rights available to be abused.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-02-0132e278.json","sourceId":"uc:UC-ACCESS-02","targetDetailPath":"/data/v1/records/risk-access-privilege-abuse-repudiation-343a8917.json","targetId":"risk:access-privilege-abuse-repudiation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d630fed7655b5c34149589e7162c5a187e7a68afd7000dae2a2dbb13cbc59b8e","properties":{},"sourceDetailPath":"/data/v1/records/wf-s5-a655abf2.json","sourceId":"wf:S5","targetDetailPath":"/data/v1/records/uc-uc-access-02-0132e278.json","targetId":"uc:UC-ACCESS-02","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d6c7ef7647d952cfb87222393bda3847697f4ff81b0458106d3c725dc431fa0a","properties":{},"sourceDetailPath":"/data/v1/records/wf-d24-a9f3daf6.json","sourceId":"wf:D24","targetDetailPath":"/data/v1/records/uc-uc-access-02-0132e278.json","targetId":"uc:UC-ACCESS-02","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e5aa29f786a1e12838e44d690a11a41c8ee5b16bb00492e03bbb42e63d90968d","properties":{"rationale":"Owner recertification of accumulated entitlements detects toxic combinations that breach segregation of duties.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-02-0132e278.json","sourceId":"uc:UC-ACCESS-02","targetDetailPath":"/data/v1/records/risk-fin-segregation-of-duties-eb7ee015.json","targetId":"risk:fin-segregation-of-duties","type":"mitigates"}],"schemaVersion":1}
