{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Access Control & Identity Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-03","description":"A documented access control policy grants access strictly on business need-to-know, with entitlements defined through roles that default to least privilege. Segregation-of-duties conflicts (e.g., request versus approve, develop versus deploy) are defined in a conflict matrix, enforced in systems, and mitigated with compensating controls where unavoidable. Role and entitlement definitions are approved by data or system owners and re-approved whenever they change.","details":{"control_category":"technical","control_type":"preventive","domain":"Access Control & Identity Management","guidance":[{"propositionId":"NIST-AGI-03","propositionTitle":"Context-sensitive authorization and least privilege","source":"nist-ai-agent-identity","sourcePages":"Concept paper pp. 4, 6: Authorization; Areas of Interest","sourceTitle":"NIST NCCoE: Software and AI Agent Identity and Authorization"}],"members":[{"control_id":"AC-5","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"AC-6","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PR.AA-05","coverage":"partial","delta":"periodic review of granted access rights, addressed by the access-review control","framework":"nist-csf-2","relationship":"intersects_with"},{"control_id":"A.5.15","coverage":"partial","delta":"also requires rules controlling physical access to information and assets","framework":"iso-27001","relationship":"intersects_with"},{"control_id":"CC6.3","coverage":"partial","delta":"modifying/removing access on change and periodic role review handled by companion controls","framework":"soc2","relationship":"intersects_with"},{"control_id":"PCI-Req7","coverage":"partial","delta":"semiannual review of all user accounts and privileges (7.2.4) not covered","framework":"pci-dss","relationship":"intersects_with"},{"control_id":"A003","coverage":"partial","delta":"agent-specific enforcement: data access scoped per task, user role, agent role, and context at inference time","framework":"aiuc-1","relationship":"intersects_with"}],"statement":"A documented access control policy grants access strictly on business need-to-know, with entitlements defined through roles that default to least privilege. Segregation-of-duties conflicts (e.g., request versus approve, develop versus deploy) are defined in a conflict matrix, enforced in systems, and mitigated with compensating controls where unavoidable. Role and entitlement definitions are approved by data or system owners and re-approved whenever they change.","title":"Enforce least privilege, need-to-know, and segregation of duties","unified_id":"UC-ACCESS-03"},"id":"uc:UC-ACCESS-03","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-03","sourceIds":["aiuc-1","iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2","pci-dss","soc2"],"sourceUrl":null,"title":"UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of duties","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:04e26852f85ae560cc2faefa344b240a5afd02d2203f703d89c20ee38b4211de","properties":{"rationale":"Segregation of duties across the revenue cycle directly prevents one party initiating and recording fictitious or mis-timed revenue.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/risk-fin-revenue-recognition-misstatement-5e181e17.json","targetId":"risk:fin-revenue-recognition-misstatement","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1ffa1b9a4f7392dad928a080fcb54d34c08c9839b31b6508e8e63587e7163858","properties":{"control_id":"CC6.3","coverage":"partial","delta":"modifying/removing access on change and periodic role review handled by companion controls","framework":"soc2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2017 TSC"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/ctrl-soc2-cc6-3-4ade392f.json","targetId":"ctrl:soc2:CC6.3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3193637bf6194ede1ea13db4689df5983493f0e3e76c62a802a7d35d77739e85","properties":{"control_id":"PR.AA-05","coverage":"partial","delta":"periodic review of granted access rights, addressed by the access-review control","framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-aa-05-63dd9f97.json","targetId":"ctrl:nist-csf-2:PR.AA-05","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4a213726cca3a4e6677d9d25c6e53b232e846c4d877f2aa9b4760bce6289e947","properties":{},"sourceDetailPath":"/data/v1/records/wf-a18-be3cee23.json","sourceId":"wf:A18","targetDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","targetId":"uc:UC-ACCESS-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5cb0a2f1e9b62aa907b0447d1955357fa4ab1d0b0b7b96839bcd1346faacb4e8","properties":{"control_id":"NIST-AGI-03","coverage":"guidance","delta":null,"framework":"nist-ai-agent-identity","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Concept paper pp. 4, 6: Authorization; Areas of Interest","source_version":"February 2026 draft concept paper"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/ctrl-nist-ai-agent-identity-nist-agi-03-0c271eec.json","targetId":"ctrl:nist-ai-agent-identity:NIST-AGI-03","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:60c4dfb06f347a6a3d5f7151b6f1835a16a2044bd1e3fd31b5accd0c281041bd","properties":{},"sourceDetailPath":"/data/v1/records/wf-d24-a9f3daf6.json","sourceId":"wf:D24","targetDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","targetId":"uc:UC-ACCESS-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:65e6929039ddbdd54312e30a9546e37a0f12f7fade9a92bbacc48432d82ab8d4","properties":{},"sourceDetailPath":"/data/v1/records/wf-c12-d75a948f.json","sourceId":"wf:C12","targetDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","targetId":"uc:UC-ACCESS-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7b637a77c95000088af42201ef97e2c4fe6da67e45bbee83d5897628dcb29bc4","properties":{"rationale":"Least privilege constrains authorized users from reaching resources beyond their authorization.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/risk-access-unauthorized-use-equipment-d2082944.json","targetId":"risk:access-unauthorized-use-equipment","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:84a5730418b891087278a23a2060cb09a770eaea3a3907844ba07b7eca0f89db","properties":{"control_id":"AC-5","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-5-da7bf8b8.json","targetId":"ctrl:nist-800-53:AC-5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:87052d2118d78233ec9621b92e656a4d259e6795a01907a3d9f9b0fb75315545","properties":{},"sourceDetailPath":"/data/v1/records/wf-c69-7c87609e.json","sourceId":"wf:C69","targetDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","targetId":"uc:UC-ACCESS-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8cf6a557412855d991f5fbe276861808067d53cad6d0a3017419b255fa47e568","properties":{"control_id":"A.5.15","coverage":"partial","delta":"also requires rules controlling physical access to information and assets","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-15-b8587804.json","targetId":"ctrl:iso-27001:A.5.15","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:916199d011646f8082ba3af42d5417a6a764bb27e8b965336bc420149a59b858","properties":{"rationale":"A defined, system-enforced SoD conflict matrix directly prevents concentration of incompatible duties.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/risk-fin-segregation-of-duties-eb7ee015.json","targetId":"risk:fin-segregation-of-duties","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:99699e35d210c6c0fb493fd0513636de333f9d74a9b4d7a236c4546b25b9a0dd","properties":{"control_id":"AC-6","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-6-5f45f08f.json","targetId":"ctrl:nist-800-53:AC-6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9c1a68b96184d8f2ca41832c3ebf18839bd8eddd027816792077c295fb60bbd8","properties":{},"sourceDetailPath":"/data/v1/records/wf-a15-e859f6b8.json","sourceId":"wf:A15","targetDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","targetId":"uc:UC-ACCESS-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:adfde43e64882cc1bf16980de560249c8a2f07b5634fc2c67bab4e9e4027ef3a","properties":{},"sourceDetailPath":"/data/v1/records/wf-c70-28fe2122.json","sourceId":"wf:C70","targetDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","targetId":"uc:UC-ACCESS-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:aebdccc9f405dd52e0939ff45911ee81ee0c822ba4c9b24413cee228d2f87b03","properties":{"rationale":"Least privilege bounds the blast radius of an inadequately vetted insider, reducing impact if a poorly screened individual turns malicious.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/risk-hr-insufficient-screening-bdce1f80.json","targetId":"risk:hr-insufficient-screening","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:be15ab2fd808e4d21d1bd3c2d1976b8552a3a82739d18bf827bb2acb60a4c6df","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","targetId":"uc:UC-ACCESS-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cd2cecf6fd40aa5ecd4bd0d4f288a3f5036c7caf45a3b46720179be93733e7b9","properties":{"rationale":"Roles defaulting to least privilege on need-to-know are the direct defense against overly broad or wrongly assigned access rights.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/risk-access-excess-privilege-cd8adadc.json","targetId":"risk:access-excess-privilege","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d19474d3402dfb5476a670d3319f08ffa741445f35f34dc56aa1e45ffac22ae5","properties":{"rationale":"Need-to-know least privilege directly limits the scope available for abuse of rights and privilege escalation.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/risk-access-privilege-abuse-repudiation-343a8917.json","targetId":"risk:access-privilege-abuse-repudiation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:da4a8461f4f084180b5ecbd3cb3d3ddda5a44a288eb2010d2de3b81ddbaea663","properties":{"rationale":"SoD separating request from approve limits any one person posting and approving unauthorized journal entries.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/risk-fin-journal-entry-management-override-b0c0ed68.json","targetId":"risk:fin-journal-entry-management-override","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:df17c535a62a12ae5d9dfd3d71c4c53be0837fa1ecd2f9cc654a2d6f2a33c9b1","properties":{},"sourceDetailPath":"/data/v1/records/wf-c19-ef930979.json","sourceId":"wf:C19","targetDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","targetId":"uc:UC-ACCESS-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ed3d957ba80b91b31fcbf1893ac766437567bfb612d054b4a1771afe8da54715","properties":{"control_id":"PCI-Req7","coverage":"partial","delta":"semiannual review of all user accounts and privileges (7.2.4) not covered","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req7-e7336c72.json","targetId":"ctrl:pci-dss:PCI-Req7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fa025a0315b5823b158620adb1e426d69f3be952af40edb9d2b815f9a31e2bc6","properties":{"control_id":"A003","coverage":"partial","delta":"agent-specific enforcement: data access scoped per task, user role, agent role, and context at inference time","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-03-43eeb212.json","sourceId":"uc:UC-ACCESS-03","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-a003-bea61fd9.json","targetId":"ctrl:aiuc-1:A003","type":"maps_to"}],"schemaVersion":1}
