{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Access Control & Identity Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-04","description":"Privileged access rights are individually authorized against a business justification, time-bound or periodically recertified, and issued on separate accounts distinct from daily-use identities. Use of utility programs capable of overriding system or application controls is restricted to authorized administrators and logged. Application allowlisting or equivalent controls prevent installation and execution of unauthorized software on managed systems.","details":{"control_category":"technical","control_type":"preventive","domain":"Access Control & Identity Management","guidance":[],"members":[{"control_id":"PR.PS-05","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"A.8.2","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"A.8.18","coverage":"full","framework":"iso-27001","relationship":"superset_of"}],"statement":"Privileged access rights are individually authorized against a business justification, time-bound or periodically recertified, and issued on separate accounts distinct from daily-use identities. Use of utility programs capable of overriding system or application controls is restricted to authorized administrators and logged. Application allowlisting or equivalent controls prevent installation and execution of unauthorized software on managed systems.","title":"Restrict privileged rights, utilities, and unauthorized software","unified_id":"UC-ACCESS-04"},"id":"uc:UC-ACCESS-04","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-04","sourceIds":["iso-27001","nist-csf-2"],"sourceUrl":null,"title":"UC-ACCESS-04 — Restrict privileged rights, utilities, and unauthorized software","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:324602df3eb0e8582973e4a17a802a9cf0d749756d1b0a67e094a043e295533f","properties":{"control_id":"A.8.2","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-access-04-75180489.json","sourceId":"uc:UC-ACCESS-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-2-3051f58f.json","targetId":"ctrl:iso-27001:A.8.2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3f0d165ed2e47cd95165c2fc5b38624ac33851e2d4ceb2a8dc8bd275bacf6e39","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-access-04-75180489.json","targetId":"uc:UC-ACCESS-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:438f150893299f8a2362aaaeed3d6ff2d4624e386e4a9f002f22d625eedad1f1","properties":{},"sourceDetailPath":"/data/v1/records/wf-c81-7e13787b.json","sourceId":"wf:C81","targetDetailPath":"/data/v1/records/uc-uc-access-04-75180489.json","targetId":"uc:UC-ACCESS-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4e4d57b1846357a09c08d81f2308447848f9c560522830014546c1e71efa5816","properties":{},"sourceDetailPath":"/data/v1/records/wf-c29-73942cbd.json","sourceId":"wf:C29","targetDetailPath":"/data/v1/records/uc-uc-access-04-75180489.json","targetId":"uc:UC-ACCESS-04","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:512254cb929c8db7c6741181a97c68d70fb9dc0d5e1449bf1d1f88ee07948fc1","properties":{"rationale":"Individually justified, time-bound privileged rights on separate admin accounts directly curb excessive privilege.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-04-75180489.json","sourceId":"uc:UC-ACCESS-04","targetDetailPath":"/data/v1/records/risk-access-excess-privilege-cd8adadc.json","targetId":"risk:access-excess-privilege","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7f8672194ad41d5d5ad2f928b4aefa5e8a161c28526d9b48e34c8eabebd7e26b","properties":{"control_id":"PR.PS-05","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-access-04-75180489.json","sourceId":"uc:UC-ACCESS-04","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-ps-05-4f56b399.json","targetId":"ctrl:nist-csf-2:PR.PS-05","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:821b41d6b14ca940fab8d95c5cb05714edf121108f046889c35c2cea8d8cfeff","properties":{"rationale":"Restricting privileged access to the GL/ERP directly limits unauthorized journal entries and top-side management override.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-04-75180489.json","sourceId":"uc:UC-ACCESS-04","targetDetailPath":"/data/v1/records/risk-fin-journal-entry-management-override-b0c0ed68.json","targetId":"risk:fin-journal-entry-management-override","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:92da6bc2ada2e72142b710a669718af8806e576052276657b64a15aa08622e76","properties":{"control_id":"A.8.18","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-access-04-75180489.json","sourceId":"uc:UC-ACCESS-04","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-18-b4f40ff4.json","targetId":"ctrl:iso-27001:A.8.18","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b5f71a9592c0d31fa8eacd28d7c6e51eb188959b973fded83b42fe830fdf30b7","properties":{"rationale":"Application allowlisting blocks unauthorized software and utility restriction prevents control-override escalation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-04-75180489.json","sourceId":"uc:UC-ACCESS-04","targetDetailPath":"/data/v1/records/risk-access-unauthorized-use-equipment-d2082944.json","targetId":"risk:access-unauthorized-use-equipment","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d4492bcc76bea14bccca8d8f3666df953feaf22fdf03b93bfd2bb3a0f35ad4b7","properties":{},"sourceDetailPath":"/data/v1/records/wf-s5-a655abf2.json","sourceId":"wf:S5","targetDetailPath":"/data/v1/records/uc-uc-access-04-75180489.json","targetId":"uc:UC-ACCESS-04","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f0b87acd2727b1785a6fd0cee779d658b3ca2f07308724f66735b80b427367b5","properties":{"rationale":"Separate admin accounts distinct from daily-use identities enforce develop-vs-deploy duty separation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-04-75180489.json","sourceId":"uc:UC-ACCESS-04","targetDetailPath":"/data/v1/records/risk-fin-segregation-of-duties-eb7ee015.json","targetId":"risk:fin-segregation-of-duties","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fc11aeba26b6a7e843d2d18e0efe5739fa5fba14ac8d5bcdb4eac5822d71dac0","properties":{"rationale":"Restricting and logging privileged and utility-program use on separate admin identities directly limits and attributes abuse of rights.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-04-75180489.json","sourceId":"uc:UC-ACCESS-04","targetDetailPath":"/data/v1/records/risk-access-privilege-abuse-repudiation-343a8917.json","targetId":"risk:access-privilege-abuse-repudiation","type":"mitigates"}],"schemaVersion":1}
