{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Access Control & Identity Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-06","description":"Every user, service, and device is assigned a unique identifier from an authoritative source; shared or group identifiers are prohibited except under documented approval with compensating controls. Identifiers are issued through a controlled process, mapped to accountable owners, deactivated promptly when no longer needed, and not reused for a defined period.","details":{"control_category":"technical","control_type":"preventive","domain":"Access Control & Identity Management","guidance":[{"propositionId":"NIST-AGI-01","propositionTitle":"Distinct agent identities and identity boundaries","source":"nist-ai-agent-identity","sourcePages":"Concept paper pp. 4, 6: Identification; Areas of Interest","sourceTitle":"NIST NCCoE: Software and AI Agent Identity and Authorization"}],"members":[{"control_id":"IA-4","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PR.AA-01","coverage":"partial","delta":"credential issuance and protection satisfied by the authenticator management control","framework":"nist-csf-2","relationship":"intersects_with"},{"control_id":"A.5.16","coverage":"full","framework":"iso-27001","relationship":"superset_of"}],"statement":"Every user, service, and device is assigned a unique identifier from an authoritative source; shared or group identifiers are prohibited except under documented approval with compensating controls. Identifiers are issued through a controlled process, mapped to accountable owners, deactivated promptly when no longer needed, and not reused for a defined period.","title":"Manage unique identities and identifiers end to end","unified_id":"UC-ACCESS-06"},"id":"uc:UC-ACCESS-06","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-06","sourceIds":["iso-27001","nist-800-53","nist-ai-agent-identity","nist-csf-2"],"sourceUrl":null,"title":"UC-ACCESS-06 — Manage unique identities and identifiers end to end","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0b7172bb9b0f1d9883dfb6400e7390650096cd4e38a906bb361c5db9f066ed99","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-access-06-623f356c.json","targetId":"uc:UC-ACCESS-06","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0d4c62ecaae2f7303c04611942d2d3c0be48b1dbbbdc87b1c12837d9d00505c0","properties":{"control_id":"A.5.16","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-access-06-623f356c.json","sourceId":"uc:UC-ACCESS-06","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-16-46fc8420.json","targetId":"ctrl:iso-27001:A.5.16","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0e0a9399b7a034b0bbe7d0c5da375cb84bd85c9c6210b7e91d9f3ac52b1cc207","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-access-06-623f356c.json","targetId":"uc:UC-ACCESS-06","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4ad2f28c314374eb079defc3f2c7250227f34678e6e5e8c469c42bf6283eeb37","properties":{"rationale":"Unique, non-shared identifiers mapped to accountable owners are the attribution foundation that defeats repudiation of actions.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-06-623f356c.json","sourceId":"uc:UC-ACCESS-06","targetDetailPath":"/data/v1/records/risk-access-privilege-abuse-repudiation-343a8917.json","targetId":"risk:access-privilege-abuse-repudiation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6737464183121b9295e5739f7d8915dd0432adfc2d092634c23bcdb79493fdd6","properties":{"rationale":"Prohibiting shared/group IDs and no-reuse rules close shared-account vectors for unauthorized use.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-06-623f356c.json","sourceId":"uc:UC-ACCESS-06","targetDetailPath":"/data/v1/records/risk-access-unauthorized-use-equipment-d2082944.json","targetId":"risk:access-unauthorized-use-equipment","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:736117cc1856c329dca10132d297298dbb515b058ef10731a015e099570b424f","properties":{"control_id":"PR.AA-01","coverage":"partial","delta":"credential issuance and protection satisfied by the authenticator management control","framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-access-06-623f356c.json","sourceId":"uc:UC-ACCESS-06","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-aa-01-0e825314.json","targetId":"ctrl:nist-csf-2:PR.AA-01","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:81b991aadcf5e8b5db0f86328fd49167acf8fcfc53215a460e56279231aa867d","properties":{"rationale":"Prompt deactivation of identifiers no longer needed supports timely de-registration.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-06-623f356c.json","sourceId":"uc:UC-ACCESS-06","targetDetailPath":"/data/v1/records/risk-access-provisioning-review-gap-dc152038.json","targetId":"risk:access-provisioning-review-gap","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:95dc75ae9668ae991c1237fece49d9db6046c85dc1ca15a3856c596c3d5044e4","properties":{"control_id":"IA-4","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-06-623f356c.json","sourceId":"uc:UC-ACCESS-06","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ia-4-a75d534b.json","targetId":"ctrl:nist-800-53:IA-4","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a57e7562a54f7cb668d0ad49c961b002f2bd53c00cdd6dd489e6bd2283f00b01","properties":{},"sourceDetailPath":"/data/v1/records/wf-c30-ece66f45.json","sourceId":"wf:C30","targetDetailPath":"/data/v1/records/uc-uc-access-06-623f356c.json","targetId":"uc:UC-ACCESS-06","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:d6c9c99163b707562e48f2c1130a329de521f088c2cef3eb22df35cf62d0cd96","properties":{"control_id":"NIST-AGI-01","coverage":"guidance","delta":null,"framework":"nist-ai-agent-identity","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Concept paper pp. 4, 6: Identification; Areas of Interest","source_version":"February 2026 draft concept paper"},"sourceDetailPath":"/data/v1/records/uc-uc-access-06-623f356c.json","sourceId":"uc:UC-ACCESS-06","targetDetailPath":"/data/v1/records/ctrl-nist-ai-agent-identity-nist-agi-01-b794d997.json","targetId":"ctrl:nist-ai-agent-identity:NIST-AGI-01","type":"informed_by"}],"schemaVersion":1}
