{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Access Control & Identity Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-07","description":"The identity of users is verified through documented evidence checks proportional to the assurance level of the access requested before initial credentials are issued. The proofed identity is bound to its credentials and recorded, and re-proofing occurs on credential recovery or other high-risk changes.","details":{"control_category":"administrative","control_type":"preventive","domain":"Access Control & Identity Management","guidance":[],"members":[{"control_id":"IA-12","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PR.AA-02","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"}],"statement":"The identity of users is verified through documented evidence checks proportional to the assurance level of the access requested before initial credentials are issued. The proofed identity is bound to its credentials and recorded, and re-proofing occurs on credential recovery or other high-risk changes.","title":"Proof identities before binding credentials","unified_id":"UC-ACCESS-07"},"id":"uc:UC-ACCESS-07","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-07","sourceIds":["nist-800-53","nist-csf-2"],"sourceUrl":null,"title":"UC-ACCESS-07 — Proof identities before binding credentials","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3c6dc8c856463292032e32bf0a63fe9ef585c7f0adc0383287070634517e5ca7","properties":{"rationale":"Re-proofing on credential recovery defends against social-engineering of help-desk account-recovery takeover.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-07-ed06e251.json","sourceId":"uc:UC-ACCESS-07","targetDetailPath":"/data/v1/records/risk-aware-phishing-social-engineering-bb9b7bd6.json","targetId":"risk:aware-phishing-social-engineering","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:56f9d14708b16b7dd3f788243943eb3d199de5cc6689cc7f3941e5cb1ac35b94","properties":{"control_id":"PR.AA-02","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-access-07-ed06e251.json","sourceId":"uc:UC-ACCESS-07","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-aa-02-6d412a10.json","targetId":"ctrl:nist-csf-2:PR.AA-02","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:65d30c22f953527bb1c0ffd6dd41e01c128ea2daa63827fa46aee4d228036e73","properties":{"control_id":"IA-12","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-07-ed06e251.json","sourceId":"uc:UC-ACCESS-07","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ia-12-87eb72e6.json","targetId":"ctrl:nist-800-53:IA-12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:87220acd20692ae410fc685a8b661e2719c00970f977855c5961fcfc730fc066","properties":{},"sourceDetailPath":"/data/v1/records/wf-c5-907af9a4.json","sourceId":"wf:C5","targetDetailPath":"/data/v1/records/uc-uc-access-07-ed06e251.json","targetId":"uc:UC-ACCESS-07","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9b1a90014f49080a84bccb8180632aa806ac659fe4d0c3c860adb77e981fa4f2","properties":{"rationale":"Proofing and binding identity to credentials prevents fraudulent enrollment and forged-identity credential issuance.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-07-ed06e251.json","sourceId":"uc:UC-ACCESS-07","targetDetailPath":"/data/v1/records/risk-access-privilege-abuse-repudiation-343a8917.json","targetId":"risk:access-privilege-abuse-repudiation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9b99bdec75ee38f020c8bccb9840c3323a9df3ec783294ee04a98fef22149a07","properties":{},"sourceDetailPath":"/data/v1/records/wf-c30-ece66f45.json","sourceId":"wf:C30","targetDetailPath":"/data/v1/records/uc-uc-access-07-ed06e251.json","targetId":"uc:UC-ACCESS-07","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ff1debb0055a7dda0745759d2de2328211ae0f94177e7f7e021345b436afb472","properties":{"rationale":"Evidence-based identity proofing before credential issuance, with re-proofing on recovery, directly defeats identity theft, impersonation, and fraudulent-application account fraud.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-07-ed06e251.json","sourceId":"uc:UC-ACCESS-07","targetDetailPath":"/data/v1/records/risk-fraud-external-c3ce412f.json","targetId":"risk:fraud-external","type":"mitigates"}],"schemaVersion":1}
