{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Access Control & Identity Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-08","description":"Authenticators (passwords, tokens, keys, certificates) are issued through a verified process, with vendor defaults changed before use and minimum strength requirements enforced. Authentication information is protected in storage (salted hashing or encryption) and in transmission, masked during entry, and never embedded in code or scripts. Authenticators are revoked on compromise or separation and rotated at defined intervals or events.","details":{"control_category":"technical","control_type":"preventive","domain":"Access Control & Identity Management","guidance":[{"propositionId":"NIST-AGI-02","propositionTitle":"Agent authentication and credential lifecycle","source":"nist-ai-agent-identity","sourcePages":"Concept paper pp. 4, 7: Authentication; Relevant Standards and Guidelines","sourceTitle":"NIST NCCoE: Software and AI Agent Identity and Authorization"}],"members":[{"control_id":"IA-5","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"IA-6","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.5.17","coverage":"partial","delta":"advising personnel on proper handling and protection of authentication information","framework":"iso-27001","relationship":"intersects_with"}],"statement":"Authenticators (passwords, tokens, keys, certificates) are issued through a verified process, with vendor defaults changed before use and minimum strength requirements enforced. Authentication information is protected in storage (salted hashing or encryption) and in transmission, masked during entry, and never embedded in code or scripts. Authenticators are revoked on compromise or separation and rotated at defined intervals or events.","title":"Manage and protect authenticators across their lifecycle","unified_id":"UC-ACCESS-08"},"id":"uc:UC-ACCESS-08","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-08","sourceIds":["iso-27001","nist-800-53","nist-ai-agent-identity"],"sourceUrl":null,"title":"UC-ACCESS-08 — Manage and protect authenticators across their lifecycle","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2432004544ec9f3eacf97724334abeba2f7a1bf4ed79d3938a37a62fee86f6fd","properties":{"rationale":"Changing vendor defaults before use closes the default-credential path to unauthorized system use.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-08-7c9dc13e.json","sourceId":"uc:UC-ACCESS-08","targetDetailPath":"/data/v1/records/risk-access-unauthorized-use-equipment-d2082944.json","targetId":"risk:access-unauthorized-use-equipment","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:391027d92d81eb9b24b986edd7d7fb70bf9e47c0f7caba2a142b5cd209cc1bbd","properties":{"rationale":"Never embedding keys in code and protecting authenticators prevents credential/key forgery used to gain privileges.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-08-7c9dc13e.json","sourceId":"uc:UC-ACCESS-08","targetDetailPath":"/data/v1/records/risk-access-privilege-abuse-repudiation-343a8917.json","targetId":"risk:access-privilege-abuse-repudiation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:511d832af5aef43ee077f8afaab1055f43513e77368c579303e9332e2a7a64ec","properties":{"control_id":"IA-6","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-08-7c9dc13e.json","sourceId":"uc:UC-ACCESS-08","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ia-6-c357f9aa.json","targetId":"ctrl:nist-800-53:IA-6","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7d52bf5b651919bf4b677c80c37922bb13874332c4942fa9689c6222ef3044cd","properties":{},"sourceDetailPath":"/data/v1/records/wf-c5-907af9a4.json","sourceId":"wf:C5","targetDetailPath":"/data/v1/records/uc-uc-access-08-7c9dc13e.json","targetId":"uc:UC-ACCESS-08","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8ad43eeb9707d403a42533306a14908e951226d382dfc555c22e8baefaf7633b","properties":{"control_id":"A.5.17","coverage":"partial","delta":"advising personnel on proper handling and protection of authentication information","framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-access-08-7c9dc13e.json","sourceId":"uc:UC-ACCESS-08","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-5-17-b45de021.json","targetId":"ctrl:iso-27001:A.5.17","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:8da0119df622f2584b835fe7c28594eb7376d95eb8637aa1a297bb82584fd66c","properties":{"rationale":"Enforced minimum strength, changed vendor defaults, salted-hash/encrypted storage, and protected transmission directly fix weak-password and clear-text credential exposure.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-08-7c9dc13e.json","sourceId":"uc:UC-ACCESS-08","targetDetailPath":"/data/v1/records/risk-access-weak-authentication-4e35bdb2.json","targetId":"risk:access-weak-authentication","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9d65cd0f17251d7ebc72a86ac628ea268fbb23b5dea6f5bd202ff6004f657375","properties":{"rationale":"Strong, rotated authenticators revoked on compromise reduce stolen-credential account takeover.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-08-7c9dc13e.json","sourceId":"uc:UC-ACCESS-08","targetDetailPath":"/data/v1/records/risk-fraud-external-c3ce412f.json","targetId":"risk:fraud-external","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a5c7ac0a3f7944c42bd127dbce6aa2a9b8dae14ea06e6d4eca80580592070ba1","properties":{"control_id":"NIST-AGI-02","coverage":"guidance","delta":null,"framework":"nist-ai-agent-identity","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Concept paper pp. 4, 7: Authentication; Relevant Standards and Guidelines","source_version":"February 2026 draft concept paper"},"sourceDetailPath":"/data/v1/records/uc-uc-access-08-7c9dc13e.json","sourceId":"uc:UC-ACCESS-08","targetDetailPath":"/data/v1/records/ctrl-nist-ai-agent-identity-nist-agi-02-8f2c52e7.json","targetId":"ctrl:nist-ai-agent-identity:NIST-AGI-02","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a8f71fefda3f22df5a8f22c68fc1b98a565a38cc92dc18f8eb26f0e03f8ad9b1","properties":{},"sourceDetailPath":"/data/v1/records/wf-d40-de759eff.json","sourceId":"wf:D40","targetDetailPath":"/data/v1/records/uc-uc-access-08-7c9dc13e.json","targetId":"uc:UC-ACCESS-08","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a91cb2e5642c24df64ebdcfecc08e94433967724411d896c03234899546e4bbb","properties":{},"sourceDetailPath":"/data/v1/records/wf-c30-ece66f45.json","sourceId":"wf:C30","targetDetailPath":"/data/v1/records/uc-uc-access-08-7c9dc13e.json","targetId":"uc:UC-ACCESS-08","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b57814bfc51eee3cb1901913de3722edbbd5fe1589adf8cfaba7a6882c7812dc","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-access-08-7c9dc13e.json","targetId":"uc:UC-ACCESS-08","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f5367068bed68ed1d1db18e9e3dcb1e5f220ef51a91b2f2473f126fb2abee44e","properties":{"control_id":"IA-5","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-08-7c9dc13e.json","sourceId":"uc:UC-ACCESS-08","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ia-5-cc50b4d0.json","targetId":"ctrl:nist-800-53:IA-5","type":"maps_to"}],"schemaVersion":1}
