{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Access Control & Identity Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-09","description":"Every user is uniquely identified and authenticated before access, with multi-factor authentication enforced for remote access, privileged access, and access to sensitive data environments. Authentication follows secure log-on practices: credentials are validated only over protected channels, and federated identity assertions (e.g., SAML/OIDC tokens) are signed, protected, and verified. External and non-organizational users are held to the same authentication rigor, with authentication strength documented against the risk of the interaction.","details":{"control_category":"technical","control_type":"preventive","domain":"Access Control & Identity Management","guidance":[],"members":[{"control_id":"IA-2","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"IA-8","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PR.AA-03","coverage":"partial","delta":"service and hardware authentication satisfied by the device/service authentication control","framework":"nist-csf-2","relationship":"intersects_with"},{"control_id":"PR.AA-04","coverage":"full","framework":"nist-csf-2","relationship":"superset_of"},{"control_id":"A.8.5","coverage":"full","framework":"iso-27001","relationship":"superset_of"},{"control_id":"500.12","coverage":"partial","delta":"amended 500.12 requires MFA for any access to any information system","framework":"nydfs-500","relationship":"intersects_with"},{"control_id":"PCI-Req8","coverage":"partial","delta":"account lockout and idle timeout satisfied by session/logon controls; credential lifecycle parameters (8.3.5-8.3.9), MFA implementation integrity (8.5), and shared/system/application account controls (8.2.2, 8.6) satisfied by companion credential- and account-management controls","framework":"pci-dss","relationship":"intersects_with"},{"control_id":"HIPAA-164.312(d)","coverage":"full","framework":"hipaa","relationship":"superset_of"}],"statement":"Every user is uniquely identified and authenticated before access, with multi-factor authentication enforced for remote access, privileged access, and access to sensitive data environments. Authentication follows secure log-on practices: credentials are validated only over protected channels, and federated identity assertions (e.g., SAML/OIDC tokens) are signed, protected, and verified. External and non-organizational users are held to the same authentication rigor, with authentication strength documented against the risk of the interaction.","title":"Authenticate all users with multi-factor authentication","unified_id":"UC-ACCESS-09"},"id":"uc:UC-ACCESS-09","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-09","sourceIds":["hipaa","iso-27001","nist-800-53","nist-csf-2","nydfs-500","pci-dss"],"sourceUrl":null,"title":"UC-ACCESS-09 — Authenticate all users with multi-factor authentication","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1762fb4e9f6fb2e2909edca7aaab776e9728dc30afb8bbba9ee6a1ba84db4965","properties":{"control_id":"PR.AA-03","coverage":"partial","delta":"service and hardware authentication satisfied by the device/service authentication control","framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-aa-03-0adc43de.json","targetId":"ctrl:nist-csf-2:PR.AA-03","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1a97a1066d9376b5ada29364face1a78c0aa532efb31a115c0c36cb332023ca2","properties":{},"sourceDetailPath":"/data/v1/records/wf-d31-af2d985a.json","sourceId":"wf:D31","targetDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","targetId":"uc:UC-ACCESS-09","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1f964b879786f00be6cd7709a8e0782c994b9ce18bfec5e706b01a5d7a06e38b","properties":{},"sourceDetailPath":"/data/v1/records/wf-c31-c58b2f38.json","sourceId":"wf:C31","targetDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","targetId":"uc:UC-ACCESS-09","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:29778728a957a7df14ccd155500df958be12445dcbd26bbbedf821682c336448","properties":{"control_id":"A.8.5","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-8-5-4c63b8ae.json","targetId":"ctrl:iso-27001:A.8.5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3f0f1be652201aa2bf52fafbaf9cbe6710fba7ceedc4cd8ad77d0983fc054e60","properties":{},"sourceDetailPath":"/data/v1/records/wf-d24-a9f3daf6.json","sourceId":"wf:D24","targetDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","targetId":"uc:UC-ACCESS-09","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:48619bb857eda4400475e1c83a40aee34ee34eb4411f46f912af642fe324dec2","properties":{},"sourceDetailPath":"/data/v1/records/wf-c5-907af9a4.json","sourceId":"wf:C5","targetDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","targetId":"uc:UC-ACCESS-09","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4aa9422606d9d7c9b4dd311d484e6623d18475b48439149993fc9f3b1012f244","properties":{"rationale":"Enforced MFA for remote access reduces credential compromise from insecure off-premises environments.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/risk-net-remote-work-mobile-exposure-d7aab6d9.json","targetId":"risk:net-remote-work-mobile-exposure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5ad2c6406f9f0fa7498762738fb631294c5b18cc81d5f508ed69dc896e35b3cc","properties":{"control_id":"PCI-Req8","coverage":"partial","delta":"account lockout and idle timeout satisfied by session/logon controls; credential lifecycle parameters (8.3.5-8.3.9), MFA implementation integrity (8.5), and shared/system/application account controls (8.2.2, 8.6) satisfied by companion credential- and account-management controls","framework":"pci-dss","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"v4.0.1"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/ctrl-pci-dss-pci-req8-fe6b4517.json","targetId":"ctrl:pci-dss:PCI-Req8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5d617594d25b8a41b14088d5998a1bdf055119fb9f57b2e22f2d2fb80e0dae91","properties":{"rationale":"MFA with credential validation only over protected channels directly remediates absent MFA and clear-text authentication.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/risk-access-weak-authentication-4e35bdb2.json","targetId":"risk:access-weak-authentication","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5f9c9f2ee7a7058784c62630d6e9a3e22633f6949103ed9b8518bb0d429377e6","properties":{"control_id":"HIPAA-164.312(d)","coverage":"full","delta":null,"framework":"hipaa","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"45 CFR Parts 160/164 (Security, Privacy, Breach Notification)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/ctrl-hipaa-hipaa-164-312-d-d1e8fe74.json","targetId":"ctrl:hipaa:HIPAA-164.312(d)","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6663c31b9b165fa27127bd92c127a2817e550fa5f05670e4f98d1ea7cee1d021","properties":{"control_id":"IA-8","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ia-8-b6acedd3.json","targetId":"ctrl:nist-800-53:IA-8","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6e7b5948b7ce48afa724d8e5d36745c514805470d3d69cca991902be3993e80b","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","targetId":"uc:UC-ACCESS-09","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9e33604ad097e8a28ce939d3a004ca175363cc5952d2d1035eab595b1624721c","properties":{"control_id":"IA-2","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ia-2-081cfd11.json","targetId":"ctrl:nist-800-53:IA-2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:be79657587a31e1e4e539adc6ab5bb7a0f9ca6cbefbbf8e284f2bb97974db7ec","properties":{"control_id":"500.12","coverage":"partial","delta":"amended 500.12 requires MFA for any access to any information system","framework":"nydfs-500","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"23 NYCRR 500, Second Amendment"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/ctrl-nydfs-500-500-12-c3c47b61.json","targetId":"ctrl:nydfs-500:500.12","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:c8436cf942803f6684548623379ec24ed1adf724f2ef38897a2c22b83c5b428f","properties":{"rationale":"MFA blocks account takeover even when a password is phished, the canonical defense against credential-harvesting social engineering.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/risk-aware-phishing-social-engineering-bb9b7bd6.json","targetId":"risk:aware-phishing-social-engineering","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f0f0e57b9b1f50b27db4bebb245066f252a19ab202769a7161673aebbbffcbf5","properties":{"control_id":"PR.AA-04","coverage":"full","delta":null,"framework":"nist-csf-2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2.0"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/ctrl-nist-csf-2-pr-aa-04-a26d715d.json","targetId":"ctrl:nist-csf-2:PR.AA-04","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f62bc12363b88d2a2532db52ba69792e4010cf7b96f0aa647a145a846a23c2a7","properties":{"rationale":"MFA directly defeats account takeover using stolen credentials.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","sourceId":"uc:UC-ACCESS-09","targetDetailPath":"/data/v1/records/risk-fraud-external-c3ce412f.json","targetId":"risk:fraud-external","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f8202fa3b22c4123e29cd9085d04187a7be7e9046640fa444a0651f1af1aa214","properties":{},"sourceDetailPath":"/data/v1/records/wf-d40-de759eff.json","sourceId":"wf:D40","targetDetailPath":"/data/v1/records/uc-uc-access-09-444baafe.json","targetId":"uc:UC-ACCESS-09","type":"operates"}],"schemaVersion":1}
