{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Access Control & Identity Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-10","description":"Devices and services (non-person entities) are uniquely identified and mutually authenticated before local, remote, or network connections are established, using cryptographically verifiable credentials such as certificates or managed service identities. Shared static secrets are prohibited or vaulted, and non-person credentials are inventoried and rotated.","details":{"control_category":"technical","control_type":"preventive","domain":"Access Control & Identity Management","guidance":[{"propositionId":"NIST-AGI-02","propositionTitle":"Agent authentication and credential lifecycle","source":"nist-ai-agent-identity","sourcePages":"Concept paper pp. 4, 7: Authentication; Relevant Standards and Guidelines","sourceTitle":"NIST NCCoE: Software and AI Agent Identity and Authorization"}],"members":[{"control_id":"IA-3","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"IA-9","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Devices and services (non-person entities) are uniquely identified and mutually authenticated before local, remote, or network connections are established, using cryptographically verifiable credentials such as certificates or managed service identities. Shared static secrets are prohibited or vaulted, and non-person credentials are inventoried and rotated.","title":"Authenticate devices and services before granting connections","unified_id":"UC-ACCESS-10"},"id":"uc:UC-ACCESS-10","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-10","sourceIds":["nist-800-53","nist-ai-agent-identity"],"sourceUrl":null,"title":"UC-ACCESS-10 — Authenticate devices and services before granting connections","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4b2f0097dcf1944017c2814c5958d1e416499b1aceb4056c1db36a2931f2a8ba","properties":{"rationale":"Requiring verifiable device credentials to connect blocks reintroduction of untrusted or compromised devices.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-10-130762ce.json","sourceId":"uc:UC-ACCESS-10","targetDetailPath":"/data/v1/records/risk-net-remote-work-mobile-exposure-d7aab6d9.json","targetId":"risk:net-remote-work-mobile-exposure","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4b97843b494ee80ad271519484cee2e291f3acf447dd4e6826ee436d49c7a2a6","properties":{"control_id":"NIST-AGI-02","coverage":"guidance","delta":null,"framework":"nist-ai-agent-identity","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"informs","sourcePages":"Concept paper pp. 4, 7: Authentication; Relevant Standards and Guidelines","source_version":"February 2026 draft concept paper"},"sourceDetailPath":"/data/v1/records/uc-uc-access-10-130762ce.json","sourceId":"uc:UC-ACCESS-10","targetDetailPath":"/data/v1/records/ctrl-nist-ai-agent-identity-nist-agi-02-8f2c52e7.json","targetId":"ctrl:nist-ai-agent-identity:NIST-AGI-02","type":"informed_by"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:59e47333cfc4a11e865b2ae80f798e9897c8f749f41604f34a33da67a77f7d5d","properties":{"rationale":"Cryptographic non-person credentials with no shared static secrets extend strong authentication to services and devices.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-10-130762ce.json","sourceId":"uc:UC-ACCESS-10","targetDetailPath":"/data/v1/records/risk-access-weak-authentication-4e35bdb2.json","targetId":"risk:access-weak-authentication","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:720ec76c5f05226806fdfae43db7f38aa662d1cd4ef219f5782e1d32b639e1b6","properties":{"control_id":"IA-3","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-10-130762ce.json","sourceId":"uc:UC-ACCESS-10","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ia-3-b1f0bec7.json","targetId":"ctrl:nist-800-53:IA-3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7376b163d03d1a126ae700e44399a7d20b79aa73135db7650b0f8342e9e91c70","properties":{},"sourceDetailPath":"/data/v1/records/wf-c49-5eff4769.json","sourceId":"wf:C49","targetDetailPath":"/data/v1/records/uc-uc-access-10-130762ce.json","targetId":"uc:UC-ACCESS-10","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:76403d6bcb069e6311e6cee4c58f9e6456b3b675e0fc6a3418e874bfca08e122","properties":{"rationale":"Mutually authenticating devices and services before any connection directly blocks rogue or unauthorized devices from connecting.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-10-130762ce.json","sourceId":"uc:UC-ACCESS-10","targetDetailPath":"/data/v1/records/risk-access-unauthorized-use-equipment-d2082944.json","targetId":"risk:access-unauthorized-use-equipment","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7c2de1bd28f521c96ffc750d79833dc5f5caf914953a78fc9f23ff4a37c5a939","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-access-10-130762ce.json","targetId":"uc:UC-ACCESS-10","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:edd818fca3cec7ef57f6f6c0fb51119f230acf6cfa20fddde35bc437da524e7a","properties":{"control_id":"IA-9","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-10-130762ce.json","sourceId":"uc:UC-ACCESS-10","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ia-9-151a6bfe.json","targetId":"ctrl:nist-800-53:IA-9","type":"maps_to"}],"schemaVersion":1}
