{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Access Control & Identity Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-11","description":"Accounts lock or are throttled after a defined number of consecutive failed logon attempts for a set duration or until administrator release. Risk-based signals such as location, device, and behavior trigger adaptive responses including step-up authentication, additional verification, or denial for anomalous logon attempts. Lockout and anomaly events are logged for review.","details":{"control_category":"technical","control_type":"preventive","domain":"Access Control & Identity Management","guidance":[],"members":[{"control_id":"AC-7","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"IA-10","coverage":"full","framework":"nist-800-53","relationship":"superset_of"}],"statement":"Accounts lock or are throttled after a defined number of consecutive failed logon attempts for a set duration or until administrator release. Risk-based signals such as location, device, and behavior trigger adaptive responses including step-up authentication, additional verification, or denial for anomalous logon attempts. Lockout and anomaly events are logged for review.","title":"Defend logons against brute-force and anomalous attempts","unified_id":"UC-ACCESS-11"},"id":"uc:UC-ACCESS-11","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-11","sourceIds":["nist-800-53"],"sourceUrl":null,"title":"UC-ACCESS-11 — Defend logons against brute-force and anomalous attempts","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2a4dcd459e177327f6c5f3a8c16c0932fdf5faf3a36434791bf6100b08f7b596","properties":{},"sourceDetailPath":"/data/v1/records/wf-c31-c58b2f38.json","sourceId":"wf:C31","targetDetailPath":"/data/v1/records/uc-uc-access-11-d0c7a1b8.json","targetId":"uc:UC-ACCESS-11","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:301e71987910971887fd90ce636fe5692599db162efe0e95c494e05888462f04","properties":{"rationale":"Risk-based anomaly signals and lockout directly detect and block credential-stuffing account takeover.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-11-d0c7a1b8.json","sourceId":"uc:UC-ACCESS-11","targetDetailPath":"/data/v1/records/risk-fraud-external-c3ce412f.json","targetId":"risk:fraud-external","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:435e2fb4240e50636eab5b16c43cbcca88008ba7abe4719e697272400a4622b3","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-access-11-d0c7a1b8.json","targetId":"uc:UC-ACCESS-11","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:4b03d6dec92c091438d0a590015df5a172bbe771684b811c56a7999c7cce4ba2","properties":{"control_id":"AC-7","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-11-d0c7a1b8.json","sourceId":"uc:UC-ACCESS-11","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-7-b8145c2d.json","targetId":"ctrl:nist-800-53:AC-7","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5ca871fd3bc257d41a984d7cf3db606ec23575270303f89754a85a07fb36eba3","properties":{},"sourceDetailPath":"/data/v1/records/wf-c5-907af9a4.json","sourceId":"wf:C5","targetDetailPath":"/data/v1/records/uc-uc-access-11-d0c7a1b8.json","targetId":"uc:UC-ACCESS-11","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b0ccdb2eee56a902f62515a1cee4335fa6d18466bbea94354557bcbe8503b9a9","properties":{"rationale":"Adaptive step-up or denial catches use of phished credentials from anomalous location/device contexts.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-11-d0c7a1b8.json","sourceId":"uc:UC-ACCESS-11","targetDetailPath":"/data/v1/records/risk-aware-phishing-social-engineering-bb9b7bd6.json","targetId":"risk:aware-phishing-social-engineering","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:b72786f1fa13edfa75b3a414d40ae68e2d5ddaed4cbaf1e7d47c4d4180a09758","properties":{"rationale":"Account lockout and throttling after consecutive failed attempts directly defeat brute-force login.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-11-d0c7a1b8.json","sourceId":"uc:UC-ACCESS-11","targetDetailPath":"/data/v1/records/risk-access-weak-authentication-4e35bdb2.json","targetId":"risk:access-weak-authentication","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:e1fe81feb49884bb34ed6e072a25b85c8be16d038978d7656a5f138ac2de282f","properties":{"control_id":"IA-10","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-11-d0c7a1b8.json","sourceId":"uc:UC-ACCESS-11","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ia-10-ee664ad9.json","targetId":"ctrl:nist-800-53:IA-10","type":"maps_to"}],"schemaVersion":1}
