{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Access Control & Identity Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-14","description":"Actions permitted without identification or authentication are explicitly defined, documented, and limited to designated public functions. Information shared with external parties requires owner authorization consistent with classification and sharing agreements. Only trained, designated individuals may post content to publicly accessible systems, with pre-publication review and periodic checks to ensure no nonpublic information is exposed.","details":{"control_category":"administrative","control_type":"preventive","domain":"Access Control & Identity Management","guidance":[],"members":[{"control_id":"AC-14","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"AC-21","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"AC-22","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"B003","coverage":"partial","delta":"controlled public release of model, system-prompt, and architecture details so technical over-disclosure does not aid adversaries","framework":"aiuc-1","relationship":"intersects_with"}],"statement":"Actions permitted without identification or authentication are explicitly defined, documented, and limited to designated public functions. Information shared with external parties requires owner authorization consistent with classification and sharing agreements. Only trained, designated individuals may post content to publicly accessible systems, with pre-publication review and periodic checks to ensure no nonpublic information is exposed.","title":"Authorize public content and external information sharing","unified_id":"UC-ACCESS-14"},"id":"uc:UC-ACCESS-14","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-14","sourceIds":["aiuc-1","nist-800-53"],"sourceUrl":null,"title":"UC-ACCESS-14 — Authorize public content and external information sharing","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:043f2c6db127eb3720fbb6fe0ef5fc523b3a1ca7932e0d7f97f882f62693315a","properties":{"control_id":"AC-14","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-14-99fd72b5.json","sourceId":"uc:UC-ACCESS-14","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-14-f34116e8.json","targetId":"ctrl:nist-800-53:AC-14","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0ce0f8467c5cbb3f7fe33b9ca92c57eaead7db87b5d205bf406223e3913e97fd","properties":{},"sourceDetailPath":"/data/v1/records/wf-g33-6008159c.json","sourceId":"wf:G33","targetDetailPath":"/data/v1/records/uc-uc-access-14-99fd72b5.json","targetId":"uc:UC-ACCESS-14","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:23043fe161d8a3824846ebf453d44150b2ff499f0c7c1afc949b74f290d2361a","properties":{"rationale":"Pre-publication review preventing exposure of nonpublic information reduces reconnaissance data available for spear-phishing.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-14-99fd72b5.json","sourceId":"uc:UC-ACCESS-14","targetDetailPath":"/data/v1/records/risk-aware-phishing-social-engineering-bb9b7bd6.json","targetId":"risk:aware-phishing-social-engineering","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:57c1e16cec640d299115c1992f9706bc20fec65222ac19a4997b8e8a7c78fab3","properties":{"rationale":"Pre-publication review of technical details keeps system-prompt and architecture information from aiding extraction attempts.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-14-99fd72b5.json","sourceId":"uc:UC-ACCESS-14","targetDetailPath":"/data/v1/records/risk-ai-endpoint-abuse-model-extraction-a3c97c52.json","targetId":"risk:ai-endpoint-abuse-model-extraction","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:61ab6cde6d899b2ba90748f2ccbfecd5f4955ab12b3f3601465f3272cad5e304","properties":{"control_id":"B003","coverage":"partial","delta":"controlled public release of model, system-prompt, and architecture details so technical over-disclosure does not aid adversaries","framework":"aiuc-1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"July 15, 2026 release (quarterly update cadence)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-14-99fd72b5.json","sourceId":"uc:UC-ACCESS-14","targetDetailPath":"/data/v1/records/ctrl-aiuc-1-b003-8c740cc9.json","targetId":"ctrl:aiuc-1:B003","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:75876308e3e0d55597a021040d43adfd1437f30d5b2ff2135f610b0952f961e0","properties":{"control_id":"AC-21","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-14-99fd72b5.json","sourceId":"uc:UC-ACCESS-14","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-21-b2e5ceab.json","targetId":"ctrl:nist-800-53:AC-21","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:855236ef33984e8f75ef0fb35a489279f0c712fd2690cbcb032d78729cc7ab6f","properties":{"control_id":"AC-22","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-access-14-99fd72b5.json","sourceId":"uc:UC-ACCESS-14","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-22-b3b8bc68.json","targetId":"ctrl:nist-800-53:AC-22","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:95af28686caa0d74cc970898977a6a92f37fd370c99315236ac3f37e066a79bd","properties":{"rationale":"Explicitly defining and limiting actions permitted without authentication to designated public functions prevents anonymous unauthorized use of system functions.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-14-99fd72b5.json","sourceId":"uc:UC-ACCESS-14","targetDetailPath":"/data/v1/records/risk-access-unauthorized-use-equipment-d2082944.json","targetId":"risk:access-unauthorized-use-equipment","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9cc18fb000966998bf9f007f0f8168674282a144230cd365ad622ad7e5ee42d8","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-access-14-99fd72b5.json","targetId":"uc:UC-ACCESS-14","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cf6570a2c3cf7f1caef0ab9a761c8dd3b18bd337750b3d0018674a9f77d403a8","properties":{},"sourceDetailPath":"/data/v1/records/wf-c32-53bd0bae.json","sourceId":"wf:C32","targetDetailPath":"/data/v1/records/uc-uc-access-14-99fd72b5.json","targetId":"uc:UC-ACCESS-14","type":"operates"}],"schemaVersion":1}
