{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-15","description":"Management selects and develops control activities, including general controls over technology, that mitigate identified access-related risks to acceptable levels, documented in a control matrix mapping risks to controls. Control designs cover the technology infrastructure, security management, and acquisition and development processes relevant to access, and are updated as risks and systems change.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"P10","coverage":"partial","delta":"principle applies across all control domains, not only access","framework":"coso-ic","relationship":"intersects_with"},{"control_id":"P11","coverage":"partial","delta":"principle applies across all technology domains, not only access","framework":"coso-ic","relationship":"intersects_with"}],"statement":"Management selects and develops control activities, including general controls over technology, that mitigate identified access-related risks to acceptable levels, documented in a control matrix mapping risks to controls. Control designs cover the technology infrastructure, security management, and acquisition and development processes relevant to access, and are updated as risks and systems change.","title":"Design control activities over technology access","unified_id":"UC-ACCESS-15"},"id":"uc:UC-ACCESS-15","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-15","sourceIds":["coso-ic"],"sourceUrl":null,"title":"UC-ACCESS-15 — Design control activities over technology access","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:04d838a2ebd498b71989710ebb6e860e4c16b5116cc025be852189625f8c67c8","properties":{"rationale":"Selecting and developing control activities and general technology controls (COSO P10/P11) directly builds the control environment.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-15-84699cae.json","sourceId":"uc:UC-ACCESS-15","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:32ebdf77cd39fd0171fbda283129683cd51cf83bf6c6b996486f8faad94bbed9","properties":{"rationale":"General controls over technology access underpin the ITGC layer supporting reliable financial reporting.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-15-84699cae.json","sourceId":"uc:UC-ACCESS-15","targetDetailPath":"/data/v1/records/risk-fin-icfr-material-weakness-cdd66323.json","targetId":"risk:fin-icfr-material-weakness","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:43475dfb7425d14278b1e6235a1f64da359783004e9a2836edb1f63b335f7555","properties":{},"sourceDetailPath":"/data/v1/records/wf-c4-4c0ca700.json","sourceId":"wf:C4","targetDetailPath":"/data/v1/records/uc-uc-access-15-84699cae.json","targetId":"uc:UC-ACCESS-15","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:520f5a633eaecdd35935d34d80124130582f6d18b4ba91cfe460f553b9e1b843","properties":{},"sourceDetailPath":"/data/v1/records/wf-s1-ee2f3289.json","sourceId":"wf:S1","targetDetailPath":"/data/v1/records/uc-uc-access-15-84699cae.json","targetId":"uc:UC-ACCESS-15","type":"oversees"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bf07ea55fc952704c5d303cbd5c6caf2fbdf32cd3874064dffdbd61f4f97d0f3","properties":{"rationale":"Access control activities limiting unauthorized access reduce opportunity for insider misappropriation.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-15-84699cae.json","sourceId":"uc:UC-ACCESS-15","targetDetailPath":"/data/v1/records/risk-fraud-internal-misappropriation-d235cd10.json","targetId":"risk:fraud-internal-misappropriation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:cb4bb91299330aba65c724847882f00b89cc0fa6a325e17292b684496c582f1b","properties":{"control_id":"P11","coverage":"partial","delta":"principle applies across all technology domains, not only access","framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-access-15-84699cae.json","sourceId":"uc:UC-ACCESS-15","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p11-2a08883b.json","targetId":"ctrl:coso-ic:P11","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:dc58a262b9c5130739984b7631650a439ee6b18ce8a57263d9b917ac82a47ad5","properties":{"control_id":"P10","coverage":"partial","delta":"principle applies across all control domains, not only access","framework":"coso-ic","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"2013"},"sourceDetailPath":"/data/v1/records/uc-uc-access-15-84699cae.json","sourceId":"uc:UC-ACCESS-15","targetDetailPath":"/data/v1/records/ctrl-coso-ic-p10-c5a97f20.json","targetId":"ctrl:coso-ic:P10","type":"maps_to"}],"schemaVersion":1}
