{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"technical","domain":"Secure Configuration & Change Management","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-16","description":"Changes to applications and infrastructure, and new system development, follow a documented lifecycle: authorized request, risk-assessed design, testing in non-production environments, documented approval, and controlled migration to production by personnel independent of development. Emergency changes are ratified retrospectively, and evidence of each gate is retained.","details":{"control_category":"technical","control_type":"preventive","domain":"Secure Configuration & Change Management","guidance":[],"members":[{"control_id":"SOC1-2","coverage":"full","framework":"soc1","relationship":"superset_of"},{"control_id":"SOC1-3","coverage":"full","framework":"soc1","relationship":"superset_of"}],"statement":"Changes to applications and infrastructure, and new system development, follow a documented lifecycle: authorized request, risk-assessed design, testing in non-production environments, documented approval, and controlled migration to production by personnel independent of development. Emergency changes are ratified retrospectively, and evidence of each gate is retained.","title":"Authorize, test, and approve changes and development","unified_id":"UC-ACCESS-16"},"id":"uc:UC-ACCESS-16","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-ACCESS-16","sourceIds":["soc1"],"sourceUrl":null,"title":"UC-ACCESS-16 — Authorize, test, and approve changes and development","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:1a8aee61fe02ddbee4aadb736a25c4da91ac46bb09d35b89cf86b7be91498103","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","targetId":"uc:UC-ACCESS-16","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3327640719d1b96d034a350d7aa59ec095723c35aface189c0344e6e951644e2","properties":{},"sourceDetailPath":"/data/v1/records/wf-s5-a655abf2.json","sourceId":"wf:S5","targetDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","targetId":"uc:UC-ACCESS-16","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3b26f5b7dd3ea6d611ce3884e501d07d1c17144ae41c092fef0c7588ce3ad15b","properties":{"control_id":"SOC1-3","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-3-762891cb.json","targetId":"ctrl:soc1:SOC1-3","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:610a50fbfce562d7abb329df448ae492410a9a88750151ea34b93e955dfdf08a","properties":{"rationale":"Requiring authorized, documented changes reduces the unauthorized changes that drive drift, though baseline monitoring is the operative control.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/risk-config-poor-baseline-drift-2dd66324.json","targetId":"risk:config-poor-baseline-drift","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9fcff12028e176d5c2873539c7d60baa0ea46c4326e0725998744121fab21a9c","properties":{},"sourceDetailPath":"/data/v1/records/wf-c41-f5b6a3b6.json","sourceId":"wf:C41","targetDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","targetId":"uc:UC-ACCESS-16","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a2e38565659d2389482f09121d6f3a226ad91bb51d3f4a289a62de12de94f513","properties":{"rationale":"Pre-production testing and approval gates catch legacy-integration interface mismatches and configuration errors before they reach production.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/risk-ai-emergent-integration-risk-8490271c.json","targetId":"risk:ai-emergent-integration-risk","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a32c1438848292071633ba6932b26ecd566dfc1598b5a5ed0957c7a2dcbd2499","properties":{},"sourceDetailPath":"/data/v1/records/wf-a18-be3cee23.json","sourceId":"wf:A18","targetDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","targetId":"uc:UC-ACCESS-16","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:abf7ed8d7b7a0a3f7db28f2713b29fef6ba0e4e2822a69a31a57217c46803f66","properties":{"rationale":"Mandatory testing in non-production before approval/migration directly prevents releasing inadequately tested software to production.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/risk-vuln-inadequate-testing-scanning-ee33b888.json","targetId":"risk:vuln-inadequate-testing-scanning","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:ac926831df5567af31dda7687bb08beb6241ad883936c5e38dcee1bd556bd753","properties":{"control_id":"SOC1-2","coverage":"full","delta":null,"framework":"soc1","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"SSAE 18 (current AICPA SOC suite)"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/ctrl-soc1-soc1-2-7fcfb329.json","targetId":"ctrl:soc1:SOC1-2","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:be88249853f99703d19cefb0ad41a99cd93d410c5b64fd1ff7f47b7359d6cb3f","properties":{"rationale":"The authorize->test->approve->independent-migration gate IS the change-control process, directly preventing unapproved or untested changes.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-16-7a8d6d65.json","sourceId":"uc:UC-ACCESS-16","targetDetailPath":"/data/v1/records/risk-config-weak-change-control-e7d90eaf.json","targetId":"risk:config-weak-change-control","type":"mitigates"}],"schemaVersion":1}
