{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Governance, Policy & Oversight","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-31","description":"Establish, document, and disseminate policies and procedures governing logical access control, identification and authentication, and personnel (human resources) security — covering authorization based on need-to-know and least privilege, credential and authenticator management, and personnel screening, transfer, and termination requirements. Communicate these policies to the workforce and review and update them at defined intervals and upon significant change.","details":{"control_category":"administrative","control_type":"preventive","domain":"Governance, Policy & Oversight","guidance":[],"members":[{"control_id":"AC-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"IA-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PS-1","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"NIS2-Art21i","coverage":"partial","delta":"asset management policy and operational measures","framework":"nis2","relationship":"intersects_with"}],"statement":"Establish, document, and disseminate policies and procedures governing logical access control, identification and authentication, and personnel (human resources) security — covering authorization based on need-to-know and least privilege, credential and authenticator management, and personnel screening, transfer, and termination requirements. Communicate these policies to the workforce and review and update them at defined intervals and upon significant change.","title":"Maintain access control, identity, and personnel security policies","unified_id":"UC-GOV-31"},"id":"uc:UC-GOV-31","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-GOV-31","sourceIds":["nis2","nist-800-53"],"sourceUrl":null,"title":"UC-GOV-31 — Maintain access control, identity, and personnel security policies","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:131ba90d30fa6f38458f6ef0c0e180e759d82363636d3927ed277275246f5ed4","properties":{"control_id":"IA-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-31-46e68199.json","sourceId":"uc:UC-GOV-31","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ia-1-bb63a54e.json","targetId":"ctrl:nist-800-53:IA-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:478768bc2b6e32df7b2b4c0aa2727e33baa93896525bb45bd9f906eba92c730a","properties":{"rationale":"Establishing access-control, identity, and personnel-security policies remedies missing policies and undefined access duties.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-31-46e68199.json","sourceId":"uc:UC-GOV-31","targetDetailPath":"/data/v1/records/risk-gov-policy-absent-cf76dbbf.json","targetId":"risk:gov-policy-absent","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5b5455de5c0de0b50a25afbc0350ba53f54669f70575e5c2acae37f5fa25ae67","properties":{"control_id":"NIS2-Art21i","coverage":"partial","delta":"asset management policy and operational measures","framework":"nis2","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"intersects_with","source_version":"Directive (EU) 2022/2555"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-31-46e68199.json","sourceId":"uc:UC-GOV-31","targetDetailPath":"/data/v1/records/ctrl-nis2-nis2-art21i-d5158327.json","targetId":"ctrl:nis2:NIS2-Art21i","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:68d27ccb03fbd66b5674b0f14150c97a1d6a5d3e1d393a4cdac3d30ac979f1b5","properties":{"rationale":"Least-privilege authorization and personnel screening/termination requirements reduce insider-fraud opportunity.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-31-46e68199.json","sourceId":"uc:UC-GOV-31","targetDetailPath":"/data/v1/records/risk-fraud-internal-misappropriation-d235cd10.json","targetId":"risk:fraud-internal-misappropriation","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7108fc4c1ccc27b062783f0c2f878d83d12c1f88f9ef73867d0f28df545f0cff","properties":{"control_id":"PS-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-31-46e68199.json","sourceId":"uc:UC-GOV-31","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ps-1-5e54c922.json","targetId":"ctrl:nist-800-53:PS-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:92c4d9bd43d662b553c21857833a52af1e04b8800dd812d89c880c69170cbc48","properties":{"control_id":"AC-1","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-31-46e68199.json","sourceId":"uc:UC-GOV-31","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ac-1-0b69cf8d.json","targetId":"ctrl:nist-800-53:AC-1","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:a07967c9377f5646dfdb472c254486f40ff70c05a9cc91aa40b3f4da38998b6f","properties":{},"sourceDetailPath":"/data/v1/records/wf-c26-0d7976b8.json","sourceId":"wf:C26","targetDetailPath":"/data/v1/records/uc-uc-gov-31-46e68199.json","targetId":"uc:UC-GOV-31","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:eaee02d29ac324222bdcbfadff33bb58c4a695fe03ec41900de9dec7895d3153","properties":{},"sourceDetailPath":"/data/v1/records/wf-c9-75fb1752.json","sourceId":"wf:C9","targetDetailPath":"/data/v1/records/uc-uc-gov-31-46e68199.json","targetId":"uc:UC-GOV-31","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f1b1da5d7d2f9272b8b80e1278376d72fa57638b9ab1d1e28438eebc4f9bf2f8","properties":{},"sourceDetailPath":"/data/v1/records/wf-g9-d1e65641.json","sourceId":"wf:G9","targetDetailPath":"/data/v1/records/uc-uc-gov-31-46e68199.json","targetId":"uc:UC-GOV-31","type":"oversees"}],"schemaVersion":1}
