{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"administrative","domain":"Human Resources / Personnel Security","type":"preventive"},"canonicalUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-HR-03","description":"A documented separation process ensures that on termination, system access is revoked and organizational assets are recovered on a defined timeline, same-day for involuntary separations, with exit discussions reaffirming surviving confidentiality obligations and notification of relevant parties. On transfer or role change, access is re-evaluated and adjusted to the new role within a defined period, with changes logged.","details":{"control_category":"administrative","control_type":"preventive","domain":"Human Resources / Personnel Security","guidance":[],"members":[{"control_id":"PS-4","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"PS-5","coverage":"full","framework":"nist-800-53","relationship":"superset_of"},{"control_id":"A.6.5","coverage":"full","framework":"iso-27001","relationship":"superset_of"}],"statement":"A documented separation process ensures that on termination, system access is revoked and organizational assets are recovered on a defined timeline, same-day for involuntary separations, with exit discussions reaffirming surviving confidentiality obligations and notification of relevant parties. On transfer or role change, access is re-evaluated and adjusted to the new role within a defined period, with changes logged.","title":"Secure termination and transfer of personnel","unified_id":"UC-HR-03"},"id":"uc:UC-HR-03","mapUrl":"https://controlsmap.com/?v=1&node=uc%3AUC-HR-03","sourceIds":["iso-27001","nist-800-53"],"sourceUrl":null,"title":"UC-HR-03 — Secure termination and transfer of personnel","type":"unified"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:221c0572868063d2db85bd10571bff2cbba0dc633113e78a4d9e4eccd007185e","properties":{"rationale":"Access revocation and transfer re-evaluation contain the blast radius of an insider who slipped through vetting but perform no screening; the operative vetting defense is UC-HR-01, so this is contributory, not primary.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-03-1f58d8f9.json","sourceId":"uc:UC-HR-03","targetDetailPath":"/data/v1/records/risk-hr-insufficient-screening-bdce1f80.json","targetId":"risk:hr-insufficient-screening","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:384f2b698a5b77da918ec446d11f2c6e1752d673f729062ae90db8cb0495f8d3","properties":{},"sourceDetailPath":"/data/v1/records/wf-c19-ef930979.json","sourceId":"wf:C19","targetDetailPath":"/data/v1/records/uc-uc-hr-03-1f58d8f9.json","targetId":"uc:UC-HR-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:648f733628f6a7bd9e685444cb0605b5332cb209a4d55e40be9cc6c2e5e671f0","properties":{},"sourceDetailPath":"/data/v1/records/wf-d30-c61ffe25.json","sourceId":"wf:D30","targetDetailPath":"/data/v1/records/uc-uc-hr-03-1f58d8f9.json","targetId":"uc:UC-HR-03","type":"operates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:6fee7f9071dd1b4fc165c0b128d5c95888e11c56a9ab58731a6fd2ec6e33fdfd","properties":{"control_id":"PS-5","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-03-1f58d8f9.json","sourceId":"uc:UC-HR-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ps-5-217bfb95.json","targetId":"ctrl:nist-800-53:PS-5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7bcb204ccae05bbf391573cd9d136907beaf293abd4f58318b111054c8761b38","properties":{},"sourceDetailPath":"/data/v1/records/wf-d06-c9616fb8.json","sourceId":"wf:D06","targetDetailPath":"/data/v1/records/uc-uc-hr-03-1f58d8f9.json","targetId":"uc:UC-HR-03","type":"tests"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:7dfb9a1bfb567751e34578de3255a09bc8e7897a1a7ea1821bdbc6ce3a7e6f7f","properties":{"control_id":"A.6.5","coverage":"full","delta":null,"framework":"iso-27001","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"2022"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-03-1f58d8f9.json","sourceId":"uc:UC-HR-03","targetDetailPath":"/data/v1/records/ctrl-iso-27001-a-6-5-0eefa5a7.json","targetId":"ctrl:iso-27001:A.6.5","type":"maps_to"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:fc926c18b8f7d8a3a697d8a6ff472266ea8a182358453ba1339611a502cb5f17","properties":{"control_id":"PS-4","coverage":"full","delta":null,"framework":"nist-800-53","provenance":{"defaultConfidence":"medium","defaultStatus":"active","direction":"canonical_to_source","mapper":"coworkcanvas-compliance-graph","note":"Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.","reviewDate":"2026-09-07"},"relationship":"superset_of","source_version":"Rev. 5"},"sourceDetailPath":"/data/v1/records/uc-uc-hr-03-1f58d8f9.json","sourceId":"uc:UC-HR-03","targetDetailPath":"/data/v1/records/ctrl-nist-800-53-ps-4-30b0fd23.json","targetId":"ctrl:nist-800-53:PS-4","type":"maps_to"}],"schemaVersion":1}
