A typical access control system aims to: let authorised people, materials and vehicles into controlled areas; detect, minimise and stop attempted entry or exit by unauthorised people, vehicles or materials; give security staff information to assess and respond to unauthorised entry; and keep an audit trail of who was granted access, to what, where and when. It does this by verifying authorisation through something the person holds (a valid credential or key), something a person knows (an identification number or code) and something inherent to the person (a biometric characteristic).
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.