All solutions have user-based access with unique client logins and authentication and authorisation controls (for example a unique username and password); shared logins are not permitted and must be blocked by the DSP, so each user and session is uniquely identifiable in audit logs. This is the minimum authentication requirement for categories D and E and part of the MFA requirement for A to C. Where MFA is not implemented, the DSP should consider passphrase management, account lockout and passphrase reset practices from the Australian Government guidelines for system hardening.
This control maps to 2 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.