Access Management and Segregation of Duties. Procedures must manage the allocation of access rights to information systems, and roles and areas of responsibility should be segregated to minimise the risk of unauthorised or unintentional modification or misuse (paras 45-46).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.