The organisation defines the account types allowed and prohibited on the system, assigns account managers and data custodians, sets prerequisites for group and role membership, and records the authorized users, their memberships and the privileges and attributes of each account. Account creation needs approval by designated roles; accounts are created, enabled, changed, disabled and removed under defined policy; account use is monitored; account managers are told within set periods when accounts become unneeded or dormant, when users leave or move, and when need-to-know changes. Access is granted only on a valid authorization and intended use, accounts are reviewed at a set frequency, shared or group authenticators are changed when members leave, and account processes are aligned with termination and transfer. 13 enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.