The organisation identifies and documents the duties of individuals that must be separated and defines system access authorizations that support that separation of duties. No enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.