Business roles and responsibilities, authority levels and segregation of duties that support process objectives are managed, and access to every information asset tied to business processes is authorised: roles and responsibilities follow approved job descriptions and process activities; authority levels for approving transactions and other decisions, and transaction limits, follow approved job roles; sensitive activities are allocated so duties are clearly separated; access rights and privileges are limited to the minimum that predefined job roles need and are removed or revised at once when a role changes or employment ends; regular awareness and training cover roles, responsibilities, why controls matter, and the privacy, confidentiality, integrity and security of information; administrative privileges are protected, tracked and controlled so they cannot be misused; and definitions of access control, together with logs and exception reports, are reviewed periodically so privileges stay valid and match current staff and roles.
This control maps to 3 controls across 2 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.