Section 11.300 establishes the controls for identification codes + passwords used as electronic signature components: (a) MAINTAINING THE UNIQUENESS of each combined identification code + password such that no two individuals have the same combination of identification code + password; (b) ENSURING that identification code + password issuances are periodically checked + recalled + or revised (e.g. to cover such events as password aging); (c) FOLLOWING LOSS MANAGEMENT PROCEDURES TO ELECTRONICALLY DEAUTHORIZE LOST + STOLEN + MISSING + or otherwise potentially compromised tokens + cards + and other devices that bear or generate identification code or password information + to issue temporary or permanent replacements using suitable + rigorous controls; (d) USE OF TRANSACTION SAFEGUARDS to prevent unauthorised use of passwords and / or identification codes + to detect and report in an immediate and urgent manner any attempts at their unauthorised use to the system security unit + and, as appropriate + to organisational management; (e) INITIAL AND PERIODIC TESTING of devices, such as tokens or cards, that bear or generate identification code or password information to ensure that they function properly and have not been altered in an unauthorised manner.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.