Section 11.10 access + control elements: (d) LIMITING SYSTEM ACCESS TO AUTHORISED INDIVIDUALS - role-based access control (RBAC) + least-privilege + provisioning + de-provisioning lifecycle + periodic access reviews + segregation of duties; (f) USE OF OPERATIONAL SYSTEM CHECKS TO ENFORCE PERMITTED SEQUENCING OF STEPS AND EVENTS AS APPROPRIATE - workflow + step-by-step controls preventing out-of-order execution (e.g. release approval before product release; review before submission); (g) USE OF AUTHORITY CHECKS to ensure that only authorised individuals can use the system + electronically sign a record + access the operation or computer system input or output device + alter a record or perform the operation at hand - the authority check is the just-in-time verification at the moment of action that the user has the right to perform the specific action; (h) USE OF DEVICE (e.g. TERMINAL) CHECKS to determine the validity of the source of data input + operational instruction - typically network-level controls + device-fingerprint or terminal-identification ensuring the data + instruction comes from a registered + authorised device. Combined § 11.10(d)/(f)/(g)/(h) form the operational-security backbone of Part 11.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.