Players authenticate with a username and password or a secure alternative accepted by the regulatory body, and more than one method may be offered; an unrecognised username or password produces an explanatory prompt to re-enter; forgotten credentials are retrieved or reset through multi-factor authentication; balance and transaction options are available once authenticated; and an account can be locked on suspicious activity such as repeated failed logins, with multi-factor authentication required to unlock it.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.