Limit, physically and logically, who can communicate with or use a CBS, handle or learn its information or control its components, without obstructing authorised staff at their level under least privilege, allowing access only to people who need it for their duties. Cat. II and III CBSs sit in lockable rooms, controlled spaces or lockable cabinets yet stay reachable for those who install and maintain them; visitors are restricted, for example to supervised access; network access points serving Cat. II or III CBSs are blocked except under supervision or documented procedure, with isolated computers or guest networks for visitors' needs such as printing; a removable media policy requires malware checks or signature validation before transfer; credentials are managed with access control lists, time-limited accounts removed when no longer needed, zone-appropriate controls (strong keys or MFA where needed) and administrator rights only for trained staff who need them; and privileges are minimal by default, raised only when needed and audited to stop accumulation.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.