Each component must be able to identify itself to, and authenticate with, any other component it communicates with (whether a software application or an embedded, host or network device), as SR 1.2 of 3-3 describes; where the component runs on behalf of a human user, as an application may, that user's identification and authentication under SR 1.1 can form part of how the component identifies itself to others. RE 1 makes that identification and authentication unique; the held ISAGCA paper places the requirement among the SL 2 additions that make a rogue device detectable.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.