The access control policy is enforced on the basis of security attributes, with explicit rules for allowing and denying operations. The standard's application note for this SFR sets how its operations are to be completed for a QKD module.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.