Kuwait NCF Protect function (Access). Access Control and Identity Management aligned with NIST SP 800-53 AC family + ISO 27001 A.9 + Zero Trust principles. Identity Lifecycle Management: provisioning (joiner) + entitlement review (mover) + deprovisioning (leaver) + service accounts + non-human identities + machine identities. Authentication: Multi-Factor Authentication (MFA) mandatory for privileged + remote + cloud admin + Internet-facing administrative + Kuwait Bayan unified identity integration + federation via SAML/OIDC + FIDO2 passkeys for high-assurance + biometric for sensitive transactions. Authorisation: Role-Based Access Control (RBAC) + Attribute-Based Access Control (ABAC) for fine-grained + least privilege + segregation of duties + just-in-time access + break-glass procedures. Privileged Access Management (PAM): vault + session recording + privileged session monitoring + ephemeral credentials + privileged identity rotation + KUWAIT NCSC requirements for CNI sector. Identity Access Governance (IAG): periodic access reviews + recertification + access analytics + access risk scoring + segregation of duties enforcement. Cloud identity federation + cross-tenant boundary controls.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.