Lloyds MS11.4 Access Control and Privileged Access Management - identity and access management (IAM) per industry best practice (ISO 27001 A.9 + NIST SP 800-53 AC family) + role-based access control (RBAC) + least privilege + segregation of duties + identity lifecycle (joiner-mover-leaver) + privileged access management (PAM) with vault + session recording + just-in-time access + ephemeral credentials + multi-factor authentication (MFA) mandatory for: (a) all privileged accounts including domain admins + cloud admin consoles + database admins; (b) all remote access (VPN + RDP + SSH); (c) all Internet-facing administrative interfaces; (d) Lloyds-required: claims handling systems + underwriting platforms + financial accounts + customer data access; (e) FCA/PRA-recommended additional MFA for senior managers SMF1-SMF24 access. Customer authentication: Strong Customer Authentication (SCA) for insurance distribution per PSD2-equivalent retail customer access where applicable. MS11.5 Vulnerability and Patch Management - documented vulnerability management programme + asset-level vulnerability scanning + container scanning + cloud Security Posture Management (CSPM) + patch SLAs (Critical 7 days + High 30 days + Medium 90 days + Low 180 days) + emergency patch process for actively-exploited vulnerabilities (zero-day) + virtual patching via Web Application Firewall (WAF) + vulnerability disclosure programme + Coordinated Vulnerability Disclosure (CVD) per ISO 29147 + bug bounty consideration + Common Vulnerability Scoring System (CVSS) prioritisation + CISA Known Exploited Vulnerabilities Catalogue alignment.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.