Disclose and operate authentication and authorization features per MDS2 PAUT + NAUT + AUTH sections. Person Authentication (PAUT) including user identification + password complexity + MFA support + biometric authentication + smart-card support + LDAP/Active Directory integration + IDP (Identity Provider) federation + SAML / OAuth / OIDC support. Node Authentication (NAUT) including device-to-device authentication + certificate-based authentication + mutual TLS + IEEE 802.1X port-based authentication + DICOM TLS + HL7 FHIR authentication. Authorization (AUTH) including role-based access control (RBAC) + least privilege enforcement + separation of duties + break-glass emergency access + delegated administration. Auto Logoff (AUTH-01) including configurable session timeout + lock screen + clinical workflow consideration. Emergency Access (EMRG) including break-glass procedures + audit trail of emergency use + post-incident review + clinical override workflow. Failed login lockout + account recovery + privilege escalation controls.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.