Implement Access Control + Cryptography + Network and Infrastructure Security per MAS TRM Chapters 9 + 10. Chapter 9 Access Control + Cryptography - access control policy + user identification + authentication (Multi-Factor Authentication MFA required for privileged access per Notice 655 + biometric + smart cards + soft tokens) + authorisation (Role-Based Access Control RBAC + Attribute-Based Access Control ABAC + Mandatory Access Control MAC) + accountability (audit logging + monitoring) + least privilege + separation of duties + privileged access management (PAM) with session recording + just-in-time access + service accounts management + machine identities + Cryptography per ISO/IEC 18033 + FIPS 140-2/140-3 validated modules + key management (key generation + storage + rotation + destruction) + Hardware Security Module (HSM) for key storage + Public Key Infrastructure (PKI) + Certificate Authority (CA) + Certificate Lifecycle Management + algorithm strength (AES-256 + RSA-3072+ + ECC P-256+ + SHA-256+) + Post-Quantum Cryptography (PQC) preparation per NIST PQC. Chapter 10 Network and Infrastructure Security - network segmentation (perimeter + DMZ + internal + management + critical systems + customer-facing) + firewall + IDS/IPS + DDoS protection + WAF + network access control (NAC) + 802.1X + secure remote access + VPN + bastion host + jump server + privileged access workstation (PAW) + endpoint protection (EPP + EDR + XDR) + email security (S/MIME + DKIM + DMARC + SPF + ATP) + DNS security + zero trust architecture (NIST SP 800-207 + CISA Zero Trust Maturity Model). MAS Notice 655 baseline: administrative accounts + security patching + security standards + network perimeter + malware protection + MFA.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.