At least every six months IT management, besides the system administrator, reviews the #32 list for unauthorized or outdated accounts and the #33 list for permissions appropriate to each user's position, with the reviewers named in the written system.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.