Agencies must confirm, before granting anyone cryptographic system administrator access, that the person has: a demonstrated need for the access; read, and agreed to follow, the KMP (Key Management Policy and Plan) that applies to the cryptographic system in use; a clearance at or above the highest classification of information the cryptographic system processes; agreed to protect the system's authentication information at the level of the highest classification it secures; agreed not to share that authentication information unless approved; agreed to be accountable for every action under their accounts; agreed to report to the GCSB any problem that may be security related; and the agency must also make sure relevant staff have had appropriate training.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.