Agencies must set out in the System Security Plan (SSP) the authorisations, security clearances and briefings that are required before anyone can access the system.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.