NIST Cybersecurity Framework 2.0
PR - Protect

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.AA-05: Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 509 controls across 168 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

PCI DSS 4.0 · 19 controls

  • 10.3.1 10.3.1 Audit log read access limited to job need
  • 10.6.3 10.6.3 Time sync configuration and time data protected
  • 2.2.2 2.2.2 Vendor default accounts managed
  • 3.4.2 3.4.2 Remote access blocks copying or relocating PAN
  • 7.2.1 7.2.1 Access control model defined
  • 7.2.2 7.2.2 User access assigned by job function and least privilege
  • 7.2.3 7.2.3 Privileges approved by authorized personnel
  • 7.3.2 7.3.2 Access control system enforces role-based permissions
  • 7.3.3 7.3.3 Access control default deny all
  • 8.2.2 8.2.2 Shared and generic IDs only by exception
  • 9.2.3 9.2.3 Physical protection of network hardware and lines
  • 9.4.1 9.4.1 Physical security of all media
  • 9.4.4 9.4.4 Management approval for media leaving facility
  • 3.6.1 3.6.1 Procedures protect keys against disclosure and misuse
  • 6.5.4 6.5.4 Separate roles between production and pre-production
  • 7.2.4 7.2.4 User accounts and privileges reviewed every six months
  • 7.2.5 7.2.5 Application and system accounts least privilege
  • 7.2.6 7.2.6 Query access to stored cardholder data restricted
  • 7.3.1 7.3.1 Need-to-know access control system covers all components

FedRAMP High · 16 controls

  • AC-2 Account Management
  • AC-2(7) Privileged User Accounts
  • AC-2(9) Restrictions on Use of Shared and Group Accounts
  • AC-3 Access Enforcement
  • AC-5 Separation of Duties
  • AC-6 Least Privilege
  • AC-6(1) Authorize Access to Security Functions
  • AC-6(7) Review of User Privileges
  • CA-9 Internal System Connections
  • CM-12 Information Location (CM-12)
  • CM-5 Access Restrictions for Change
  • MA-3 Maintenance Tools (MA-3)
  • MA-4 Nonlocal Maintenance
  • PS-4 Personnel Termination
  • PS-5 Personnel Transfer
  • SC-18 Mobile Code

FedRAMP Moderate · 16 controls

  • AC-2 Account Management
  • AC-2(7) Privileged User Accounts
  • AC-2(9) Restrictions on Use of Shared and Group Accounts
  • AC-3 Access Enforcement
  • AC-5 Separation of Duties
  • AC-6 Least Privilege
  • AC-6(1) Authorize Access to Security Functions
  • AC-6(7) Review of User Privileges
  • CA-9 Internal System Connections
  • CM-12 Information Location (CM-12)
  • CM-5 Access Restrictions for Change
  • MA-3 Maintenance Tools (MA-3)
  • MA-4 Nonlocal Maintenance
  • PS-4 Personnel Termination
  • PS-5 Personnel Transfer
  • SC-18 Mobile Code

NIST SP 800-53 Rev 5 · 15 controls

CMMC 2.0 · 13 controls

  • ASBv3-AM-4 Limit access to asset management
  • ASBv3-DP-8 Ensure security of key and certificate repository
  • ASBv3-GS-2 Define and implement enterprise segmentation/separation of duties strategy
  • ASBv3-IM-9 Secure user access to existing applications
  • ASBv3-PA-4 Review and reconcile user access regularly
  • ASBv3-PA-5 Set up emergency access
  • ASBv3-PA-7 Follow just enough administration (least privilege) principle
  • IM-7 Restrict resource access based on conditions
  • PA-1 Separate and limit highly privileged/administrative users
  • PA-2 Avoid standing access for user accounts and permissions

CIS Controls v8 · 10 controls

  • CIS-12.5 Centralize Network Authentication, Authorization, and Auditing (AAA)
  • CIS-12.8 Establish and Maintain Dedicated Computing Resources for All Administrative Work
  • CIS-13.5 Manage Access Control for Remote Assets
  • CIS-3.3 Configure Data Access Control Lists
  • CIS-5.1 Establish and Maintain an Inventory of Accounts
  • CIS-5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts
  • CIS-6.1 Establish an Access Granting Process
  • CIS-6.2 Establish an Access Revoking Process
  • CIS-6.7 Centralize Access Control
  • CIS-6.8 Define and Maintain Role-Based Access Control

ISO 27002:2022 · 9 controls

  • 5.10 Acceptable use of information and other associated assets
  • 5.15 Access control
  • 5.16 Identity management
  • 5.18 Access rights
  • 5.3 Segregation of duties
  • 8.18 Use of privileged utility programs
  • 8.2 Privileged access rights
  • 8.3 Information access restriction
  • 8.4 Access to source code

NIST SP 800-171 Rev 3 · 9 controls

C5 (Germany) · 8 controls

  • ANSSI-HYG-05 Maintain an Exhaustive Inventory of Privileged Accounts
  • ANSSI-HYG-06 Organise Joiner, Leaver and Role Change Procedures
  • ANSSI-HYG-08 Identify Each Person by Name and Separate User and Administrator Roles
  • ANSSI-HYG-09 Assign the Correct Rights on Sensitive Resources
  • ANSSI-HYG-27 Prohibit Internet Access from Administration Workstations and Servers
  • ANSSI-HYG-28 Use a Dedicated and Partitioned Network for Administration
  • ANSSI-HYG-29 Limit Administration Rights on Workstations to Operational Need

HIPAA Security Rule · 7 controls

ISO 27001:2022 · 7 controls

  • 5.15 Access control
  • 5.18 Access rights
  • 5.3 Segregation of duties
  • 6.5 Responsibilities after termination or change of employment
  • 8.2 Privileged access rights
  • 8.3 Information access restriction
  • 8.4 Access to source code

NIST SP 800-66 Rev 2 · 7 controls

ISO 27701:2019 · 6 controls

  • 6.3.2 Mobile devices and teleworking
  • 6.4.3 Termination and change of employment
  • 6.6 Access control
  • 6.6.1 Business requirements of access control
  • 6.6.2 User access management
  • 6.6.4 System and application access control

SOC 2 · 6 controls

  • SOC2-CC4.2 CC4.2 Evaluating and communicating control deficiencies (COSO principle 17)
  • SOC2-CC6.1 CC6.1 Logical access security over protected information assets
  • SOC2-CC6.2 CC6.2 Registering and authorising users before issuing credentials
  • SOC2-CC6.3 CC6.3 Role-based access, least privilege and segregation of duties
  • SOC2-CC7.4 CC7.4 Responding to security incidents
  • SOC2-P5.1 P5.1 Data subject access
  • NRC7354-2 Critical Digital Asset (CDA) Identification, Scope, and Boundary
  • NRC7354-4 Security Controls Implementation per NRC RG 5.71 Appendix B/C
  • RG5.71-C.3 Cyber Security Training
  • RG5.71-C.5 Recovery and Restoration
  • RG5.71-C.6 Configuration Management
  • ASD37-18 Restrict administrative privileges (Essential)
  • ASD37-20 Multi-factor authentication (Essential)
  • ASD37-21 Disable local administrator accounts (Excellent)
  • ASD37-37 Personnel management (Very Good)
  • AWWA-1.1 Security Policy and Governance
  • AWWA-1.3 Security Awareness and Training
  • AWWA-2.1 User Access Management
  • AWWA-3.2 Remote Access Security
  • DA-1 Enterprise Data Architecture
  • DIQ-2 Data Quality Management
  • DSO-3 Data Access Management
  • RMD-1 Reference Data Management
  • ISO-15189-5.1 Legal entity
  • ISO-15189-5.4 Structure and authority
  • ISO-15189-6.2 Personnel
  • ISO-15189-6.7 Service agreements
  • ISO-19650-1-4 Information management concepts
  • ISO-19650-1-7 Common Data Environment (CDE) concept
  • ISO-19650-2-5.7 Information model delivery
  • ISO-19650-3-5.3 Trigger events for information exchange
  • SSAE18-CC6.2 CC6.2 - New User Registration and Authorization
  • SSAE18-CC7.4 CC7.4 - Incident Response
  • SSAE18-PI1.1 PI1.1 - Processing Integrity Definition
  • SSAE18-SOC1-06 Transaction Processing Controls
  • ISM-1508 Least privilege for privileged access
  • ISM-1833 Minimum privileges for user accounts
  • ISM-1852 Least privilege for unprivileged access
  • IEC62304-5.2 Software Requirements Analysis
  • IEC62304-5.3 Software Architectural Design
  • IEC62304-7.2 Risk Control Measures

ISO 22320:2018 · 3 controls

  • ISO-22320-5.1 General process requirements
  • ISO-22320-5.3 Incident management structure (command)
  • ISO-22320-5.4 Roles and responsibilities

ISO/IEC 23894:2023 · 3 controls

  • ISO23894-1 Scope of AI Risk Management
  • ISO23894-3 AI-Specific Terminology
  • ISO23894-6.2 Scope, Context and Criteria

ISO/IEC 27004:2016 · 3 controls

  • 27004-3 Terms and definitions
  • 27004-A.2 Patching and Vulnerability Measures
  • 27004-B.1 Example measurement definitions

ISO/IEC 27011:2024 · 3 controls

  • 27011-1 Scope
  • 27011-3 Terms and definitions
  • 27011-8.1 User Endpoint Devices
  • 27557-1 Scope
  • 27557-3 Terms and definitions
  • 27557-6.2 Scope, context, and criteria for privacy

ISO/IEC 29100:2024 · 3 controls

  • 29100-1 Scope
  • 29100-3 Terms and definitions
  • 29100-4.1 Actors and roles
  • PR.AC-1 PR.AC-1: Identities and credentials are managed for authorized devices and users
  • PR.AC-3 PR.AC-3: Remote access is managed
  • PR.AC-4 PR.AC-4: Access permissions are managed, incorporating the principles of least privilege and separation of duties
  • PR.AC-1 PR.AC-1: Identities and credentials are issued, managed, verified, revoked, and audited for authorized devices, users and processes
  • PR.AC-3 PR.AC-3: Remote access is managed
  • PR.AC-4 PR.AC-4: Access permissions and authorizations are managed, incorporating the principles of least privilege and separation of duties

NIST SP 800-172 · 3 controls

  • 3.1.1e Dual Authorization for Sensitive System Operations
  • 3.1.2e Restrict Access to Organization-Owned, Provisioned, or Issued Information Resources
  • 3.13.2e Introduce Unpredictability into System Operations
  • NISTSP82-1 OT Security Program Governance, Policy, Roles, and Safety-Security Integration
  • NISTSP82-4 OT Access Control, Identity, Authentication, and Remote Access
  • NISTSP82-7 OT Incident Response, Forensics, Recovery, and Continuity
  • ORANWG11-2 O-RAN Interface Security: E2, A1, O1, O2, Open Fronthaul
  • ORANWG11-3 Cryptography, TLS, SSH, IPsec, and PKI Lifecycle Management
  • ORANWG11-6 Security Test Specifications, Certification, and Conformance
  • PICSGMP-2 Chapter 2: Personnel - Qualified Personnel, Key Responsibilities, Training
  • PICSGMP-5 Chapter 5: Production Operations and Material Management
  • PICSGMP-7 Chapter 7: Outsourced Activities and Supplier Management
  • TRINIDAD-1 Scope, Definitions, Commission
  • TRINIDAD-2 Lawful Processing and Consent
  • TRINIDAD-3 Data Subject Rights

UK Bribery Act 2010 · 3 controls

  • Section 6(5) Definition of Foreign Public Official
  • Section 8 Definition of Associated Person
  • UKBRIBE-3 Due Diligence on Third Parties

UK Cyber Essentials · 3 controls

  • CE-AC.4 Privileged Account Approval and Tracking
  • CE-AC.5 Separate Admin Accounts for Administrative Activities
  • CE-AC.6 Periodic Review of Privileged Access
  • 58.1 Scope
  • 58.3 Definitions

ACSC Essential Eight · 2 controls

  • E8-ADMIN-ML1 Restrict Administrative Privileges (ML1)
  • E8-ADMIN-ML3 Restrict Administrative Privileges (ML3)
  • AL-DPA-1 Scope and Definitions
  • AL-DPA-3 Lawful Basis for Processing
  • MYHR-SEC-2 Access controls and user account management
  • MYHR-SEC-7 Consumer access controls and consent
  • AT-DSG-2 Section 2 - Scope and application
  • AT-DSG-8 Section 22 - Functions and powers of the DPA
  • MLE.1 Machine Learning Requirements Analysis
  • MLE.3 Machine Learning Training

FedRAMP Rev 5 · 2 controls

  • FEDRAMP-CM-6 Configuration Settings
  • FEDRAMP-CP-9 System Backup
  • FDBR-702 Definitions (§501.702)
  • FDBR-Scope-Defs Scope, Applicability Thresholds and Definitions (Fla. Stat. 501.701, 501.702, 501.703, 501.704)
  • 60601-1.3 Terminology and definitions
  • 60601-1.4.1 General requirements
  • 62351-2 Glossary of terms
  • 62351-8 Role-based access control (RBAC)
  • ISO-20400-4.2 Principles of sustainable procurement
  • ISO-20400-7.2 Integrating sustainability into specifications
  • ISO-41001-4.1 Understanding the organization and its context
  • ISO-41001-4.3 Determining the scope of the FM management system

ISO 56002 · 2 controls

  • ISO-56002-4.3 Determining the scope of the innovation management system
  • ISO-56002-8.3.4 Develop solutions
  • ISO8000-DQM-02 Data Quality Dimensions
  • ISO8000-MDG-03 Continuous Improvement
  • ISO-17025-5.1 Legal entity
  • ISO-17025-5.4 Personnel for the management system
  • ISO-25012-5.2 Defining data quality measures
  • ISO-25012-5.3 Planning and performing data quality evaluations

ISO/IEC 27014:2020 · 2 controls

  • 27014-1 Scope
  • 27014-3 Terms and definitions

ISO/IEC 27043:2015 · 2 controls

  • ISO27043-04 Roles and responsibilities definition
  • ISO27043-14 Privileged access management

ISO/IEC 27400:2022 · 2 controls

  • 27400-3 Terms and definitions
  • 27400-6.1 Secure Device Design

ISO/IEC 29147:2018 · 2 controls

  • 29147-3 Terms and definitions
  • 29147-9.2 Contact mechanisms and scope

ISO/IEC 30111:2019 · 2 controls

  • 30111-3 Terms and definitions
  • 30111-5.1 Organizational policy

ISO/SAE 21434 · 2 controls

  • ISO21434-04 Roles and responsibilities definition
  • ISO21434-14 Privileged access management
  • STANAG-1 STANAG 4774 Confidentiality Label Schema and XML Structure
  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding
  • NISTPF-3 Control-P - Privacy Controls, Data Management, and Disassociated Processing
  • NISTPF-5 Protect-P Access Control (PR.AC-P)
  • NISTSP115-1 Scope, Methodology, and Assessment Planning
  • NISTSP115-8 Operational Considerations - Tools, Reporting Templates, ISMS Integration, Annex Material

NIST SP 800-123 · 2 controls

  • NISTSP123-3 Authentication, Access Control, and Account Management
  • NISTSP123-8 Governance, Policies, and ISMS Integration

NIST SP 800-137 · 2 controls

  • NISTSP137-1 ISCM Strategy, Governance, and Volatility Assessment
  • NISTSP137-6 Malware, Identity Access, and Network Boundary Monitoring

NIST SP 800-145 · 2 controls

  • NISTSP145-7 Cloud Procurement Standards Aligned to NIST SP 800-145 Definition
  • NISTSP145-8 Governance, Reporting, and Stakeholder Education on Cloud Definition

NIST SP 800-146 · 2 controls

  • NISTSP146-1 Cloud Adoption Strategy, Workload Suitability, and Decision Framework
  • NISTSP146-6 Cloud Security and Privacy Recommendations

NIST SP 800-190 · 2 controls

NIST SP 800-61 Rev. 3 · 2 controls

  • NISTSP61-2 Computer Security Incident Response Team (CSIRT) Structure and Staffing
  • NISTSP61-5 Containment, Eradication, and Recovery

NIST SP 800-63-4 · 2 controls

  • NISTSP63R4-1 Digital Identity Risk Management and IAL/AAL/FAL Assurance Level Selection
  • NISTSP63R4-3 Authentication: Authenticator Types, MFA, Phishing-Resistance, and Syncable Authenticators

NIST SP 800-92 · 2 controls

  • NISTSP92-1 Log Management Programme, Policy, Roles, and Operational Runbooks
  • NISTSP92-4 Log Management: Time Synchronisation, Parsing, Storage, Integrity, Access Control
  • NDPA-2 Consumer Rights - Access, Correct, Delete, Portability, Appeal
  • NDPA-5 Privacy Notice, Data Minimisation, and Purpose Limitation

OWASP SAMM · 2 controls

  • OWASPSAMM-1 Governance: Strategy, Policy, Compliance, Education, Champions
  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture

OpenSSF Scorecard · 2 controls

  • OSSFSC-1 Branch Protection, Code Review, and Repository Governance
  • OSSFSC-3 Build, CI/CD Security, Workflow Permissions, Dangerous Patterns

PTES · 2 controls

  • PTESPHASE-1 Pre-Engagement Interactions and Scoping
  • PTESPHASE-2 Intelligence Gathering (OSINT)
  • PICERL-P2 Risk Assessment
  • PICERL-P3 CSIRT Formation
  • SHAREASSESS-1 Information Governance and Risk
  • SHAREASSESS-2 Access Control, Identity, Authentication

SLSA · 2 controls

  • SUPCHAIN-1 Build Integrity - Source, Build, Provenance
  • SUPCHAIN-2 Source Integrity - Branch Protection, Code Review, Two-Person Rule
  • SAM-1 Customer Information Confidentiality (Section 48)
  • SAM-6 Legal Authorization Requirements
  • C1 Organizational Boundary
  • C3 Scope 1 and 2 Coverage
  • IM8-RES.2 Disaster Recovery
  • IM8-SEC.2 Access Control

South Korea ISMS-P · 2 controls

  • ISMSP-AC-01 Access Control Policy
  • ISMSP-SYS-04 Vulnerability Management
  • TANZANIA-1 Scope, Registration, Lawful Basis
  • TANZANIA-4 Security and Cross-Border
  • UKGAMBLE-1 Scope and Applicability to Licensees
  • UKGAMBLE-4 Resilience and Incident Response
  • UK-TSA-NET-01 Security Architecture
  • UK-TSA-NET-02 Access Control and Authentication
  • US-SEC-DA-SC-01 Howey Test Application
  • US-SEC-DA-SC-02 Registration Requirements
  • CFR211-A-3 Section 211.3 - Definitions

APPI · 1 control

  • 4.4.1 Resources, Roles, Responsibility, and Authority
  • AUCDR-IS-1 Limit risk of unauthorised access to the CDR data environment
  • AESCSF-IAM-2 Access control
  • AZ-DPA-2 Article 2 - Basic Concepts

BSI IT-Grundschutz · 1 control

  • BSI-02 Access enforcement and least privilege
  • BMA-16 Access Management and Segregation of Duties

COBIT 2019 · 1 control

  • COBIT-BAI02 Managed requirements definition
  • CTDPA-1 Definitions

DORA · 1 control

  • CAT-IRP-4 Organizational characteristics
  • FFIEC-05 Roles and responsibilities definition
  • FTC-Safeguards-Scope-Defs Scope, Definitions and Financial Institution Applicability (16 CFR 314.1, 314.2)
  • Sapin2-Pillar1-Code-of-Conduct Pillar 1 - Anti-Corruption Code of Conduct

GDPR · 1 control

  • ICP-1 Objectives, Powers and Responsibilities of the Supervisor
  • IATA-IOSA-Section1-ORG-Organization-ManagementSystem-SMS IATA IOSA Section 1 - ORG Organization and Management System + Safety Management System (SMS) + Safety Policy + Hazard ID + Quality
  • ISO-14064-1-5.1 Organizational boundaries
  • ISO-26262-3-5 Item definition

ISO 27799:2025 · 1 control

  • ISO27799-01 ePHI access controls and authorization
  • ISO28001-PI-01 Personnel Security Screening

ISO/IEC 23837:2023 · 1 control

  • 23837-1.1 Scope

ISO/IEC 27003:2017 · 1 control

  • ISO27003-4.3 Determining the scope of the information security management system

ISO/IEC 27007:2020 · 1 control

  • 27007-5.2 Audit Programme Objectives

ISO/IEC 27031:2011 · 1 control

  • 27031-5.1 IRBC Policy
  • 27050-1.4 Terms and definitions
  • 29115-3 Terms and definitions

ISO/IEC 29134:2023 · 1 control

  • 29134-3 Terms and definitions
  • BIPA-SEC5-1 Biometric Identifier Definition

NIS2 Directive · 1 control

  • Art.21.2.i Human resources security, access control policies and asset management

NIST SP 800-144 · 1 control

  • NISTSP144-1 Cloud Governance, Risk Assessment, and Provider Trust Evaluation

NIST SP 800-218 · 1 control

NIST SP 800-66 · 1 control

  • NISTSP66-6 Technical Safeguards: Access Control, Audit Controls, Integrity, Person Authentication

NIST SP 800-88 · 1 control

  • NISTSP88-1 Media Sanitization Policy, Roles, and Decision Framework

OSFI B-13 · 1 control

  • OSFIB13-1 Governance, Risk Management, and Three Lines of Defense
  • OMANCS-3 Identity and Access Management, Authentication, Privileged Access
  • OPENBANK-2 Strong Customer Authentication (SCA), Consent Lifecycle, and Customer UX

PCI P2PE · 1 control

  • PCI-P2PE-05 Roles and responsibilities definition

PCI PIN Security · 1 control

  • PCI-PIN-05 Roles and responsibilities definition

PCI SSF · 1 control

  • PCI-SSF-05 Roles and responsibilities definition

PSD2 SCA · 1 control

  • PSDTWO-1 Strong Customer Authentication (SCA) Core Requirements
  • PHILCC-1 Computer Crime Offences (Illegal Access, Interference, Misuse of Devices)
  • RCEPEC-1 Online Personal Information Protection (12.13)
  • RIDTPPA-1 Scope, Applicability, Definitions
  • CISABD-1 Take Ownership of Customer Security Outcomes
  • SOCI-CIRMP-SUPPLY CIRMP hazard vector: Supply chain
  • SIGSTORE-2 Transparency Log (Rekor) and Verification
  • SCA-S2 Interpretation and Definitions

South Korea PIPA · 1 control

  • PIPA-Data-Subject-Rights-Access-Correction-Erasure-Portability-Automated-Decisions-Articles-35-37-2 Korea PIPA Data Subject Rights + Access + Correction + Erasure + Portability + Article 35-37
  • SWE-2 Relationship to GDPR
  • TSAPIPE-2 OT/IT Network Segmentation and Access Control
  • UKGDPRREG-1 Subject Matter, Scope, Principles (Articles 1-11)
  • OB-OPS.2 Performance Standards
  • ACE-CR-4 Cargo Release Authorization
  • 15 U.S.C. § 78dd-2(h) Definition of Domestic Concern
  • UGA-10 Sensitive Personal Data Prohibition

WCAG 2.2 · 1 control

  • WCAGREC-3 Principle 3: Understandable
  • SO2.2 Digital health architecture blueprint

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in PR - Protect

You are reading one control. How much of NIST Cybersecurity Framework 2.0 have you already done?

NIST Cybersecurity Framework 2.0 NIST-CSF-PR.AA-05 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of NIST Cybersecurity Framework 2.0 your existing evidence covers. Hold ISO 27001:2022 and 73 of 106 NIST Cybersecurity Framework 2.0 controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 174 were rejected on the ISO 27001:2022 pair alone.

Query this from an agent

The graph holds this control, the 509 it maps to, and the evidence behind each claim, over MCP and REST.