Implement Section 5.1-5.2 authentication and access control including: strong authentication per NIST SP 800-63 (AAL2 minimum for sensitive systems + MFA where appropriate + risk-based authentication) + identity management + role-based access control (RBAC) per NIST SP 800-178 + attribute-based access control (ABAC) per NIST SP 800-162 + privileged access management (PAM) with session recording + just-in-time access + access reviews quarterly + account lifecycle management. Implement least privilege + separation of duties + need-to-know principles.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.