Determines whether multi-factor authentication is implemented for the required access, including privileged and network access, and whether it cannot be bypassed.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.