Operate cross-cutting controls per NIST SP 800-63-4. Identity service operational audit per Volume B Chapter 10: continuous audit of authentication events + identity proofing decisions + federation assertions + administrative actions with retention aligned to legal + investigative + regulatory requirements. Session management per Volume B Chapter 7: session binding via cryptographic protection of session tokens + reauthentication every 12 hours OR 30 minutes idle at AAL2 + every 12 hours OR 15 minutes idle at AAL3 + secure session termination + concurrent session limits where appropriate. Authenticator recovery per Volume B Chapter 6 with no weak fallback. Biometric governance per Volume A Section 4.3.6 + Volume B Section 4.10 + Volume B Chapter 9: subject consent + presentation attack detection + accuracy thresholds per AAL + bias testing + retention restrictions. Memorised secret requirements per Volume B Section 4.1: minimum 8 characters + check against breached passwords + check against context-specific common words + no composition rules + no security questions + no hint storage. Pre-incident integration with NIST SP 800-61 IR runbooks for identity compromise scenarios + post-incident lessons learned.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.