Implement access control + authentication + removable media controls per 10 CFR 73.54(c) + NRC RG 5.71 Appendix B Section B.1.1 (Access Control) + Section B.1.7 (System and Communications Protection - Portable Media Controls). Access control must (a) enforce unique user identification + authentication + authorisation for all CDA access including engineering + operations + maintenance + administrative + vendor access, (b) implement multi-factor authentication for privileged access + remote access + access to highest-assurance security levels, (c) enforce least privilege + separation of duties + emergency-access procedures with audit, (d) manage shared accounts only where individual identification is operationally infeasible with compensating monitoring, (e) restrict and log remote access via authorised pathway only (jump host + PAM + session recording + JIT approval). Authentication credentials must follow strong-cryptography requirements with periodic review. Removable media and portable devices controls per RG 5.71 require (a) prohibit removable media + portable devices on highest-assurance security levels except via authorised transfer process, (b) implement sandboxed transfer stations with antivirus + integrity check + content inspection between non-CDA and CDA boundaries, (c) maintain inventory + chain of custody for all media authorised to cross boundaries, (d) configure CDA systems to disable removable media interfaces where operationally feasible.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.