MFA required for any individual accessing the Covered Entity's information systems. Specifically required for remote access to information systems, remote access to third-party applications including cloud-based, and all privileged accounts other than service accounts that prohibit interactive login. Reasonably equivalent or more secure controls require CISO written approval and annual review.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.