Limit user access privileges to Nonpublic Information based on least privilege, limit privileged accounts, periodically review access (at least annually), promptly terminate access on role change or separation, disable or securely configure remote access, implement password policy aligned with industry standards. Class A must implement privileged access management and prohibit commonly used passwords.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.