Implement identity and access management + authentication + privileged access per Oman framework. Apply role-based access + multi-factor authentication for privileged + remote + and administrative access + just-in-time access + session recording + credential vaulting for privileged accounts + automated joiner-mover-leaver workflow. Apply identity federation where appropriate + maintain audit logs of authentication and authorisation events.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.