At the ACS and DS, anything done through non-console access still complies with every other HSM and key-management requirement. (Under Technical FAQ Q3's alternative, key components and shares loaded through a non-console interface are encrypted under a key-encryption key dedicated to key transport; the secure channel's own encryption does not count.) The assessor examines policies and procedures, interviews personnel, examines HSM configurations and observes connection processes.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.