Loading clear-text keys with a key-loading device needs dual control to authorise each session so that no single person can load clear keys alone, implemented by two or more passwords or authentication codes of at least five characters with vendor defaults changed, multiple tokens or physical keys, physical access controls, or separate loading devices per component; a single device password may be split into two halves of at least five characters held by different custodians.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.