Requirement 0192 (Part Six: Physical, section 23.2 Physical Security Lifecycle; applies to All entities; dated 31 October 2024; retained from Release 2025): When designing or modifying facilities, the entity secures and controls access to facilities to meet the highest risk level to entity resources in accordance with Security Zone restricted access definitions. Layers deter, detect, delay, respond and recover; Table 37 defines access from Zone One (public) to Zone Five (cleared personnel with dual-factor authentication).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.