Per RBI Cyber Framework: identity + access. Requirements include (a) Identity and Access Management + (b) Multi-Factor Authentication for sensitive systems + (c) Privileged Access Management (PAM) + (d) periodic access review + recertification + (e) maintain audit + (f) align with RBI MITM/phishing-resistant authentication.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.