Access is robustly verified, authenticated and authorised. Partially achieved: initial identity verification gives reasonable confidence, all users and systems are individually identified and authenticated, access is limited to the minimum, strong authentication such as MFA protects privileged access, all remote access is individually authenticated, and the access list is reviewed at least annually. Achieved: high-confidence verification, only authenticated users can physically and logically connect, MFA for all user access including remote access, reviews at least every six months, and authentication follows current best practice.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.