The organisation knows and trusts the devices used to access its systems and data. Partially achieved: only corporately owned and managed devices connect, privileged operations use managed devices separated from standard use, third-party devices' security is understood with risks mitigated, plugging into a port grants no access, and unknown devices can be detected. Achieved: privileged operations only from highly trusted devices such as privileged access workstations, independent assurance of third-party devices or only dedicated ones allowed, certificate-based device identity with only known devices permitted, and regular scans for unknown devices.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.