Privileged access is closely managed. Partially achieved: all privileged access uses strong authentication such as MFA, privileged identities (including third parties) are known and managed, their activity is reviewed at least annually, and rights are limited to role needs. Achieved: separate dedicated privileged accounts closely monitored, temporary time-bound privileged and third-party support access, rights reviewed regularly and through joiner-mover-leaver processes, and all privileged activity reviewed and recorded for offline analysis. Not achieved includes shared or default privileged accounts, system-wide rather than role-based privilege and unprotected always-on control room terminals.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.