Identity and access for users, devices and systems are closely managed. Partially achieved: a robust procedure issues minimum access rights, reviewed regularly and through joiner-mover-leaver processes, and all access is logged and monitored. Achieved: the procedure is regularly audited, rights are reviewed at least annually and on role change, access logs are correlated with other records and expected activity, and unauthorised connection attempts raise alerts that are promptly investigated.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.