Answer yes if your software, products or services have a well-defined account model, and all access to data and functionality (including via APIs and administrative interfaces) requires authentication and authorisation. No data or functionality should be reachable by an unauthenticated user by default. Describe the account model and authorisation mechanisms in the notes section, or upload supporting documentation such as an architecture diagram.