The organisation establishes and documents configuration settings for system components that reflect the most restrictive mode consistent with operations, using defined common secure configurations, implements them, identifies, documents and approves deviations for defined components on defined operational grounds, and monitors and controls changes to the settings. 4 enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.