Collect security-relevant logs from IT and OT assets and retain for at least 30 days, ideally 180.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.