Actively monitor for adversarial penetration in five key places (IP traffic on ICS boundaries; IP traffic within the control network; host-based detection; login analysis for stolen-credential use; account/user-administration actions) and maintain a prepared response plan (disconnect, scoped malware search, disable affected accounts, isolate systems, full password reset, escalation) and a restoration plan including gold disks to restore systems to known-good states.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.