Identify, for each information system and component, the applicable Security Requirements Guides and product Security Technical Implementation Guides, and establish them as the secure-configuration baseline for build and operation.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.