Institutions shall implement security measures in ICT operations, including configuration and hardening, protection against malware, vulnerability and patch management, and encryption of data in transit and at rest as appropriate.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.