Sensitive security parameters (e.g. cryptographic keys, credentials) in persistent storage shall be securely stored, protected against tampering and unauthorised disclosure; secure storage should use hardware-protected secure elements or equivalent mechanisms where feasible.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.