16 CFR 314.4(c)(1-9) the 9 SPECIFIC SAFEGUARD ELEMENTS (added by 2021 amendments). (1) ACCESS CONTROLS - place access controls + limit access to authorized users + role-based + least-privilege + periodic review + revoke access promptly upon termination/role change; (2) DATA INVENTORY AND CLASSIFICATION - identify + manage data + personnel + devices + systems + facilities that enable the institution to achieve its purposes in accordance with their relative importance to business objectives + risk strategy; (3) ENCRYPTION of customer information held or transmitted by the institution both at REST and in TRANSIT over external networks - if encryption is infeasible + the Qualified Individual may approve compensating controls in writing; (4) SECURE DEVELOPMENT PRACTICES for in-house developed applications used to transmit + access + store customer information; (5) MULTI-FACTOR AUTHENTICATION (MFA) for any individual accessing any information system that contains customer information - except where the Qualified Individual approves alternative compensating controls equivalent or more secure than MFA; (6) SECURE DISPOSAL of customer information no later than 2 YEARS after the last date the information is used in connection with the provision of a product or service to the customer except where information is reasonably necessary for business or legal purposes or where targeted disposal is not reasonably feasible; (7) CHANGE MANAGEMENT PROCEDURES with documented procedures for changes to information systems; (8) MONITORING AND LOGGING of the activity of authorized users + detecting unauthorized access or use of, or tampering with, customer information by such users; (9) CONTINUOUS MONITORING OR ANNUAL PENETRATION TESTING + SEMIANNUAL VULNERABILITY ASSESSMENTS (or annual penetration testing with quarterly vulnerability assessments per the institution risk + complexity).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.