DNS for the system uses a secure primary and a secure secondary server, logically and physically separate; the primary sits in a secure data centre or an appropriately secured hypervisor; logical and physical access is restricted to authorised personnel; zone transfers to arbitrary hosts are disallowed; cache poisoning is prevented by DNSSEC or equivalent; multi-factor authentication is in place; and registry lock requires manual verification of any DNS server change.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.