A cryptographic controls policy is developed and implemented: player data and sensitive information are encrypted when crossing a network of lower trust; data that need not be hidden but must be authenticated uses message authentication; authentication uses a certificate from an approved organisation; the encryption grade matches the data's sensitivity; algorithms are reviewed periodically for continued security; weaknesses are corrected as soon as practical or the algorithm replaced; and keys are stored on secure redundant media after being encrypted by a different method or key.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.