The IACS shall provide the capability to verify intended operation of security functions and report when verification fails, including periodic self-tests, configuration baselines and integrity checks.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.