Keep Internet-exposed services that could be exploited to a minimum; run an approval process for hardware and software; collect logs and store them securely for intrusion detection and incident response; and segment OT device networks from IT networks (2.2.2 adds that OT should be shielded from Internet-facing systems and given protection tools). Build security into the acquisition, development and maintenance of network and information systems, including how vulnerabilities are handled and disclosed.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.