Kuwait NCF Protect function (Data). Data Protection and Encryption aligned with NIST SP 800-53 SC family + ISO 27001 A.10 cryptography + A.13 communications security + KDPPR CITRA data protection coordination. Data Classification scheme (Top Secret + Secret + Confidential + Internal + Public) + Kuwait NCSC handling standards by classification + labelling + watermarking + DRM for sensitive content. Encryption: at-rest (full-disk + file + database + tokenisation + format-preserving) using AES-256 minimum + in-transit (TLS 1.3 + IPsec + MACsec) + in-use (homomorphic + confidential computing where applicable). Cryptographic standards: FIPS 140-3 modules (or equivalent) + Suite B + Commercial National Security Algorithm Suite (CNSA) + Kuwait NCSC-approved algorithms. Key Management: Hardware Security Modules (HSM) + Key Management Service (KMS) + customer-managed keys (CMK) for cloud + key rotation + escrow + revocation + Public Key Infrastructure (PKI) + certificate lifecycle management. Data Loss Prevention (DLP): endpoint + email + cloud + network + content inspection + behavioural analytics. Post-Quantum Cryptography (PQC) readiness + crypto agility + NIST PQC migration planning for hybrid + multi-PQC. Coordination with KDPPR Articles 4-5 security requirements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.