Implement NIST 800-53 CP Contingency Planning + MP Media Protection + SI System and Information Integrity families per MARS-E v2.0. Contingency Planning with Business Impact Analysis (BIA) + Recovery Time Objective (RTO) of 24 hours for Exchange consumer-facing systems + 48 hours for administrative + Recovery Point Objective (RPO) of 4 hours. Backup strategy with daily incremental + weekly full + off-site replication + tested restore quarterly. Disaster Recovery (DR) site geographically separated + tested annually full-scale. Continuity of Operations Plan (COOP) for Exchange essential functions during open enrolment + special enrolment periods. Media Protection with media marking + access controls + sanitisation per NIST 800-88 (clear + purge + destroy) + media transport protections + media accountability. Encryption FIPS 140-2 / 140-3 validated cryptographic modules for PII + PHI + FTI at rest and in transit + TLS 1.2 minimum (1.3 preferred) + AES-256 for data at rest. System Integrity with flaw remediation within 30 days for critical + 90 days for high + malicious code protection + information system monitoring + software firmware integrity verification + anti-tampering. Vulnerability disclosure programme aligned with CISA Binding Operational Directive 20-01 where applicable.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.