Disclose and operate malware detection + system hardening + cybersecurity upgrade features per MDS2 MLDP + SAHD + CSUP sections. Malware Detection and Protection (MLDP) including anti-malware software support + signature update mechanism + behavioural detection + endpoint detection and response (EDR) compatibility + application allowlisting/denylisting + USB control + removable media policy. System and Application Hardening (SAHD) including hardening baseline + CIS Benchmarks alignment + DISA STIG alignment + unnecessary services disabled + default credentials changed + secure configuration + privileged access restriction + memory protection + ASLR + DEP + secure boot + measured boot + Trusted Platform Module (TPM) support. Cybersecurity Product Upgrades (CSUP) including patch management capability + patch testing + patch deployment frequency + emergency patch deployment + signed patches + offline patching + co-ordination with FDA for substantive patches + concurrent operation during patching where required + post-patch validation. Software supply chain risk management. End-of-support transition planning. Operating system upgrade pathway. Service-pack policy for products on legacy operating systems.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.