Configuration standards covering every server, network device and system component, virtual images, snapshots and the hypervisor included, consistent with industry-accepted hardening standards. Level 1 (a to f): configuration files of network devices and servers kept secure and synchronised; vendor-supplied default settings changed before a system joins the network; hardened configurations for images, snapshots and hypervisors; periodic hypervisor log analysis and integrity checks, including self-checks at hypervisor boot; clipboard and file-sharing services disabled; and secure lifecycle management of images and applications at the CSP's edge nodes. Level 2 is the same; Level 3 deploys only systems and infrastructure independently tested and certified for security assurance (for example Common Criteria EAL4 or equivalent).
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.