Implement governance + ISMS + risk + HR + lifecycle per MTCS SS 584 covering Information Security Management System (ISO/IEC 27001 alignment) + Risk Management (ISO 31000 + ISO/IEC 27005) + Human Resource Security (employment screening + training + termination + post-employment) + Cloud Service Lifecycle (acquisition + provisioning + operation + termination/exit + data return) + Regulatory Compliance (legal mapping + standards adherence) + Roles and Responsibilities including shared responsibility model (CSP responsibility vs CSC Cloud Service Customer responsibility) + Cloud Security Policy and Strategy + Risk Appetite Statement + Three Lines of Defence (1st line Operations + 2nd line Risk and Compliance + 3rd line Internal Audit) + CISO + Cloud Security Officer + Data Protection Officer per PDPA. Cloud Service Customer (CSC) data ownership + CSP custodial role + Tier 3 enhanced governance with Board oversight required + monthly Risk Committee reviews + quarterly Board reporting + annual independent risk assessment. CSA Star + SOC 2 + ISO 27017 + 27018 cross-walks.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.