Implement Logging and Monitoring + Compliance and Audit + Cloud Configuration Management + Cloud Security Monitoring + SLA Management per MTCS SS 584. Logging and Monitoring (ISO 27001 Annex A.12.4) - centralised logging + audit logging + log retention (90 days online + 7 years offline for regulated + 3 years for unregulated) + log integrity protection (cryptographic hashing + WORM Write Once Read Many storage + immutable storage) + log analysis + Security Information and Event Management (SIEM) integration (Splunk + Sentinel + QRadar + Chronicle + Elastic + Sumo Logic + Devo + LogRhythm) + SOAR (Splunk Phantom + Microsoft Sentinel + Cortex XSOAR + Tines) + UEBA + cloud-native logging (AWS CloudTrail + Azure Activity Log + GCP Cloud Audit Logs + Container audit logs + Kubernetes audit logs). Compliance and Audit (ISO 27001 Annex A.18) - independent audit + internal audit + external audit + regulatory inspection cooperation + audit trail preservation + SOC 2 Type 2 + ISO 27001 surveillance audits + MTCS surveillance audits annual + recertification every 3 years. Cloud Configuration Management - approved baseline + change control board + drift detection + Cloud Security Posture Management (CSPM) - Wiz + Lacework + Orca + Prisma Cloud + Microsoft Defender for Cloud + AWS Security Hub + Azure Security Center + GCP Security Command Center + container security CWPP + cloud-native application protection CNAPP. Cloud Security Monitoring - 24x7 monitoring + EDR + NDR + cloud-native threat detection (AWS GuardDuty + Azure Sentinel + GCP Security Command Center) + threat intelligence integration + threat hunting + Continuous Compliance Monitoring. SLA Management - service level agreements + availability SLAs (99.9% Tier 1 + 99.95% Tier 2 + 99.99% Tier 3) + performance SLAs + security SLAs + breach notification SLAs + escalation procedures + service credits + monthly SLA reporting + Quarterly Business Review.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.