Implement Operations Security + Physical/Environmental Security + Communications and Network Security per MTCS SS 584. Operations Security (ISO 27001 Annex A.12 alignment) - documented operating procedures + capacity management + separation of dev/test/prod + change management + patch management (security patching baseline + emergency patching) + clock synchronisation NTP + system hardening (CIS Benchmarks + DISA STIG + Microsoft Security Baselines + Apple Security + Linux/CIS) + secure configuration baselines + drift detection + container image scanning + serverless function scanning. Physical and Environmental Security (ISO 27001 Annex A.11) - Tier III+ data centre (Uptime Institute or TIA-942 Tier III/IV) + geographic separation primary + secondary + power redundancy (UPS + generators + 2N or N+1) + cooling redundancy + fire suppression + physical access controls (multi-factor + biometric + escort) + CCTV + environmental monitoring + data centre certifications (ISO 22301 + SOC 2 Type 2 + Uptime Tier). Communications and Network Security (ISO 27001 Annex A.13) - network segmentation (DMZ + internal + management + customer-facing + critical) + firewall + IDS/IPS + WAF + DDoS protection (volumetric + protocol + application layer) + Network Access Control (NAC) + 802.1X + secure remote access + VPN + bastion host + jump server + Privileged Access Workstation (PAW) + microsegmentation + zero trust architecture (NIST SP 800-207 + CISA Zero Trust Maturity Model) + Secure Access Service Edge (SASE) + Secure Service Edge (SSE) + ZTNA + browser isolation.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.