Implement baseline cybersecurity controls including network segmentation, perimeter defence, multi-factor authentication for administrative access, privileged access management, vulnerability management, patch management, malware protection, and cryptographic protection of data at rest and in transit. Use only cryptographic algorithms permitted by the MoTC (with prohibition or restriction of certain end-to-end encryption implementations that block lawful access in scope of the Cybersecurity Law).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.