Apply NATO-specific configuration baselines for NATO-Authorised Information and Communications Systems (ICS) per AC/322(SC/4) Cryptographic Policy + STANAG 4774 Confidentiality Metadata Binding. Conduct continuous vulnerability scanning + patch management within risk-based timelines (Critical 7 days + High 30 days + Medium 90 days). Apply Software Bill of Materials (SBOM) requirements per NATO Software Supply Chain guidance + NCI Agency Acquisition Policy. Pre-screen suppliers via NATO Industrial Advisory Group (NIAG) + national agencies (NSA + GCHQ + ANSSI + BfV + AISI + AIVD + others) for cyber adversary nation linkages.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.