Before discovery, the organisation identifies its cryptographic policy and what it must comply with, so that discovery is prioritised and roles are defined. The policy covers how keys are created, distributed, stored, rotated and destroyed across their lifecycle; algorithms and parameters for encryption and integrity; authentication and authorisation mechanisms; prevention of unauthorised modification; which protocols and versions are allowed or prohibited; and roadmaps and deadlines for cryptographic migrations. It reflects applicable law and sector rules (the handbook names PCI DSS, HIPAA, ISO/IEC 27001, GDPR and NIS2) and adjacent areas such as data classification, ICT and third-party risk and incident response, and it is revised as technical and regulatory developments and the quantum risk assessment require.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.