Documented policies and procedures secure data against unauthorized or accidental exposure or loss through mistake or malicious conduct (file shares, cloud systems, external memory devices, mobile devices, malware, social engineering) and include controls to prevent, detect and report such events, with the responsible employee named.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.