Apply Protect-P Data Security (PR.DS-P) including: data-at-rest protected + data-in-transit protected + systems managed during removal/transfer/disposition + adequate capacity to ensure availability + data leak protections + integrity verification for software/firmware/information + development/test separated from production + hardware integrity verified. Implement encryption (AES-256 + TLS 1.3 + PQC migration per FIPS 203/204/205) + DLP + secure software/hardware supply chain.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.