Establish governance per supporting controls including: information security policy framework + management direction and commitment + policy review and update procedures + roles and responsibilities (CISO + Server Administrator + System Owner + System Security Officer + Privileged User) + contact with authorities and special interest groups (CISA + FBI + ISACs + ISAOs) + integration with information security management system (ISMS) per ISO/IEC 27001 + Annex A controls + Information classification and labeling + asset inventory + acceptable use policies + audit considerations + administrative + technical + physical controls coverage.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.