Apply NIST SP 800-123 Guide to General Server Security published July 2008 + foundational reference for server hardening + complement to NIST SP 800-53 + NIST CSF 2.0 PROTECT function + NIST SP 800-44 Public Web Servers + NIST SP 800-45 Email Servers + NIST SP 800-95 Web Services Security. Plan server security per Section 2 including: server selection + cost-benefit analysis + security categorisation per FIPS 199 + threat modelling + secure development lifecycle + integration with broader information security programme + identification of required services + system roles + sensitivity of data processed.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.