Adopt common secure configurations from authoritative sources such as USGCB, DISA STIGs, CIS Benchmarks, or vendor security guides as the starting point for baselines, and tailor them with documented justification for deviations.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.