Monitor vulnerability per Section 4.1 continuously: scanning + assessment + risk prioritisation + remediation tracking aligned with NIST SP 800-40 + NIST SP 800-126 SCAP + Tenable + Qualys + Rapid7 + open-source OpenVAS. Monitor patch management status per Section 4.2 including Critical 7 days + High 30 days + Medium 90 days + emergency patching processes + WSUS + SCCM + JAMF + automated patching pipelines. Monitor configuration status per Section 4.3 including baseline compliance per CIS Benchmarks + DISA STIGs + custom baselines + drift detection + configuration management database (CMDB) currency.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.