Apply Section 6 data classification and handling in cloud per FIPS 199 categorisation + agency data sensitivity + GDPR + CCPA + 24 state privacy laws + HIPAA + PCI DSS + SOX. Address data residency and sovereignty per Section 6.2 covering: in-country data localisation requirements (EU + China + Russia + UAE + Saudi + India + Brazil) + cross-border transfer mechanisms (SCCs + BCRs + Data Privacy Framework) + government access (CLOUD Act + Schrems II) + data flow mapping + processing location attestation. Configure secure data deletion in cloud per Section 6.3 including: crypto-shredding + sanitisation + verification + provider attestation.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.