Apply Section 7.5 cloud workload protection covering CWPP (Cloud Workload Protection Platform - CrowdStrike Falcon + Trend Micro Deep Security + Wiz + Lacework + Orca Security + Aqua + Sysdig + Prisma Cloud) + image and template hardening (Packer + Hashicorp + AMI/VHD hardening + scanning) + container security (Docker + Kubernetes + Aqua + Twistlock + Anchore + Trivy + Falco) + serverless security (Lambda + Cloud Functions + Azure Functions + Vercel + Cloudflare Workers + IAM least privilege + cold-start security). Apply Section 7.18 cloud configuration management + CSPM (Cloud Security Posture Management - Wiz + Lacework + Prisma Cloud + Microsoft Defender for Cloud + AWS Security Hub + Azure Security Center) + IaC scanning (Checkov + tfsec + Snyk IaC + Bridgecrew).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.