Apply Section 5 cloud architecture and service selection covering IaaS + PaaS + SaaS + FaaS + serverless models + deployment models (public + private + community + hybrid + multicloud) per NIST SP 800-145. Assess tenant isolation (hypervisor + container + namespace + network + storage + memory + cache) per Section 5.4 including side-channel attacks (Spectre + Meltdown + Foreshadow + Zombieload + MDS + Microarchitectural Data Sampling) + noisy neighbour + microcode patches + hardware attestation. Apply Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM) for shared responsibility.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.