Apply Section 7 encryption and key management in cloud including: data at rest (provider-managed encryption + customer-managed encryption keys CMEK + Bring Your Own Key BYOK + Hold Your Own Key HYOK) + data in transit (TLS 1.3 + IPsec + mTLS) + data in use (confidential computing + Intel SGX + AMD SEV + AWS Nitro Enclaves + Azure Confidential Computing + Google Confidential VMs) + key management services (AWS KMS + Azure Key Vault + Google Cloud KMS + HashiCorp Vault) + HSM (CloudHSM + Dedicated HSM + Bring Your Own HSM) + PQC migration per FIPS 203/204/205 + envelope encryption + key rotation.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.