Apply NIST SP 800-146 Section 9.4 (Security Recommendations) and Section 9.5 (Privacy Recommendations) across the cloud portfolio. Security recommendations must address (a) shared responsibility model documented per service-model, (b) identity and access management (federation, MFA, privileged access, JIT access), (c) data protection (classification, encryption at rest and in transit, key management with consumer-controlled keys where appropriate, secure deletion), (d) network protection (segmentation, default deny, edge protection), (e) monitoring and logging (cloud audit trail, SIEM ingestion, retention), (f) incident response (cloud-aware IR runbooks, provider notification channel, evidence collection capability), (g) vulnerability management (continuous scanning, patch responsibility split). Privacy recommendations must address data subject rights, lawful basis for processing in the chosen jurisdiction, cross-border transfer mechanism, and provider sub-processor inventory. Address Section 9.6 Open Security Issues explicitly (multi-tenancy data leakage, VM escape, side-channel, provider insider threat) in the cloud risk register.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.