Apply NIST SP 800-146 Chapter 5 SaaS operational recommendations to every SaaS service consumed. Coverage must include (a) data ownership and exit clauses in the SaaS subscription contract, (b) provider security and privacy assurance package (SOC 2 Type II / ISO 27001 / FedRAMP equivalent), (c) application configuration baseline aligned to organisational policy (password complexity, session management, MFA, audit logging, retention), (d) integration security (SSO via SAML or OIDC, SCIM provisioning, API access control), (e) data export and portability path (machine-readable export format and frequency), (f) tenant administrator separation of duties. Maintain a SaaS register that records the operational posture for every active SaaS subscription with annual re-assessment.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.