Apply NIST SP 800-146 Section 9.7 (Auditing and Accountability) + Section 9.8 (Cost Management) + Section 9.9 (Lessons Learned). Auditing and accountability require (a) cloud audit log ingestion into the enterprise SIEM, (b) cloud provider audit report (SOC 2 Type II / ISO 27001 / FedRAMP) reviewed annually with gap analysis, (c) right-to-audit clause in provider contracts where regulator demands it, (d) accountability matrix mapping each control objective to the responsible party (provider, consumer, shared). Cost management requires (a) tagging and allocation strategy enforced via policy, (b) FinOps function or equivalent for showback or chargeback, (c) reserved-capacity / savings-plan strategy reviewed quarterly, (d) anomaly detection on cloud spend with budget breach alerts. Lessons learned require (a) post-incident review of cloud-impacting incidents, (b) post-migration review of every workload moved to or out of cloud, (c) feedback loop into the cloud adoption strategy and decision framework.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.