Configure the container runtime to reduce kernel level attack surface using seccomp profiles, AppArmor or SELinux, and capability dropping. Ensure these controls apply to every container, not just hand picked services.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.