Apply baseline and restricted pod security standards so that workloads cannot run privileged containers, mount the host file system, or use the host network without an approved exception. Enforce these controls at admission, not just at lint time.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.