Execute the Implement step per NIST SP 800-37 Rev 2 Chapter 3 Step 4. Implement the controls selected in Step 2 and document how the controls are employed in the system and environment of operation. Tasks include (I-1) implement security and privacy controls per SSPP, (I-2) update SSPP with as-built implementation details (settings, configurations, evidence locations). Implementation must produce machine-readable evidence where feasible (configuration scanning results, IaC repositories with policy-as-code, build provenance) and preserve traceability from control selection through configuration through evidence collection.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.