Handle cloud, third-party, and supply chain incidents and integrate threat intelligence per NIST SP 800-61 Rev 2 supplemented by NIST SP 800-150 (Cyber Threat Information Sharing) + NIST SP 800-161 (Supply Chain Risk Management). Cloud incident handling must address (a) shared responsibility model per cloud service (SaaS + PaaS + IaaS) with provider-side vs consumer-side responsibilities documented in advance, (b) cloud provider incident reporting channels and SLAs (incident notification timing + scope + format), (c) evidence collection in cloud environments (audit log export + snapshots + identity provider logs + control-plane logs + workload artefacts) where consumer access to underlying infrastructure is limited, (d) cross-tenant isolation verification post-incident, (e) cloud-specific containment (revoke API keys + rotate credentials + isolate accounts + cordon affected workloads + suspend automation), (f) cloud-specific recovery (clean image redeploy + IaC redeploy + verified-clean container image rebuild). Third-party and supply-chain incidents must address (a) supplier incident notification clauses in contracts, (b) joint investigation and information sharing protocols, (c) compromise assessment of supplier-provided components and services. Threat Intelligence Integration must produce continuous intelligence feed consumption + indicator-of-compromise enrichment + retrospective hunting across historical logs when new IoCs emerge.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.