Organizations must determine the appropriate sanitization method based on data confidentiality (Low, Moderate, High), security categorization per FIPS 199, and whether the media will be reused internally, transferred externally, or destroyed.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.