Securely maintain systems that, based on Risk Assessment, are designed to reconstruct material financial transactions and include audit trails to detect and respond to cybersecurity events that have material likelihood of harming operations. Retain transaction records five years and audit trails three years.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.