Operate network security + endpoint protection + secure system development + configuration management per Oman framework. Network security must include segmentation + perimeter protection + intrusion detection + DLP + zero trust architecture aligned with maturity. Endpoint protection must include EDR + application allowlisting + USB control + patching + hardening. Secure system development must apply SDLC controls including threat modeling + secure coding + SAST + DAST + dependency scanning + secrets management + SBOM. Configuration management must maintain hardened baselines per asset class + automated compliance scanning + drift detection + remediation. Vulnerability and patch management must consume Oman CERT + ICS-CERT + vendor advisories + KEV + apply risk-based remediation + compensating controls.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.