Comprehensive logging must be implemented for all key management activities, with logs protected from tampering and retained for sufficient time to support audit and investigation.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.