Sensitive data including cardholder data, sensitive authentication data, and cryptographic material must be inventoried, minimized, protected at rest and in transit, and securely deleted when no longer required.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.