Entities must protect physical assets including ICT equipment, security containers, keys, and devices storing classified information, with controls for handling, storage, and disposal.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.