Per RBI Cyber Framework: data protection. Requirements include (a) data classification + handling + (b) encryption at rest + in transit + (c) data loss prevention + (d) customer data security per PMLA + DPDPA + (e) cross-border data transfer compliance + (f) maintain documented data protection.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.