Per ECC Domain 2: Cybersecurity Defence. Requirements include (a) Asset Management + (b) Identity + Access Management + (c) Information System and Network Protection + (d) Email Protection + (e) Mobile Devices + (f) Data Protection + (g) Cryptography + (h) Backup + (i) Logging + (j) Vulnerability Management + (k) Application Security + (l) Penetration Testing + (m) Patch Management.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.