Within a year of signing, show a measurable increase in customers' ability to gather evidence of intrusions affecting the manufacturer's products. Example approaches: logs in the baseline product covering configuration changes and reads, identity events such as sign-in and token creation, network flows and access to or creation of business-relevant data; for cloud and SaaS, retention for a set period such as six months at no charge; and, where logs are not supported, published guidance on monitoring and response. Progress may be shown by documented logging and retention policies or a roadmap for logging improvements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.