Implement and maintain the security controls required by the Common Agreement and the QTF, including HITRUST or equivalent third party security framework attestation, vulnerability management, and incident response.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.