Security is designed into essential-function systems, the attack surface is minimised and no single vulnerability should disrupt the function. Partially achieved: appropriate expertise, strong boundary defences, simple data flows for monitoring, easy recovery, and inputs checked at the boundary or monitored for content-based attacks. Achieved: systems segregated into security zones with essential functions in a highly trusted zone, simple component data flows, design for easy recovery, content-based attacks mitigated for all inputs through transformation, inspection and validation, and restrictions on automated decision-making technologies that could cause harm.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.