Systems supporting essential functions are securely configured. Partially achieved: assets needing careful configuration are documented, secure builds and minimal consistent configurations are used, boundary configuration changes are approved and documented, software is verified before installation, default and shared accounts are removed or re-credentialled and service accounts protected, and standard users cannot weaken security. Achieved: such assets are actively managed and patched, all platforms meet a defined secure baseline, changes are closely managed, configurations are regularly validated, only permitted software can be installed, and automated decision-making is understood and reproducible.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.