Systems are managed so as to enable and maintain security. Partially achieved: administration is done only by authorised privileged users from devices separated from standard use, technical documentation and diagrams are regularly reviewed, and malware and unauthorised software are prevented, detected and removed. Achieved: administration only from highly trusted dedicated devices such as privileged access workstations, documentation kept current and securely stored, and malware controls using technical, procedural and physical measures.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.