Log data is held securely, accessible only with a business need, and deleted after a suitable retention period. Partially achieved: only authorised users and systems access logs, access is partly monitored, retention periods are defined, and legitimate reasons for access are set out. Achieved: the logging architecture protects itself from threats comparable to those it detects, analysis uses copies leaving the master intact, every action on log data is attributable, and log integrity is protected with modification or deletion detected and attributed.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.