Per CAF Objective B: protect. Requirements include (a) B.1 Service Protection Policies + Processes + (b) B.2 Identity and Access Control + (c) B.3 Data Security + (d) B.4 System Security + (e) B.5 Resilient Networks and Systems + (f) B.6 Staff Awareness and Training.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.