Maintain a process to identify, evaluate, and apply security patches and vendor advisories for systems supporting MTSA security functions, with compensating controls when patching is not feasible and documented risk acceptance.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.