Maintain records of training, drills, exercises, incidents, MARSEC level changes, declarations of security, audits, and annual reviews for at least two years and protect records from unauthorized disclosure as sensitive security information.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.