How does blocking destructive shell commands satisfy NERC CIP requirements?

Kastra enforces blocking destructive shell commands at the moment of execution and writes a signed evidence record for every shell command. Auditors get a complete, append-only trail of who attempted what, what policy fired, why the decision was made, and what data was touched. This evidence maps directly to NERC CIP, ISO 27001 control families.