A process is planned, put in place and controlled for managing the operational risks that could stop applicable requirements being met. As fitting, it covers: who is responsible for managing operational risk; the criteria used to assess risk (for example likelihood, consequence and what level of risk is acceptable); finding, assessing and communicating risks across operations; deciding on, carrying out and managing actions to reduce risks above the acceptance threshold; and accepting whatever risk is left once mitigation is done. The clause concerns only risks in the clause 8 operational processes, and risk is usually expressed as how likely something is to happen and how severe the consequence would be.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.