Begin with identification of the data the organisation possesses by answering why data is collected/used/stored, who is responsible, what type of data, where it is located and how it is accessed; update understanding as new data types arise.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.