Entities must establish processes to identify, analyse, allocate and treat procurement risk, with effort commensurate with the procurement; they should consider procurement security and cyber risk under the Protective Security Policy Framework and allocate risks to the party best placed to manage them (limiting insurance demands to the risk actually borne).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.