Incidents usually come from a chain of events in which one or more links fail, so stopping or changing one link can eliminate or reduce the risk. One method is to find the starting point where things go wrong and ask what could happen next. Consider how effective existing controls are against every type of harm, how work is really done rather than what manuals say, infrequent or abnormal situations, and harm during maintenance, cleaning, breakdowns and failure of controls. Appendix C shows the method.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.