The requirement for service providers to report cyber security incidents to a designated point of contact as soon as possible after they occur or are discovered is documented in contractual arrangements with service providers.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.