Patches, updates or other vendor mitigations for vulnerabilities in high assurance IT equipment are applied only when approved by ASD, and in doing so, using methods and timeframes prescribed by ASD.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.