System owners, in consultation with each system's authorising officer, determine the system boundary, business criticality, and security and resilience objectives for each system based on an assessment of the impact if it were to be compromised or attacked.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.