Risk assessment procedures. Implements CyFun ID.RA: asset vulnerabilities are identified, internal and external threats are identified, and risks (likelihood and impact) are determined.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.