Board and Senior Management Oversight. The board of directors and senior management team must have oversight of cyber risk and of the operational cyber risk management programme (para 14).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.