Three Lines of Defence. Cyber risk governance should follow a three lines of defence model (operational management; risk and compliance oversight; internal audit) (para 19).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.