Third-Party, Outsourcing and Cloud Risk. Outsourced functions must be governed by service agreements with compliance terms; cloud services must be risk-assessed; end-user-developed systems and critical new projects must be assessed (paras 26-32).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.