Use the SMS five-level impact scale across safety of people, environment, cargo, assets, business continuity, finance and reputation, or a business impact analysis model, adjusting level wording for cyber if needed, so the company understands the ratings and can rank ships by criticality. Other methods, for example the low, moderate and high potential impact levels of the CIA model drawn from FIPS 199 or methods in ISO/IEC 27005, COSO ERM or ISO 31000, can size the impact.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.