Third party risk assessments. The company should assess cyber risks introduced by third parties (vendors, ports, agents) and reflect them in the risk assessment and contracts.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.