Defence in depth and in breadth. Protection should apply layered (defence in depth) and broad (defence in breadth) measures across people, processes and technology for both IT and OT.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.