Controls organised into families: access control, audit, certification, configuration management, contingency, identification, incident response, maintenance, media, physical, planning, personnel, risk, and system protection.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.