The organisation identifies the user actions that may be performed on the system without identification or authentication, consistent with its mission, and documents them with supporting rationale in the system security plan. 1 enhancement.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.