The organisation identifies the event types the system can log to support auditing, coordinates event logging with other entities that need audit information, specifies the subset of events to log with the frequency or situation for each, records why those events suffice for after-the-fact incident investigation, and reviews and updates the selection at a set frequency. 4 enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.