The organisation develops a concept of operations describing how it intends to operate the system from a security and privacy perspective and reviews and updates it at a set frequency. No enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.