s.10.2: an organization must notify other organizations or government institutions that may be able to reduce or mitigate the risk of harm from a breach.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.