Defines the operative scope: a covered entity is an entity in a critical infrastructure sector (PPD-21) meeting the criteria set by the CISA final rule; a covered cyber incident is a substantial cyber incident (substantial loss of confidentiality, integrity or availability; serious impact on the safety and resiliency of operational systems; disruption of business/industrial operations; or unauthorized access enabled by a third-party/supply-chain or cloud/MSP compromise); a ransom payment is the transfer of money or other property as the result of a ransomware attack.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.