The report must include, to the extent applicable and available: a description of the incident and affected systems/networks/devices; the nature of unauthorized access and impact on operations; the estimated date range; vulnerabilities exploited and security defenses in place plus tactics/techniques/procedures; identifying/contact information for the responsible actor; categories of information accessed; and the covered entity identity and contact information.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.