Entities may voluntarily report cyber incidents or ransom payments that are not required, and may include additional information in required reports, to enhance situational awareness; the Section 2245 protections apply to voluntary reports in the same manner.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.