If CISA has reason to believe a covered entity experienced a covered cyber incident or made a ransom payment but failed to report, it may request additional information; the entity should respond to confirm whether a reportable event occurred.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.