Reported information may be disclosed, retained and used only for defined purposes (cybersecurity, identifying a cyber threat or vulnerability, mitigating specific threats of harm, or prosecuting an offence arising from a reported incident); reports must be stored and protected at a minimum at the FIPS-199 moderate baseline and personal information protected.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.