The entity must have a documented security plan, policies and processes covering governance, personnel, physical, and information/cyber security appropriate to its membership level.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.