Undertakings implement a risk-based process governing ICT systems acquisition, development and maintenance ensuring CIA and defined protection requirements: clear functional/non-functional (incl. security) requirements; measures preventing alteration/manipulation during development; a testing/approval methodology; security testing; segregation of production from non-production; source-code integrity and documentation; and the process extends to end-user-developed applications with a register of those supporting critical functions.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.