The assessment examines how each control is meant to modify risk, whether it is in place, capable of working and achieving results, whether design or application has shortcomings or gaps, whether controls work independently or only together, what conditions could reduce or defeat them including common cause failure, and whether controls introduce new risk. It distinguishes controls that change likelihood or consequence from risk-sharing arrangements such as insurance. Assumptions about control effect and reliability are validated where possible, especially for controls assumed to have large effect, using routine monitoring information.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.