Asset owner performs high-level and detailed cybersecurity risk assessments of IACS considering threats, vulnerabilities, consequences to safety, environment, production and reputation, and documents risk treatment decisions before commissioning and on significant change.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.