Partition the SUC into zones (groupings with common security requirements) and conduits (communications between zones), based on function, risk, criticality, ownership and physical or logical boundaries.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.