Product supplier defines and maintains a documented Security Development Lifecycle covering organisation, responsibilities, training, security expertise, third-party component management and security plan for each product.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.