A process shall be employed to receive and track security-related issues reported by internal and external sources, with a published way for customers, researchers and suppliers to report them.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.