A process shall be employed to address security-related issues in a manner consistent with their assessment: fixing, removing the function, mitigating in the security context, or documenting the acceptance of the risk, with timelines that depend on severity.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.