A process shall be employed to conduct design reviews to identify, characterise and track security issues: whether the design meets the requirements, addresses the threat model, applies the principles and has no unnecessary attack surface.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.