Cyber risk management should begin with senior management. Senior managers should themselves take the relevant training, build awareness of cyber risk into every level of the organization, and make sure the cyber risk management regime is holistic and adaptable, runs continuously and is kept under constant evaluation through working feedback loops.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.