If the triage concludes that a security-minded approach is needed, the organization starts one (Figure 2 A) and works through clauses 5 to 9: governance, the security strategy, the security management plan, the breach and incident management plan, and working with appointed parties.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.