The organisation builds and keeps alive a culture in which achieving functional safety is actively supported and encouraged; sets up, runs and upkeeps its own rules and processes for reaching and holding functional safety and for meeting the standard; keeps working lines of communication open between functional safety, cybersecurity, SOTIF and the other disciplines that bear on safety; carries out the safety activities the lifecycle calls for, documentation included; supplies the resources those activities need; operates a continuous improvement loop fed by lessons from past lifecycles, field monitoring and confirmation measure findings; and gives the people accountable for, performing or supporting safety work enough authority to discharge it (Annex B contrasts good and poor safety cultures).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.