Assessment criteria say how a risk's significance is judged through its consequences, likelihood and level, and take account of how appropriate the risk management activities are, considering: the classification level of the information; its quantity and any concentration; how strategically valuable the business processes using it are; the criticality of the information and related assets; the operational and business weight of availability, confidentiality and integrity; what interested parties such as top management expect and perceive; negative consequences such as lost goodwill and reputation; and consistency with organisational risk criteria. The criteria, or a formal footing from which they are defined, are made uniform across all kinds of assessment so risks from different business domains can be communicated, compared and aggregated; they typically cover consequences, likelihood and level of risk.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.