Consequence criteria express the extent of damage, loss or harm to the organisation or individuals when in-scope information loses its confidentiality, integrity or availability, with particular regard to: loss of life or harm to people or groups; loss of freedom, dignity or privacy; loss of staff and intellectual capital; disrupted internal or third-party operations; effects on plans and deadlines; loss of business or financial value; reduced market share or competitive advantage; harm to reputation or to public trust; failure to meet legal, statutory or regulatory requirements; failure to honour contracts or service levels; adverse effects on interested parties; and harm to the environment or pollution. The organisation settles how many consequence categories there are, how each is defined and what belongs in it, fitted to its context. A monetary scale can be bounded by the largest annual write-off it will bear and the smallest loss that would force liquidation, then divided into categories reflecting its risk perception and appetite, commonly on a logarithmic scale though other schemes may fit better. Where departments express consequences differently, cross-referencing them to a common anchoring scale keeps comparable levels comparable and allows aggregation across domains; a data breach, for instance, can touch privacy, confidentiality, integrity or availability and data protection compliance at once.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.