The operational environment is assumed to give: physical protection of the module, so no threat agent can get near it (an assumption that does not remove threats arriving through its external interfaces); trusted operators, meaning administrators, auditors and other legitimate roles act in the organization's security interest; and a pre-shared key that is random and kept confidential before it is loaded. Assumptions are made only where a matter cannot be handled technically by an SFR, and they reduce but do not remove side-channel considerations (6.1).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.