Threats to the conventional network components of a module: audit circumvention, exploitation of cryptographic weaknesses, exploitation of failures, abuse of functions, physical security violation (limited here to remotely exploitable non-invasive attacks such as timing or cache-timing side channels that need no contact with the module), exploitation of randomness defects, misuse of residual data and unauthorized access. The ST maps each to the SFRs of 9.2.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.