At LoA2 and higher actors should have documented information security management practices, policies, risk management and recognized controls, and for LoA3 and above a formal ISMS such as ISO/IEC 27000 should be used; actors should ensure parties abide by their commitments with an avenue for redress, supported at LoA2 and higher by internal and external security audits and secure retention of records of significant events including the audits; dispute resolution services may be used.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.