Policy makers set the technical requirements (product versions, configuration, settings, protocols) and contractual requirements (fair information practices) for trust frameworks and should include criteria by which potential trust framework entities can be measured, drawing on standard criteria such as this framework rather than developing their own, so that entities can apply them consistently and named sets of criteria can indicate degrees of rigour at various LoAs.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.