A vendor should watch its own reporting channels and the public places where vulnerability information about its products surfaces (mailing lists, forums, social media, vulnerability databases), so that vulnerabilities reported from outside or disclosed publicly are picked up and fed into handling; ISO/IEC 30111 6.5.3.2 gives the PSIRT this public monitoring task, and the CRA harmonized-standard draft maps its external-monitoring requirement onto this clause.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.