Beyond the initial assessment the vendor should investigate the reported vulnerability further: reproduce it, determine the root cause, the affected products, versions and components including those from other vendors, and other instances of the same class, as ISO/IEC 30111 7.1.4 c) and d) describe; ISO/IEC 30111 6.5.3.8 cites this clause with 5.4.6 for tracking vulnerabilities in third-party components.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.