Vendors should set up a process for handling vulnerabilities that follows this document, so they are ready to investigate and fix potential vulnerabilities; review it from time to time to confirm it works as intended and to support improvement; and document it so it can be repeated, with the documentation explaining the procedures and methods by which every reported vulnerability is tracked. Finding the root cause, one step in the process, can inform secure development life cycles (ISO/IEC 27034).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.