Handling vulnerabilities involves more than engineering (customer service and public relations, among others), so an organizational framework should be designed and then recognised and backed by the divisions responsible for each area. The organization should provide: a role or capability with responsibility and authority for decisions on vulnerability handling, ideally at management level, that understands the duty owed to users, the internal processes and the framework; a named contact role or capability for handling potential vulnerabilities in every division or department that provides products or services; a contact for outside parties, which may sit within a CSIRT or PSIRT; and customer and public relations divisions ready to deal with customers and the media once a disclosure is made.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.