The PSIRT sits at the heart of the vendor's vulnerability handling processes: it coordinates handling inside the vendor and is the one contact point for outside stakeholders, for example coordinators, reporters and other vendors. Vendors should bring every product and service they offer within their disclosure and handling processes. A PSIRT should be set up centrally, although it may be placed inside a business unit provided it covers every product and service.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.