A PSIRT should set up one entry point, usually an email address or web form, through which reporters and coordinators submit potential vulnerabilities. It is responsible for keeping in touch with reporters, understanding what they want and why, and replying promptly. It may route reports from customers who hold a valid support contract through customer support, in which case that division needs suitable processes and training and must work closely with the PSIRT; ISO/IEC 29147:2018 5.5.4 and clause 6 say more.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.