Before launching a programme for handling vulnerabilities, vendors should put in place the policy (6.3), the processes and the capability. They may set up a response team (PSIRT or CSIRT) and internal security assessment teams, recruit and assign people, and build tools. Vendors shall put in place a process for disclosing vulnerabilities as ISO/IEC 29147 defines it.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.