Once the remediation is out, vendors should keep the case open alongside other work, revising the remediation where needed and going back through earlier phases until no further updates are warranted; feed what the root cause analysis found into the secure development life cycle, so that similar vulnerabilities are avoided in new or revised products (ISO/IEC 27034); and, where a service was fixed, watch how stable the product or service remains after the fix goes in.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.