Assets and their cybersecurity properties (confidentiality, integrity, availability, authenticity, authorisation, non-repudiation) are identified as the basis for threat analysis.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.