Attack feasibility is rated and combined with impact to determine cybersecurity risk levels per threat scenario.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.