Where the attack-potential-based method is chosen, the rating should come from its core factors: specialist expertise, elapsed time, window of opportunity, equipment, and knowledge of the item or component (ISO/IEC 18045; Annex G.2).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.