The organization shall give out, and make known, the responsibilities and the matching organizational authority for reaching and keeping cybersecurity, covering both organizational activities and those tied to projects.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.