Tools that could influence how cybersecure an item or component is shall be managed. These include tools used in development (model-based tools, static checkers, verification tools), in production (flash programmers, end-of-line testers) and after sale (diagnostic and reprogramming tools). Management covers user manuals and errata, protection against use for unintended purposes, access control for users, and tool qualification.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.