Information on the item's operational environment that matters for cybersecurity shall be described, so that threat scenarios and attack paths can be found; this includes assumptions, for example that each PKI certificate authority the item depends on is managed correctly.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.