Where the decision on treating a threat scenario's risk involves reducing the risk, one or more matching cybersecurity goals shall be stated. A goal is a requirement to shield an asset from that threat scenario; it may be assigned a CAL (Annex E) and may concern any phase of the lifecycle.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.