Where the decision on treating a threat scenario's risk involves sharing the risk, or retaining a risk that stems from an assumption made in the analysis, one or more matching cybersecurity claims shall be stated; such claims may be taken into account in cybersecurity monitoring.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.