To reach the cybersecurity goals, cybersecurity requirements for the item and requirements on its operational environment shall be set, in line with the description made under RQ-09-08. Requirements on the environment are met outside the item yet are covered when the item is validated, and they may turn into requirements for other items.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.