Threat scenarios shall be identified, including the targeted asset, the compromised cybersecurity property and the cause of the compromise; methods include brainstorming and systematic approaches (misuse cases, EVITA, TVRA, PASTA, STRIDE); a damage scenario can correspond to several threat scenarios and a threat scenario to several damage scenarios.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.