To compare and assess very different impacts consistently the organization should define impact types and criteria that show the impact over time of a disruption to product and service delivery, approved by top management (impact types are not the same as the consequence categories of risk management); the choice depends on sector, context, nature of activities and culture, and the selection including the need for quantitative and qualitative information and the level of detail should suit the selection or justification of priorities and requirements; impact types can include business objectives, environmental, financial, health and safety, legal, regulatory and contractual, market share, operational and reputational, and can be consolidated for instance to business objectives, financial, legal, regulatory and contractual, and reputational; the organization can define thresholds at which impact becomes unacceptable (Table 2) or an impact matrix with criteria per impact level and type (Table 3, five levels adaptable), with criteria as objective and measurable as possible.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.