Protect the information needed by the organisation to conduct its business by establishing confidentiality, integrity, availability, authentication, and non-repudiation controls aligned with business risk appetite.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.