Management oversight: the MTCS places this on the Board of Directors, where ISO/IEC 27001 speaks only of the organisation. Level 1 (a to d): the Board (or its delegate) sets direction and commitment for security, allocates resources and roles, approves the approach to risk treatment, and reviews the security programme periodically; Levels 2 and 3 are the same.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.