The organisation defines how it will find and document its cryptographic assets: the objective (for example compliance, maintenance or updating measures), the scope (which asset types, such as keys, algorithm metadata and certificates, and what to prioritise by criticality), the discovery method (tools, systems to examine and division of tasks), the information wanted for each kind of asset and how detailed it must be, with metrics for effectiveness, compliance and risk, the reporting format and structure, and how and how often the inventory is reviewed and updated.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.