The auditor must review the Information Security Policy (SecPol) to confirm that it covers every applicable control specified in the NZISM.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.