Agencies should make sure information security documentation is written by personnel who understand well the policy requirements, the subject matter, the essential processes, and how the agency operates and does business.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.