Agencies should have information security reviews carried out by personnel who are independent of what is being reviewed, or by an independent third party.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.