Continuity plans are required to identify and record: which stakeholders are to be notified; which processes have to keep running; who carries out the continuity strategies and what each is responsible for; how the plan is activated and who has authority to activate it; the critical, time-sensitive technology, applications and information; information security; alternative work sites; and workaround procedures.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.