Apply NIST SP 800-115 Technical Guide to Information Security Testing and Assessment published September 2008 + still operative for security testing methodology + complement to NIST SP 800-53A + NIST SP 800-30. Define assessment scope + objectives + roles and responsibilities + rules of engagement (RoE) per Section 2 and Section 3.1 including type of testing (review + identification + validation) + targets + boundaries + sensitivity + impact assessment + escalation procedures + assessment plan documentation. Coordinate with risk management framework + system owner + system security officer + ISSO + CISO + authorising official.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.