Determines whether systems are scanned for vulnerabilities at the defined frequency and on new vulnerability reports, whether results are analysed, and whether findings are remediated within defined periods.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.