Determine likelihood and impact per NIST SP 800-30 Rev 1 Section 3.2 Step 4 (Likelihood) + Step 5 (Impact) + Appendix G (Likelihood) + Appendix H (Impact). Likelihood determination combines (a) likelihood of threat event initiation (adversarial capability + intent + targeting), (b) likelihood of threat event resulting in adverse impact given vulnerabilities and predisposing conditions, into an overall likelihood value. Impact determination assesses harm to operations, assets, individuals, other organisations, and the Nation from successful threat events, considering (a) confidentiality + integrity + availability impact on information and systems, (b) operational impact on mission and business functions, (c) financial impact, (d) regulatory and legal exposure, (e) reputational impact, (f) safety impact. Use the qualitative or semi-quantitative scales in Appendix G/H and adapt to organisational risk tolerance. Document the likelihood and impact rationale per scenario in the risk register.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.