Establish an organisation-wide risk management strategy per NIST SP 800-39 Chapter 2 (Fundamentals) covering the three-tier hierarchy (Tier 1 Organisation + Tier 2 Mission/Business Process + Tier 3 Information System) and Chapter 3 Section 3.1 (Frame Risk). The strategy must define purpose + scope + assumptions + constraints + risk tolerance + risk priorities + risk-to-be-shared-across-tiers, all aggregated upward and propagated downward across the three tiers. Tier 1 governs organisational risk decisions (risk appetite + budget + executive accountability + Risk Executive Function). Tier 2 governs mission and business process risk (enterprise architecture + segment architecture + protection priorities). Tier 3 governs information system risk (system categorisation + control selection + authorisation decisions per NIST SP 800-37). The strategy document must name the Risk Executive Function (Tier 1) + Information Security Architect (Tier 2) + Authorising Official / System Owner (Tier 3) and define the communication paths between tiers.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.