Define and operate the risk management roles per NIST SP 800-39 Appendix D and integrate them with broader governance per Section 2.2. Roles include (a) Head of Agency (Chief Executive Officer) accountable for risk management programme, (b) Risk Executive (Function), (c) Chief Information Officer (CIO), (d) Senior Information Security Officer (SAISO), (e) Senior Agency Privacy Officer (SAPO), (f) Authorising Official, (g) Authorising Official Designated Representative, (h) Information System Owner, (i) Information Owner / Steward, (j) Information System Security Officer (ISSO), (k) Mission / Business Owner, (l) Common Control Provider, (m) Enterprise Architect, (n) Information Security Architect, (o) Information System Security Engineer (ISSE), (p) Security Control Assessor. Each role must have documented responsibilities + reporting lines + decision authority + integration with broader governance (board, audit committee, risk committee, enterprise risk management function).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.