Operate supply chain risk management + information sharing + risk management strategy maintenance per NIST SP 800-39 (foundational reference) and the implementing publications NIST SP 800-161 (Supply Chain Risk Management Practices) + NIST SP 800-150 (Cyber Threat Information Sharing). Supply chain risk management must (a) identify supply chain risks during Frame + Assess + Respond + Monitor, (b) integrate with procurement + contracts + vendor management + service provider oversight, (c) align supply chain risk responses with overall risk frame. Information sharing must (a) define what information is shared with whom on what basis under what trust assumption, (b) integrate with CISA + sector ISACs + threat intelligence providers + mission partners + customers + suppliers, (c) preserve confidentiality + integrity of shared information per organisational policy + legal constraint. Risk management strategy maintenance must (a) review the strategy annually at minimum, (b) refresh on significant organisational change (restructure + merger + divestiture + mission change + regulatory change), (c) refresh on significant threat change (new adversary + new technique + active campaign affecting the sector), (d) feed lessons learned from Frame + Assess + Respond + Monitor back into strategy updates.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.