Establish incident response policy, plan, and procedures per NIST SP 800-61 Rev 2 Chapter 2 (Organizing a Computer Security Incident Response Capability) Section 2.1 and Chapter 3 Section 3.1 (Preparation). Policy must define statement of management commitment + purpose and objectives + scope (to whom and what the policy applies) + roles and responsibilities + reportable incident definitions + reporting requirements + performance measures + reporting and contact forms. Plan must operationalise the policy with mission + strategies and goals + senior management approval + organisational approach + communication path between teams + measures of effectiveness + roadmap for maturing capability. Procedures must include standard operating procedures + technical processes + use of incident response toolkits + checklists. Review policy + plan + procedures at least annually and after every significant incident or substantive change to environment.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.