Conduct penetration testing at least annually by qualified internal or external party, automated scans of information systems and manual reviews of systems not covered by scans, document and report material issues, prioritize and remediate. Class A must use external experts at least every three years.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.