Where secret keys are distributed using public-key protocols, the protocols meet Annex A: key lengths follow Annex C, generation follows current ANSI and ISO standards, and host and POI (or host and host) authenticate each other so the host is assured that the device holds the session key, or is able to compute it, and that no other party is able to.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.