Per PSD2 + EBA Guidelines: governance + risk + compliance. Requirements include (a) implement comprehensive Information Security Program Management + Board and Management Oversight + Risk Appetite and Tolerance for IT Risk + (b) implement Security Policy Framework + Roles and Responsibilities + (c) implement Network Security and Segmentation + Endpoint Protection + Application Security + (d) cooperate with EBA + national supervisor + (e) maintain compliance monitoring + reporting + (f) integrate with DORA + GDPR.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.