Per RFC 2350: incident reporting + authentication. Requirements include (a) reporting methods including secure channels + (b) authentication of reports + PGP keys + (c) confidentiality protections + (d) chain of custody + (e) maintain reporting infrastructure.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.