A foreign private issuer's annual report on Form 20-F gives the same disclosures as Item 106: the processes for assessing, identifying and managing material cybersecurity risks (with integration, third-party assessors and third-party service provider oversight), whether cybersecurity threats have materially affected or are reasonably likely to materially affect it, board oversight, and management's role and expertise, using the same definitions and board-of-directors instructions, tagged in Inline XBRL. Item 16K applies only to annual reports, not Form 20-F registration statements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.