Per SEC Item 106(b) Regulation S-K: annual cybersecurity risk management disclosure. Requirements include (a) Risk Management Processes including assessment + identification + management of material cybersecurity risks + (b) Third-Party Engagement including external service providers + assessors + auditors + (c) Third-Party Risk Oversight + (d) Prior Incident Impact disclosure + (e) integration with overall risk management + ERM + (f) document risk management processes for annual 10-K.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.