Executives should make secure by design and default a buying priority, require IT to assess a product's security before it is bought, back IT in setting and enforcing purchasing criteria built on these practices, and ensure any acceptance of a product's risk is written down, signed off at senior business level and reported to the board on a regular cycle.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.