Treat every new setting as extra cognitive load to be justified by its business benefit; ideally the most secure behaviour is built in with no setting at all, and where configuration is needed the default should be broadly secure against common threats.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.