Beyond the CISO's report on enterprise security, boards should ask for information on product security and its effect on customer security, and should look primarily to company management, not only the CISO, to drive customer risk down.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.