Per SIG (Shared Assessments) Standardized Information Gathering: vendor risk assessment. Requirements include (a) governance + risk management of vendors + (b) information security policies + (c) risk identification + treatment + (d) maintain SIG questionnaire responses.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.