Management specifies the control objectives, states them in the description and, where a law, regulation, user group or professional body specified them, identifies that party; the objectives must be reasonable in the circumstances and relevant to user entities' financial reporting, which the auditor evaluates.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.