The description sets out whatever else about the service organisation is relevant to the services: its control environment, how it assesses risk, its information and communication (business processes included), its control activities and how it monitors, the COSO components as they bear on the system, without which the objectives and controls sit in a vacuum.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.