For each objective the risks that threaten it have been identified and the described controls, provided they operate effectively, would give reasonable assurance that the risks will not stop the objective from being met; the auditor assesses design by understanding management's risk process, evaluating the linkage of controls to risks including risks from each class of transactions and the risks IT poses to user entities, and determining the controls are implemented.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.